5 ms·
This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprin
by Seylerius 10y ago
This is an adorably bad idea:
+ As fdik said above, you can't change your fingerprint or face easily, and it's always public
+ Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both
+ You can be compelled to authenticate a biometric without a warrant
Don't use biometrics as a password; use them as a username.
- BinaryIdiot 10y ago> Don't use biometrics as a password; use them as a username Even then people's faces change and through accidents fingerprints can also be changed / removed and then you're shit out of luck. I'm terrified I would store my important shit in something like that then get into a car accident or something and be no longer able to open it.
- Seylerius 10y agoYet another reason why this is a horrible idea.
- wolrah 10y agoImplement it like the Xbox Kinect auto-signin where you still have a username but the camera lets the device figure it out on its own. That way people can still manually enter their username in the event of any disfiguring injury or technical glitches but don't have to normally.
- BinaryIdiot 10y agoRight but the post I was responding to said to use biometrics as the username hence my comment. You're suggesting using it as a type of password :)
- wolrah 10y agoNo I'm not, I'm suggesting it be used to identify the user, then they can enter their password the same as always.
- imtringued 10y ago"We couldn't detect your face/fingerprints please enter your username directly instead." What if you get into a car accident and no longer remember the master password to your hardware password safe? What if you remember it but lost your arms and are no longer able to type? The car accident scenario is not very useful.
- Freak_NL 10y agoYou can write down your master password somewhere, or share it with a loved one. This is no different from having backups for important data. You can't easily backup your iris, face, or fingerprints.
- wolrah 10y agoBiometrics are in a really weird place as far as security goes. For the average person who's more concerned about opportunistic theft of a device than a targeted attack I'd argue that biometrics are more secure because you can't have the equivalent of a shitty password. There is no fingerprint equivalent of "1111" as your device PIN. A random pickpocket in the subway doesn't know who you are and thus can't implement any spoofs. For anyone trying to defend against an attacker specifically targeting them, you're completely right.
- SomeStupidPoint 10y agoYour fingerprints are probably all over the device they stole, though. It's like if you wrapped your laptop in a decorative cover of your password written everywhere. Similarly, if facial recognition becomes the standard, thieves will just take a snap when they rob you.
- sqeaky 10y agoYou average pick-pocket is not going to lift fingerprints of a phone. He will drop the phone in a plastic bag and fence it to someone who can lift the prints or factory reset it without the prints.
- Tharkun 10y agoAnd this is better, somehow?
- wilg 10y agoDepends if it reduces theft.
- newscracker 10y agoI think post Activation Lock and similar features on smartphone platforms, thieves usually sell stolen devices to those who rip them apart to get to specific parts that they can resell. That will continue until the phone makers figure out how to disable the display, digitizer, battery and other parts that have value even in a "bricked" phone.
- newman314 10y agoIndeed, Microsoft (of all companies) had a blog post about this that I came across a while ago that nicely summarizes this. https://technet.microsoft.com/en-us/library/cc512578.aspx https://technet.microsoft.com/en-us/library/cc512578.aspx
- sedatk 10y agoFingerprint and face recognition don't have the same threat models. And two differ from password too. For end users, fingerprint makes sense: - Stealing fingerprint requires access to your fingerprint in the first place. That narrows down the attack surface A LOT. - Coercing someone to authenticate is possible for password too. Unlike fingerprints passwords can be stolen remotely. - People tend to use same PIN everywhere. Therefore "can't change your biometric info" isn't that big of a problem. Fingerprints aren't prone to dictionary attack either because there are no "common fingerprints". Face recognition can be bypassed more easily thanks to a huge database of faces called facebook. But we shouldn't reject a security solution outright before properly analyzing the threat model. They all can have their legitimate use cases for certain scenarios.
- dalai 10y ago> Stealing fingerprint requires access to your fingerprint in the first place. This is not as difficult as some might think. We leave them all over our devices for example, but physical access is not even necessary. Jan Krissler managed to get the fingerprint of the German defense minister 2 years ago using only photos of her.