6 ms·
So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these
by KeitIG 9y ago
So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?
- jbg_ 9y agoA fingerprint is just a really complex password that you leave on everything you touch. Your face is just a really complex password that is written on the front of your head. It should be self-evident that neither of these is "secure" for some level of "security", but they might be perfectly fine for the level of threat that you face, which is not likely to be particularly high. But I don't know you, so maybe you face a higher-than-average level of threat, in which case, yes, a sufficiently long password/passphrase that you memorise is probably the best option for your mobile device.
- contras1970 9y agofingerprints and faces are just really complex usernames: they're not secret at all.
- valuearb 9y agoYour biometric measurements are essentially secrets. They work today because it's far too difficult for a thief to steal your device AND copy your biometrics at the same time. This makes them the most secure tokens we have in real world use, given the number of people with 0000 passcodes. Eventually they may become easy to copy, then their utility as secrets will be gone.
- tzahola 9y agoThe solution is obvious: genital scanners! https://www.youtube.com/watch?v=0zu4XlM_89s https://www.youtube.com/watch?v=0zu4XlM_89s
- timthelion 9y agoAdvanced fingerprint recognition devices recognize things that are not left on things that you touch. They look under the skin at blood vessel and measure body capacitance and other statistics. That's why there is the weird light on the "biometrics" device in the airport, to be able to see through the outer layers of skin. https://en.wikipedia.org/wiki/Finger_vein_recognition https://en.wikipedia.org/wiki/Finger_vein_recognition
- teniutza 9y agoI've read somewhere (probably in one of Troy Hunt's posts) that biometric data should not the be password, but rather the username. Maybe we're looking at this the wrong way. Biometric data seams to be equivalent (or at least similar) to a public key.
- mmirate 9y agoPublic keys still (ought to) get rotated-out when they've been in-use long enough that they could have been factored in that time.
- raverbashing 9y agoNothing is secure about a determined attacker (in the same way the door to your house doesn't resist being battered with a ram) The issue is convenience together with good enough security
- mtgx 9y ago> Are passwords/double authentication the only way to keep things private and secure these days That's always been the case. The main promise of biometric security was not "better security", but better convenience. The best argument for it would be that it makes average security better, in the sense that more people use it than not use anything at all or re-using passwords, but it's not the best way to secure your devices. Password manager + U2F token is the most secure way to lock your accounts.
- Yizahi 9y agoFingerprint or face or retina is not a "password", it is a "login". And we should have a proper password in addition to the login, not as a substitute.
- Fnoord 9y agoOne problem with passwords is that one has to use an input device like a keyboard or touchscreen to enter them (not needed with a password manager but how to enter that? via a password). Cameras and eyes can record this. Wouldn't surprise me if software can already accurately record keystrokes via a camera feed.
- lightbyte 9y agoI wonder if Apple experimented with using eye movements as a passcode? I imagine they have the technology available to do such a thing. That would make it so your face is your username and a specific movement you made with your eyes the password.
- newscracker 9y agoThere are conditions that may make an average person unable to perform the movement, like getting a severe cold or an eye infection that makes an eye water. They may still want to use their phones with minimum inconvenience, instead of resorting to entering a passcode. It may not be possible for some people to configure it well either, and may probably result in eye movements that others may consider weird (imagine rolling your eyes in front of your boss because you wanted to unlock your phone).
- nsxwolf 9y agoThen what's the point of the added complexity? It's a single user device, so just have a password.
- Yizahi 9y agoAppliances like telephones will never have secure passwords (e.g. 32 random symbols), they will have at most short and insecure pins/passwords, 6-10 numbers or letters. But adding on top of that fingerprint/face with 1/10000-1000000 security will make it acceptably secure and still convenient.
- threeseed 9y agoIt's pointless even thinking about IMHO. Someone could just hold a gun to your head or to your partner/child and then it's irrelevant what the security mechanism is. You are going to hand over the credential since your privacy is not more important than your life.
- rodorgas 9y agoit’s not equivalent because there’s very different penalties in hacking someone vs torturing or coercing. So it requires different levels of motivation.
- true_religion 9y agoAnd you can scale hacking to millions of people via computer automation or hiring out of country workers. Scaling kidnapping and torture to millions will attract significantly more government attention.
- acdha 9y agoThis is why you can't meaningfully talk about security without talking about a threat model. People don't talk about safes being broken because advanced tools will eventually open anything because the model assumes the police will show up and so the safe just needs to delay an attacker or require them to bring conspicuous or slow equipment. If your goal is not having the punk who grabs your phone be able to get access to your banking info or personal data, any competent biometric system is a huge win if it means that the average person keeps their device locked rather than unlocked because it's too much trouble. If you're worried about mass surveillance-style attacks, a fingerprint sensor or advanced face scanner is likely better than a password because it's significantly harder to harvest using a camera in a public place. If you're being targeted, all of those trade-offs change, almost completely if state-level resources are involved.