Live data from Hacker News

Fake fingerprints can imitate real ones in biometric systems

theguardian.com

41–44 of 44 posts

Re: Fake fingerprints can imitate real ones in biometric systems

#41
post #32
post #28

Earlier quoted context omitted.

defined as such! good grief. anyone can code up a system that uses a fingerprint as a username -- you can't reply "thats not a username!" yes it is, because its defined as such! similarly, lots of applications use the fingerprint as both username and password, again defying your platonic ideal. you can go ahead and define the proper "taxonomy of authentication factors" but the whole irony is you think everyone has th…

> anyone can code up a system that uses a fingerprint as a username Really? Please describe such a system. Will it use a photograph of the fingerprint? A hash value? What hash? How do you deterministically arrive at the exact same one each time, or do you plan to "change the user name every single time" and in that case what is the actual persistent pointer to the account/person? Do you expect people to then use that…

Re the hash value. Are you aware of fuzzy commitment[1]? It is a crypto scheme for protecting and/or deriving encryption keys from data that is subject to noise (such as in biometrics). If you can derive encryption keys, you can also derive hashes.

[1] https://dl.acm.org/citation.cfm?id=319714

Re: Fake fingerprints can imitate real ones in biometric systems

#42
Hum, about fingerprints as keys to store valuable and personal things. What happens if tomorrow I would suffer a car accident and 'lost' my key? or have a new scar hiding a part of my key? Would be locked out forever?

Or how to explain a machine that will keep asking for my 'real key', the concept of a wasp's sting for example?

Re: Fake fingerprints can imitate real ones in biometric systems

#43
post #25
post #22

Earlier quoted context omitted.

Not trolling, but pouring more oil on the fire... TLDR yes, biometrics are the closest thing to a user ID > Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention. > That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but…

[flagged]

> Yet again, there are three basic classes of common authentication factors: something you know, something you have, and something you are. Biometrics belong to the "something you are" class.

It's so odd to me that we consider fingerprints "something you are". Fingerprints surely are "something I have" in that I can lose them by disfigurement or maiming. "Something I am" is more like my DNA which can't be taken from me to the point of loss, unlike someone cutting off my fingers which would deny me access to whatever system it's used for.

Re: Fake fingerprints can imitate real ones in biometric systems

#44
post #13

I used to have stacks of these yellow sticky notes with my password printed on it. I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Thanks to fingerprint biometrics I can do this now just as well without even having to buy sticky notes.

> I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Indeed, sticky notes with a password printed on them stuck around where they'd be needed is exactly what my very intelligent grandmother, doctor, and likely tens if not hundreds of millions of other people do worldwide. Often to comply with "good password policies" passed down from on high by though…

The point apparently went way over your head.

Your grandmother does not leave her password all over random places. At the coffee shop, the neighbors kitchen or the airport restroom as she does with her fingerprints, or does she ?

Post reply on HN