3 ms·
Many countries now take fingerprint scans when you cross the border. Even if they themselves never use it, its easily conceivable that they could be hacked or l
by posnet 11y ago
Many countries now take fingerprint scans when you cross the border. Even if they themselves never use it, its easily conceivable that they could be hacked or leaked. Then what? You can't revoke your fingerprint.
- zuppy 11y agoWho will bother to recreate the fingerprint, most of us aren't that important? (I'm not) :) Don't get me wrong, I do understand the main problem is that you can't change this "token" and it's something that the people have easy access to. It shouldn't be used to keep data that has a higher value than the effort required.
- zmmmmm 11y agoThe real risk is that if it reaches a certain level of ubiquity (which it appears it is), authorities will invest in a) laws and b) technology to break it with almost trivial ease. The US already has my fingerprints on file from crossing the border. Presumably it means that if they wish they could trivially unlock my phone and search its contents. I fully expect that if fingerprint access does become the universal security mechanism used on computing devices we'll soon enough have fully automated solutions where law enforcement can either download your fingerprint from their existing database or scan it from any available surface in real time and apply an image to the sensor to fool it into unlocking. Obviously this will take a while to happen, so for now people are lulled into a rather false sense of security that their fingerprints are a "pretty good" way to secure their phone when they are only "pretty good" because technology will take a few years to automate the breaking of them, at which point they will become "very bad".
- r-w 11y agoWhy bother breaking into a phone manually when you already have access to all the data it sends, receives, and contains (especially now that cloud storage solutions are all the rage)? What do passcodes and fingerprint scanners even mean when the target data is already being made accessible to national governments through more convenient channels? In my mind, the only reasons tech giants continue to force centralization on their users are PRISM and data mining. Today’s devices have sizable internal drives, so all personal data could realistically be stored and processed locally; and secure, distributed systems have been proven to work for data transfer (BitTorrent), monetary transactions (Bitcoin), message boards (Aether—sort of), and more. Hopefully solutions like Copperhead OS and Blackphone that secure our mobile devices and communication channels, respectively, make it to the mainstream.
- branchan 11y agoBottomline is that in this day and age, if someone wants to hack a server and steal passwords, they can so it probably doesn't matter.
- nitrogen 11y agoNot exactly, that's what bcrypt and scrypt are for. Attackers would have to modify the running code to divert raw passwords elsewhere, which would be a lot more noticeable.
- hueving 11y agoNo, that's not the bottom line. One fingerprint opens everything and cannot be changed. You can use a different password for each site so when some craptastic one gets compromised, you're not screwed for life.