Live data from Hacker News

Amazon One – Palm recognition for Amazon Go

blog.aboutamazon.com

71–80 of 151 posts

Re: Amazon One – Palm recognition for Amazon Go

#71

Coupling un-alienable, (purposefully) unchangeable biological marks to any account is always horrible idea. And not just the privacy part, for one, it can (only) be unwillingly altered (eg. by an accident), the same way as fingerprints, so a secondary backup code is needed anyway, making the whole setup a bad sort of convenience feature. The proper solution would be a safe hardware key mechanism.

I'm waiting for fake palm gloves. I'm sure such things already exist for finger prints.

Re: Amazon One – Palm recognition for Amazon Go

#72

Earlier quoted context omitted.

Or we could (radical idea here) not use biometrics . I don't mean to be dismissive, but what advantage does this provide over opening a web site and hitting "pay" or maybe some sort of NFC tap? This looks like biometrics for the sake of being cool and flashy, which is not a trade-off I'm willing to make.

Here's an example which something like Amazon One can solve, but a card cannot: When I go to the grocery shop and I buy alcohol then I have to wait at the self checkout till until a member of staff comes to verify my age before I can pay for my shopping basket. That involves me showing them an ID (e.g. my driving license) and them having to verify my biometric (face) by looking at me and then looking at my driving li…

Plus all your alcohol (and other) purchases are permanently logged and associated with you. Hell yeah.

Re: Amazon One – Palm recognition for Amazon Go

#73

Earlier quoted context omitted.

> Why not do the same thing, but instead of verifying your palm you verify a device? Because my (imaginary) 12 year old son can grab my phone and then pretend to be an adult when doing booze shopping. This is the reason why most Western countries don't allow this kind of technology for age verification. For example in the UK you have to file an application if your new technology can be authorised to be used for age v…

But why couldn't the device handle your biometric authentication? Your 12-year-old son can't (hopefully) steal your face or your fingerprint.

You might be able to avoid a central database of biometric data, but who is going to certify the accuracy of these biometric authentication devices?

Presumably if a manufacturer made a device that didn't actually bother checking the fingerprint, the systems that integrate with these devices would have to refuse to accept claims from it.

Re: Amazon One – Palm recognition for Amazon Go

#74
So far what Apple and other companies did is to keep the biometric auth tied to the device and not let leak out. Now Amazon is saying leaking it is the feature. They are using the hand as the identifier, so the biometric id is what is used to identify a person, not an email address, not a random number or a handle. The biometric data that cannot be changed ever is the identifier.

It's very troubling.

- The privacy and security implications are huge.

- Its tied to commerce, not some airport entry thing. Commerce has legs.

- On top of that its scary because Amazon can push this all over the world and give their tech for free to businesses.

- Other companies will provide this "feature" too.

The one door I was hoping will never be opened is opened now.

Re: Amazon One – Palm recognition for Amazon Go

#76
post #61

My college uses these to control entrance to the dining halls. The technology has been around for years and it works consistently and effectively. They want you to think this is something highly innovative but I’m pretty sure they’re just licensing already existing palm scanners.

Were those dining hall scanners using a palm-on-glass technology, or mid-air like what Amazon is showing?

Re: Amazon One – Palm recognition for Amazon Go

#77
post #58

I still don’t get it: why would you choose something that’s so hard to change, if ever, for a store ID? It’s convenient but is it secure? There are photos of me waving with my palms out...

The photo of your palms out doesn't include an image of your veins because it wasn't taken with an infrared camera.

“ One reason was that palm recognition is considered more private than some biometric alternatives because you can’t determine a person’s identity by looking at an image of their palm.”

Wow. Never thought of that. But is it easy to reconstruct veins?

Re: Amazon One – Palm recognition for Amazon Go

#78
post #68

This is a continuation of Amazon's remove all inconvenience strategy. And it'll work. You're waving your hand and walking through now, no more scanning, no more opening up an app, no more tinkering with your phone. By chipping away at each of these friction points, no manner how minor, their moat grows and customers will notice a difference between an Amazon retail store vs. a competitor's.

What I think is interesting is that I suspect they’ll eagerly license this to competitor stores. A palm reader does not turn your local Safeway into Amazon Go, and they know that.

Having a slice of every point of sale could be huge; imagine how much better this is than having to use FaceID during a pandemic. (Tap tap, pin, pin, tap is a LOT more friction than “hover.”)

I’d pay for it if I ran a retail store. I wonder if Amazon will ever compete with Visa or other payment providers.

Re: Amazon One – Palm recognition for Amazon Go

#79
post #57

Earlier quoted context omitted.

We should read the opposite of what they're saying to be true: they already have our fingerprints, and they want the rest of our hands.

Hate to go that way but I was thinking this. What's worse is that it is uploaded to some server somewhere instead of being kept localized.

My hope and suspicion is that they’re storing a one way hash of the data to create the signature.

Re: Amazon One – Palm recognition for Amazon Go

#80

Year 2030. I kind of like the old school physical credit cards. It was fun to carry a wallet too. You could customize it, add a bit of flair and constantly obsess about making it thin. Good ol’ days.

Yeah, but that's just simply inconvenient. When you look at a copyrighted building or hear a copyrighted song, you need a quick and integrated way to debit the royalties from your crypto wallet. How did folks do that in 2020? Did you have to enter your credit card details in hundreds of websites before leaving the house each day?

If you think that updating people's financial balance was difficult in 2020, wait until you hear how they updated their social credit scores. Basically, everyone had to write their thoughts down on one of a few government-approved social media websites, but the government would crowd-source most of the actual surveillance and punishment, by relying on mobs of users to "cancel" people who expressed the wrong ideas. Completely inefficient!
Post reply on HN