4 ms·
> A passwords work by being (a) secret and (b) changable. Your biometrics are categorically not secret and categorically not changable. Very true, the biometri
by therobot24 11y ago
> A passwords work by being (a) secret and (b) changable. Your biometrics are categorically not secret and categorically not changable.
Very true, the biometric itself (face, fingerprint, iris, etc) really shouldn't change for it to be reliable. But this doesn't always mean that a picture of your face will automatically allow someone else to gain access in a real world system. Further, even a stolen raw template from a data breach doesn't necessarily guarantee anything.
Currently, I disagree that a biometric should be used in the same role as a password for most applications. Most research is geared toward recognition performance, but comparatively little is focused on system security (such as spoofing). However, i still get uneasy when i see such declarative statements claiming that a biometric can never be a password. Microsoft Windows "Hello" [1] is really the best implementation of what i mean. The user sits down at the computer and the system recognizes them. For consumer applications this is really the goal of any biometric system.
[1] http://windows.microsoft.com/en-us/windows-10/getstarted-what-is-hello http://windows.microsoft.com/en-us/windows-10/getstarted-wha...
> A biometric 100% authenticates identity....
the author assertively states that a biometric does not authenticate identity, so my comment is related to the fact that the purpose is to authenticate identity (not that it will be right 100% of the time - easy to see how that would be confused - probably should have used different terminology)