Live data from Hacker News

Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

cnet.com

71–80 of 141 posts

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#71

i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…

The scary part of that trend is that biometrics should not be replacing passwords. User ID, fine, but finger prints are something you have, not something you know.

Rather than calling it "something you know", it should be called "something you can forget if needed."

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#72

It seems like they could add a few less-predictable factors to improve the security of thumbprints without completely ruining their convenience. For instance: — Maybe you must use two or more particular fingerprints in sequence, selected by you in advance. This would require a “sleep attack” to at least try different combinations of your fingers (without knowing which to use first or how many fingers are required). —…

I'm just imagining the court case where they can force the defendant to put their finger to the reader, but they can't force them to say what order it has to be in, so they'll slowly make the defendant try all the combinations.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#73

There's not a way to combine both Touch ID and PIN for iOS access, but some apps do provide a PIN or passcode setting. For me, with the banking apps on my phone for example, I use my fingerprint to get into my phone and then manually type in the password. Seems like the best combo to me for mobile security. (Not that I'm worried about it, I'm just security minded.)

It'd seem fairly trivial for, e.g. Amazon (as in this case) to ask for your Amazon password if you go over a certain dollar-spend - or even weigh the risk of various product categories (e.g., you commonly overnight items from household goods, so we'll trust your thumbprint; but you've never ordered 5 TVs before, you're gonna need your password for that one).

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#75
post #73

There's not a way to combine both Touch ID and PIN for iOS access, but some apps do provide a PIN or passcode setting. For me, with the banking apps on my phone for example, I use my fingerprint to get into my phone and then manually type in the password. Seems like the best combo to me for mobile security. (Not that I'm worried about it, I'm just security minded.)

It'd seem fairly trivial for, e.g. Amazon (as in this case) to ask for your Amazon password if you go over a certain dollar-spend - or even weigh the risk of various product categories (e.g., you commonly overnight items from household goods, so we'll trust your thumbprint; but you've never ordered 5 TVs before, you're gonna need your password for that one).

Smart authentication/authorization is really interesting and I think a good middle ground for most people.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#76
post #58

i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…

I had to disable touch ID on my iPhone out of frustration. It works for me maybe 1 out of 10 times no matter which finger I try to use (my wife has no problem with hers). But I've always had trouble with fingerprint readers. At the DMV, govt ID card office (back when I was in the Army), etc. "Place your finger on the scanner. Nope, try again.. press harder. No, harder." I have no idea what's wrong with my fingers :|

Have you tried registering the same finger 5x?

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#77
post #64
post #37

Earlier quoted context omitted.

The most fascinating part for me is that 6 year old managed to find a way to circumvent biometric security without hacking off someone's finger: authenticate while the user is asleep. Necessity is truly the mother of innovation.

And I thought me using a keylogger as a teen to access my mom's AOL account was impressive. Clever 6 year old.

I wish my tech arms race with my parents had been simple...I had to socially engineer my dad into logging into the router on my desktop(no keylogger, just firefox password saving) so I could bypass whatever he was doing to cut me off at midnight.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#78
post #58

i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…

I had to disable touch ID on my iPhone out of frustration. It works for me maybe 1 out of 10 times no matter which finger I try to use (my wife has no problem with hers). But I've always had trouble with fingerprint readers. At the DMV, govt ID card office (back when I was in the Army), etc. "Place your finger on the scanner. Nope, try again.. press harder. No, harder." I have no idea what's wrong with my fingers :|

Certain professions have a big problem with fingerprints.

Most notable: brick masons. The fingerprints are damaged and smoothed out over the years by acids in the cement and the roughness of the bricks.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#79

It seems like they could add a few less-predictable factors to improve the security of thumbprints without completely ruining their convenience. For instance: — Maybe you must use two or more particular fingerprints in sequence, selected by you in advance. This would require a “sleep attack” to at least try different combinations of your fingers (without knowing which to use first or how many fingers are required). —…

This will only end in nano-blood-draws with genotypic personalization built into my online refrigerator all over LDAP.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#80

Earlier quoted context omitted.

Identity Authentication Authority I deal with this in my industry (telecommunications). Just because you've provided proof of identity (eg your phone number, account number), there are still things you're not allowed to do until you've authenticated your identity--and the system determines your authority, to perform an action. This is accomplished through a password, a PIN, etc. On a phone, it's an interesting shift…

You're demonstrating the difference between authentication and authorization, not the difference between identity and authentication. Notice you use the word authority, which has the same root word as authorization. Authentication is merely the confirmation of identity...it is not the same thing as authorization.

In the case of a single-user phone, is there a difference? The phone's owner has authorization to do anything, including spend funds they've previously enrolled into the phone's wallet systems, etc., so it's kind of a moot point for the purposes of this incident.

You seem to be suggesting we add extra layers here so that merely authenticating as the device's owner is insufficient authorization to conduct some actions, and re-authenticating as the owner by using something they know (secret token like PIN/password) instead of something they possess (finger) will re-grant authorization, but users find this constant re-auth very annoying.

Most would probably prefer device makers to allow them to trust the people whom they sleep around rather than input another authentication method all the time. Personal responsibility has to enter into the equation somewhere.

My advice to this parent would be to keep their phone and/or body inaccessible while unconscious.

Post reply on HN