4 ms·
The real problem is that bio-metrics are basically unchangeable. As soon as a database gets hacked or stolen, or whatever device does the recording has a vulne
by Figs 11y ago
The real problem is that bio-metrics are basically unchangeable. As soon as a database gets hacked or stolen, or whatever device does the recording has a vulnerability, your security with such systems is compromised forever -- not just at the original place that was breached, but with everyone else who uses the same metrics.
- acdha 11y agoYes - my rule is that if the other side knows you're using biometrics, the system is too dangerous to use. The weird part is how unnecessary the Mission Impossible stuff is: replacing passwords is a legacy hassle so if you're going to do that there's no reason not to do so with a flexible public key design which doesn't make assumptions about the client hardware and can be patched when it's compromised. (Biometrics might be a fine usability option for the client store)