13 ms·
Fingerprints are usernames, not passwords (2013): http://blog.dustinkirkland.com/2013/10/fingerprints-are-user-names-not.html http://blog.dustinkirkland.com/201
by throwawayReply 8y ago
Fingerprints are usernames, not passwords (2013): http://blog.dustinkirkland.com/2013/10/fingerprints-are-user-names-not.html http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
edit: The original headline before being changed, "Web standard brings password-free sign-ins to virtually any site", and contained a paragraph espousing fingerprints in place of passwords.
- nodesocket 8y agoForgive me ignorance, but wouldn't backends needs to store a "hash" of your fingerprint to validate? This essentially means a single giant password.
- throwawayReply 8y ago1. A fingerprint is something you cannot change, cannot revoke if leaked and cannot be unique across different sites. 2. A fingerprint hash isn't a cryptographic hash because you need to be able to match to nearby matches. A small variation in input needs to have a small variation in the hash so a distance function can be applied. Those are terrible properties for a password.
- andrewstuart2 8y agoIMO, you don't even need any arguments beyond #1. Your fingerprint can't be changed and it's public information. You leave traces/copies of it everywhere you go. Just because it's more difficult to read now doesn't mean that technology won't make lifting and reusing your oily prints trivial someday. Would you create a rubber stamp of your passwords, slather it with oil, and then go around stamping it on everything you own and everywhere you go?
- ng-user 8y agoThis is the current case with SSN's in North America. A unique identifier being treated as a password cannot act as a password.
- dspillett 8y ago> A fingerprint is something you cannot change Many builders/carpenters/etc will tell you this is not true. People who work in abrasive environments sometimes without proper protection often temporarily have no fingerprints as they are "warn off". Many injuries can effectively modify or remove the too, at least temporarily. This makes them bad usernames as well as bad passwords.
- gfo 8y ago> People who work in abrasive environments sometimes without proper protection often temporarily have no fingerprints as they are "warn off". Do they come back in the same form as they previously were?
- marzell 8y agoEither way, this is a terrible argument toward good security. "Oh, someone got a copy of your fingerprint? No problem! There's a belt sander right over there!"
- underbluewaters 8y agoThis is a sore point with the new iphones for me. It happens at least once a week with routine hobby-farm work. I'm really looking forward to getting faceid.
- Tharkun 8y agoInteresting. I wonder if anyone has studied what it would take to render fingerprints useless? Like N minutes/day of sanding with Y grit sandpaper? Additionally, I was under the impression that some fingerprint readers looked at the blood vessels rather than the actual prints. Not sure how that would be affected by abrasion. Perhaps this is a misunderstanding on my end.
- cpeterso 8y agoAn example that can affect many people: my iPhone can't read my fingerprint when I'm sweating at the gym.
- paulcole 8y agoBut you have 10 of them (20 counting toes). Why can't you just cycle through them as needed?
- todd8 8y agoYou can just keep your socks on to protect your login toeprint when not in use.
- volkk 8y agofurthermore, you can combine your fingers/toes in specific unique combinations. it's foolproof
- neolefty 8y agoI like it. Two factors in one! Even allows panic passwords.
- paulie_a 8y ago"Press your toe here" has to be some of the worst ux ever
- estebank 8y agoI see that you haven't used git.
- eafkuor 8y agoAnd let's not forget that some people don't have fingerprints
- emlun 8y agoNo, in webauthn they don't, because the biometric data is never sent to the server. The test is done locally, and the server can trust it (if it cares) by verifying a cryptographic attestation of the authenticator's capabilities. All that's sent to the server is a public key and a private key signature.
- Ajedi32 8y agoThe fingerprint is just to authenticate to your local device. So an attacker with access to your fingerprint can't get at your account without also having your phone (which stores the private key _actually_ used for remote authentication in secure, tamper-resistant hardware).
- Spivak 8y agoThis meme needs to die. Fingerprints are a perfectly fine authentication factor. They are unique enough and require effort to fake. Consider a simple fingerprint USB vault which stores your keys: * Factor 1: You must have physical possession of my vault. * Factor 2: You must be me or have a convincing fake of my fingerprint. Before we even think about a password I've already prevented almost all of the attacks I'm likely to ever encounter against my accounts. * I have made it impossible for someone to casually break into my accounts/device. * I've created enormous distance between myself and remote attackers. * I've eliminated password reuse and contained the effect of data breaches to the service that was breached. * I've made it much more difficult for network operators to carry out MitM attacks since tokens are origin bound and the challenges are real-time with replay protection. Yes in a forum of nerds you can point out that lifting fingerprints is possible but if everyone switched to this simple U2F device the world would be far far more secure. Passwords optional. Then if you're worried about a more sophisticated attackers like corporate espionage or governments you can add a password.
- um_ya 8y agoThe difference is you leave your password everywhere you go. Doesn't matter how unique it is, if I leave a sticky note with a password everywhere I touch, then it's not very good security.
- robotrout 8y agoFingerprints are also not that reliable. Some gun safes that use fingerprints are notorious for opening too easily with wrong fingerprints. On the other end of the spectrum, India is struggling with their fingerprint authentication system, as the system fails to recognize the fingerprints on file. [1] [1] https://scroll.in/article/857274/now-even-the-fingerprints-of-urban-indians-are-failing-during-aadhaar-authentication https://scroll.in/article/857274/now-even-the-fingerprints-o...
- imron 8y ago> The difference is you leave your password everywhere you go. And you can't easily change them.
- specialist 8y agoHow do two parties mutually verify, authenticate each other online? I'm struggling to remember the protocol from a sci-fi novel where two secret agents who (separately) had their minds transferred to new meat sacks reconnected in a new (hostile) environment. I think it had three parts: What you have, what you know, what you are.
- u801e 8y ago> How do two parties mutually verify, authenticate each other online? We verify the server's identity though it's public certificate that's signed by a certificate authority. The server can verify the client's identity via a public client certificate that's signed by an authority the server trusts. It's already possible to do this over a TLS connection.
- specialist 8y agoSorry, I wasn't being clear. If the finger print is what you are, and password is what you know, then what is the "what you have"? Mostly I'm curious if that sci-fi books' "three factor auth" scheme (because I don't know what else to call it) is a feasible model.
- u801e 8y ago> If the finger print is what you are, and password is what you know, then what is the "what you have"? One possible form of "three factor auth" would be to use a passphrase for the private key, the client certificate to connect with the server over TLS, and a username/password login at the application level. The certificate/certificate fingerprint is what you have, the password and passphrase are two things that you know. I don't know what would fit under the "what you are" category though (unless you're considering some sort of biometric based method).
- tialaramex 8y agoTwo humans who know each other can use the Socialist Millionaire's Protocol, this does some fancy mathematics to prove they were both thinking of the same number (for Bill and Ted this would be "69, dude") and of course we can encode any answer e.g. "Sarah", "Washington", "Lakers Game Six" as a large number trivially. The SMP would be weak if you could iterate it many times, but it's for humans, after "Ted" guesses 4, 19, and 22, Bill will stop asking and assume it's not Ted at the far end. A machine can obtain Certificates from a CA which show the CA validated its identity, and use Public Key Cryptography to prove this is its certificate. This is how HTTPS works when you connect to a remote web site, but it can be mutually authenticated too, that's just not how web browsers use it.