Live data from Hacker News

MasterCard to start verifying transactions through selfies

americans.org

31–40 of 56 posts

Re: MasterCard to start verifying transactions through selfies

#31
post #6

Relevant link: "Fingerprints are usernames, not password" (applies to all biometrics): http://blog.dustinkirkland.com/2013/10/fingerprints-are-user... Long story short, it's a bad idea, and it's really not secure.

It's much worse for pictures than fingerprints because most people have tons of pictures of themselves online now, and many are also public. It's probably just a matter of time before malicious hackers start spoofing their identities.

don't forget all the ongoing advances in the "here's a bunch of pictures, come up with a 3d model of the person" problem, making the spoofing even easier

Re: MasterCard to start verifying transactions through selfies

#32
post #29

I'm starting to feel like a grey neckbeard. In my day, when I wanted to hang out with my friends, I called them, from a landline, known simply as "the phone". These days, I'm at or near a desktop/laptop computer almost 24/7 so don't see much need for a smartphone. I dread the day when a smartphone is required to be a part of society. It's shifting in that direction rapidly. If being on Facebook/LinkedIn also becomes…

The next step will be to embed smart phones in children at birth. I guess "The President's Analyst" was more prescient than we gave it credit for.

Re: MasterCard to start verifying transactions through selfies

#34
post #6

Relevant link: "Fingerprints are usernames, not password" (applies to all biometrics): http://blog.dustinkirkland.com/2013/10/fingerprints-are-user... Long story short, it's a bad idea, and it's really not secure.

It's much worse for pictures than fingerprints because most people have tons of pictures of themselves online now, and many are also public. It's probably just a matter of time before malicious hackers start spoofing their identities.

Well we had this idea ten years ago, but the biometric scan was checked for freshness against a database of biometric scans. It was thought for protect the conversation between two leers however and not for blind validation.

The idea to protect against this kind of replay attack was that if the algorithm was unsure of the scan it could request a new one, validate it and present it to the user in case of low confidence biometric match or high confidence forgery: the point being that humans are good at detecting the kind of tampering that could fool an algorithm and vice versa.

This required to send the biometric scan to the peer and to validate it on the other side of the communication channel instead that on the device.

Well, we weren't technically using it as password in the end, I guess I'll have a closer look at what they're doing. And check if that old patent is still good. Eheh not that I have any rights to it left of course.

Re: MasterCard to start verifying transactions through selfies

#35
post #29

I'm starting to feel like a grey neckbeard. In my day, when I wanted to hang out with my friends, I called them, from a landline, known simply as "the phone". These days, I'm at or near a desktop/laptop computer almost 24/7 so don't see much need for a smartphone. I dread the day when a smartphone is required to be a part of society. It's shifting in that direction rapidly. If being on Facebook/LinkedIn also becomes…

Actually the main reason I have a smartphone is for GPS. Imagine a device where you enter the name of a place and it tells you how to go there.

Re: MasterCard to start verifying transactions through selfies

#36
post #29

I'm starting to feel like a grey neckbeard. In my day, when I wanted to hang out with my friends, I called them, from a landline, known simply as "the phone". These days, I'm at or near a desktop/laptop computer almost 24/7 so don't see much need for a smartphone. I dread the day when a smartphone is required to be a part of society. It's shifting in that direction rapidly. If being on Facebook/LinkedIn also becomes…

[deleted]

Re: MasterCard to start verifying transactions through selfies

#38

Earlier quoted context omitted.

In the two years since that article was written, how many cases have there been of iPhones actually hacked in the wild through TouchID?

How would one measure that, even if it is happening?

Not hacked in the normal sense but there have been kids who needed their sleeping parents' phones unlocked, so they just put the phone to their parents' fingers...

Re: MasterCard to start verifying transactions through selfies

#39
post #29

I'm starting to feel like a grey neckbeard. In my day, when I wanted to hang out with my friends, I called them, from a landline, known simply as "the phone". These days, I'm at or near a desktop/laptop computer almost 24/7 so don't see much need for a smartphone. I dread the day when a smartphone is required to be a part of society. It's shifting in that direction rapidly. If being on Facebook/LinkedIn also becomes…

I always wonder if there were these old fogeys who complained when the first postal services were brought in in the 19th century. Like "Back in my day, I visited my friends and family because I cared, but now any idiot with a stamp can send me an annoying letter."

Re: MasterCard to start verifying transactions through selfies

#40
post #2

My question is: "Selfie as a Password", - Is it really secure?

Its a terrible idea. Its a password you can't change, can't even choose, leave lying about all over the place. Its everything a password shouldn't be.

To our valued MasterCard customers,

We recently learned that one of our service providers, was the victim of an illegal and unauthorized intrusion into its network during the first quarter of 2016. In response, the service provider enhanced the security of its network systems, cooperated with law enforcement including the United States Secret Service (“USSS”), and investigated using leading outside security firms.

Out an abundance of caution we are recommending all of our customers to get plastic surgery to their face in order to secure your identity and financial accounts. As a token of our apology, we will be paying 80% of all related surgical costs. Again we apologize for this incident and we will be taking steps to ensure it does not happen again.

Post reply on HN