30 ms·
If you believe your key has been compromised (say duplicated), you can change the lock and your key. If you believe your fingerprint data has been compromised,
by foo101 9y ago
If you believe your key has been compromised (say duplicated), you can change the lock and your key.
If you believe your fingerprint data has been compromised, can you change your fingerprint data?
- seandougall 9y agoAs far as your phone is concerned, yes. Nine times, for most people.
- curun1r 9y agoBelieve it or not it's actually nineteen times, not nine. Though the last ten introduce a fair amount of inconvenience and eww-factor when unlocking your phone.
- zingmars 9y agoI don't know about Apple phones, but I had luck getting my phone to unlock by using my chin. It wasn't really reliable (stopped working after a few hours, probably because of the beard growing), but I'm sure we can figure something out.
- andrewingram 9y agoI tried using TouchID with my toes and it didn't really work.
- valuearb 9y agoBeing male, I actually have 21 digits, if you can stomach more inconvenience and eww-factor when unlocking a phone.
- lazyjones 9y ago> Nine times, for most people. It's not too difficult to get access to the full 50000-odd combinations (see https://support.apple.com/en-us/HT204587 https://support.apple.com/en-us/HT204587 for where that number comes from) Apple hardware can identify with a little work. https://www.theguardian.com/technology/2014/dec/30/hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands https://www.theguardian.com/technology/2014/dec/30/hacker-fa...
- kibwen 9y agoThis is irrelevant, because if you believe that you're at risk from your fingerprint data being compromised, you can always fall back to not using biometrics at all. They aren't your primary authentication mechanism.
- yeukhon 9y agoThe trend is we are going to see more use of biometrics to authenticate.
- foo101 9y agoWhether you can fallback to not using biometrics is irrelevant to whether biometrics is equivalent to usernames or passwords. In fact, your point that one can fallback to not using biometrics once it is compromised proves that biometrics is not equivalent to passwords.
- kibwen 9y agoAt no point have I argued that biometrics are equivalent to passwords. But to conclude that biometrics must be equivalent to usernames because of that fact would be a false dichotomy. Biometrics serve an auxiliary role in security as an optional, subservient supplement to passwords.
- unkown-unknowns 9y agoIf you never use your password do you then expect to remember it?
- kibwen 9y agoYes. If you read about how biometrics are implemented on handsets, a user is required to enter their password every time that the device is rebooted. The password is also required at random intervals, once every few days or so. And if the biometric scanners log a handful of failed accesses, the handset is locked and a password is again required to enter.
- seanp2k2 9y agoSame with SSNs. Try changing yours. And yet, they're used as passwords.
- shangxiao 9y agoAnd what's worse is when utility companies require me to "authenticate" over the phone with my name, address & dob: all publicly (to varying degrees) available information.
- wruza 9y agoMy pet peeve is an incoming call with authentification demand (name, dob) before we speak. As if I'm going to tell my personal info to random id, no matter is it publicly available or not. At the same time they easily send me sms with private accounting info.
- newscracker 9y agoThere are many people who get scammed through such calls. I believe it is up to the technology and technology security savvy people to constantly educate others.
- wruza 9y agoEven today when I speak about info security they look like you're wearing a foil hat. Another scam is people knocking into doors to "deliver useful social information" and asking for your ids/signature in the end. It may be marketing info collection or even simply visual wealth evaluation, but sure there are those who believe it's done for good [edit:] intents. I'm usually let them tell their tale (out of my room, of course), ask a lot of questions, nod with them happily, and in the end I say thanks, but I'm sorry, I don't disclose my info, full stop. Their butthurt is sometimes too cool to watch without popcorn.
- jrimbault 9y agoI always hoped those tests were more about a human measuring my reaction speed. If I am who I say I am I should be able to answer all three without much thinking and answer naturally to my name.
- zwily 9y agoWhat exactly does “fingerprint data has been compromised” mean? Someone lifted my print off a glass?
- bodz 9y agoLifted it off a glass/phone/anything else you touched. Or it can be "compromised" in the same way your SSN can be compromised through hacking. The millions of people who were exposed in the OPM hack all have records of their fingerprints now floating out on the darkweb somewhere.
- newscracker 9y agoIt could also be someone lifting it off through software on your phone if you had a device with a terrible implementation for handling fingerprints. See this piece about the HTC One Max from two years ago - the fingerprint was stored as a bitmap image in a "world readable" folder and refreshed with the image from the latest touch! [1]: http://www.theregister.co.uk/2015/08/10/htc_caught_storing_fingerprints_as_worldreadable_cleartext/ http://www.theregister.co.uk/2015/08/10/htc_caught_storing_f...
- proactivesvcs 9y agoA badly-written program that stores the fingerprint data in a reversible/plaintext manner. Once their database gets pwned (and/or is left wide open on the cloud) your biometrics can be reconstructed and used to authenticate as you.
- valuearb 9y agoSomeone 1) lifted it off some surface. 2) got the right fingerprint when they did it 3) modeled a fake fingerprint well enough that it would fool touchID 4) Was able to get access to your touchID device while you weren't aware or unable to stop them Most experts recommend that you instead use a pin-code of at least 6 numbers, or a password of at least 12 random characters using at least one number, and at one punctuation mark. In that case the attacker's algorithm changes to 1) Check for posted note containing password on computer monitor, or 2) Check purse or wallet for posted note containing passcode
- evincarofautumn 9y agoIn case anyone’s genuinely curious about fingerprint removal, rather boringly the best solution in practice is just to wear gloves. The alternatives are mostly temporary and much more painful than you’d expect, such as branding, abrasion, or chemotherapy drugs such as capecitabine.
- apexalpha 9y ago>If you believe your fingerprint data has been compromised, can you change your fingerprint data? Yep. I can use another finger. If all 10 have been compromised you probably have bigger issues. Or you just turn it off.