Great! Now the FBI does not even have to arrest me to get my fingerprints and retina scanned!
I'd assume it's doing the equivalent of password hashing, so the authentication mechanism just verifies a hash match.
61–70 of 95 posts
Great! Now the FBI does not even have to arrest me to get my fingerprints and retina scanned!
I'd assume it's doing the equivalent of password hashing, so the authentication mechanism just verifies a hash match.
As someone who actively researches biometric authentication, when I hear/read someone saying that biometrics are "usernames" and not "passwords", I automatically think they fundamentally misunderstand what a biometric is. A biometric is both a 'username' and a 'password' - for instance, when you access your computer/device/whatnot you type in your username and your password to identify to the system that you are requ…
> if the data breaches we hear about almost monthly (Uber, Target, etc) are any indication, your password is just as at risk as your fingerprint. Two things - let's assume these companies follow best practices and both the fingerprints, biometric details and passwords are all hashed. Still: a) Unlike a password your biometric data is publicly obtainable. b) You cannot change your biometric data after it's been compro…
Read the post, i never discuss the security or merit of a biometric versus a standard user/pass login. I only discuss the advantages/disadvantages and goals of each system. If you inferred a recommendation for one or the other then you misunderstood.
> Finally I think typing passwords just isn't that hard - everyone is used to it by now. I maybe odd in this
I completely agree. However, when you see people go to their 'secret drawer' and open up their password book to login to X, then you realize it's a fundamentally broken system (just as using a raw biometric is).
As someone who actively researches biometric authentication, when I hear/read someone saying that biometrics are "usernames" and not "passwords", I automatically think they fundamentally misunderstand what a biometric is. A biometric is both a 'username' and a 'password' - for instance, when you access your computer/device/whatnot you type in your username and your password to identify to the system that you are requ…
"A biometric is both a 'username' and a 'password' " This is true, but usually people don't go around showing their passwords to any camera they walk by or surface they touch. That is why people say that it is more appropriate for biometrics to identify someone than it is to provide their authentication. "our password is just as at risk as your fingerprint." Also true, but what do you do when these breaches happen if…
Yea i see the point, but there will always need to be an asterisk after the statement, "a biometric is a username, not a password", because it's only valid in the sense there are concerns about the security of the biometric template. Down the line maybe we'll figure out this spoofing/liveness test thing, but we won't find out while many instantly write off the merit of the system to begin with.
> what do you do when these breaches happen if the data is biometric? You can't send out an e-mail asking people to change their fingerprints or face.
I did mention this somewhat in the original post. Saving a raw biometric template (minutiae points or whatnot) is synonymous to keeping a database of plain text passwords. It's just wrong. The data breaches (Uber, Target, etc.) are proof that in 2015, we still have this problem. I would never trust a start-up or large corporation with consumer grade biometric authentication. However, on my laptop a different story...i've been using the Thinkpad fingerprint reader for years and love it.
Passwords are only broken because for most intended purposes they act as a symmetric key that you happen to leave around everywhere and when it leaks, you have a problem.
If we had a web standard for asymmetric key authentication, you just unlock your device and your device authenticates you. A leaked public key (created for a single service) is useless.
And once you only need to unlock ONE device, you might as well remember that single password, because at that point it is way more secure than a fingerprint.
Of course devices break and get stolen, so you need to back up your keychain, and I bet that is exactly what MS Passport does for you, which is why it will never be adapted by other vendors.
Convenient, for sure. However, I always have the choice of not giving up my passwords, under (even painful) threat. Also, someone cannot get my passwords if I am dead. Ever. Unfortunately, with biometrics, it is quite easy to force me to put my face/finger/iris in front of the machine and unlock it. Even if I am (freshly) dead. Not that cool, really.
As someone who actively researches biometric authentication, when I hear/read someone saying that biometrics are "usernames" and not "passwords", I automatically think they fundamentally misunderstand what a biometric is. A biometric is both a 'username' and a 'password' - for instance, when you access your computer/device/whatnot you type in your username and your password to identify to the system that you are requ…
As someone who actively researches biometric authentication, when I hear/read someone saying that biometrics are "usernames" and not "passwords", I automatically think they fundamentally misunderstand what a biometric is. A biometric is both a 'username' and a 'password' - for instance, when you access your computer/device/whatnot you type in your username and your password to identify to the system that you are requ…
there are 2 main reasons why you wouldn't want this as a password, 1: you leave a biometric footprint everywhere you go, 2: once compromised, you can't reset your biometric profile. In situations where you would want it to automatically authenticate you, it's likely for a system you wouldn't have had password protected in the first place ex. your xbox.
Latent fingerprints, high resolution video, facebook profiles...all examples of how i can pick up someone's biometric. This is not an unknown problem.
> 2: once compromised, you can't reset your biometric profile.
Clearly. Just based on the definition you can draw that conclusion - a unique, unchanging trait that is used to separate the user from a group.
Common and justified criticisms that people think are just the 'silver bullet' of why a biometric should never be implemented. I've posted replies to these a few times. Feel free to check them out.
Either way, the difference between a corporate login system, and me logging into my laptop is huge. MS implementing a biometric for a consumer laptop is fitting given the current state of the field. Use it or don't, no one is forcing you.
Biometrics sound like the next frontier for milking licensing revenue. Pretty soon they will offer a discounted license for office, but only for one biometricly identified user. Multiple users, such as library users, will require the special license, even though they are all using the same computer.