4 ms·
I think this has been mentioned before on HN. Finger prints, retina scans, brain scans are not passwords, they're userid's. If the scanner could read a passwor
by xedarius 10y ago
I think this has been mentioned before on HN. Finger prints, retina scans, brain scans are not passwords, they're userid's.
If the scanner could read a password out of my head then it would be a password. But merely knowing it's my brain isn't good enough (for secure transactions at least).
- draugadrotten 10y agoThe trinity: Something you know, something you have, something you are. Reading the article, the 'brainprint' seems to be more similar to a challenge/response password than an identity. The brainprint is the brain response to 500 images. It can therefore be changed and replaced by another response to another set of images. It can be seen as a high security biometric challenge/response password mechanism which can not easily be eavesdropped or faked. The brainprint is something you HAVE (the response) which is different from something you ARE (a fingerprint, a retina, a brain)
- TeMPOraL 10y ago> different from something you ARE (a fingerprint, a retina, a brain) How is "something you ARE" a useful classification? A fingerprint can be easily changed. And retina patterns could (probably already can) be faked too.
- fosco 10y agowhat happens when instead of my association of apples to keeping doctors away changes to Isaac Newton and Gravity. does my identity change? (assuming one image is an apple)
- SEJeff 10y agoYup, you just nailed it. Here is the best writing on just that I've found (and have shared before on HN): http://blog.dustinkirkland.com/2013/10/fingerprints-are-user-names-not.html http://blog.dustinkirkland.com/2013/10/fingerprints-are-user... Biometric data makes for great usernames, but not so much for a password. How do you "reset" your brainwaves? The wishy-washy part of TFA on that made me question the entire premise.
- 794CD01 10y agoThat's not a complete complaint. If the password were your brainwaves, why would you still need to reset it? Did someone else steal your brain and you need to make sure they no longer have access?
- JoshTriplett 10y ago> Did someone else steal your brain and you need to make sure they no longer have access? Password databases get compromised all the time; so would a "brainprint" database. You can change a password.
- Lx1oG-AWb6h_ZG0 10y agoThat's what one-way hash functions are for. You never store the raw fingerprint data, just its unique salted hash so the data cannot be reused elsewhere.
- Vraxx 10y agoIt only takes one case of blatant disregard by a trusted source to spoil the entire process. What do you do when the scandal leaks that X Co didn't do due diligence and now 100 million of their customer's brainprints are leaked and able to be compromised?
- heffo 10y agoThat's the same reasoning for text passwords, yet there are huge password dumps every year. It only takes one place where security standards aren't implemented properly to have your print leaked forever. Never mind a malicious user managing to alter the code to leak the print before it's hashed. Or even someone physically accosting you and retrieving a brain scan. They could do the same thing and force you to give up a password, but at least the password you can change later on.
- JoshTriplett 10y ago
- dewiz 10y agoRight, and password should be voluntarily entered. This system would be able to steal my password, e.g. unlocking my laptop, forcing me to look at some photo
- namlem 10y agoBrainprints are not like retina scans and finger prints. They can't be read without you knowing and can be cancelled, as they are tied to a specific stimulus. If you want to change your brainprint password, just change the image it's coded to.