3 ms·
But isn't it still a stronger form of authentication than the average password? I would not use it for authentication against the missile launch system, but my
by evfanknitram 8y ago
But isn't it still a stronger form of authentication than the average password?
I would not use it for authentication against the missile launch system, but my ex will probably not chop of my finger to access my Facebook account, nor will random bots trying to access my Gmail account.
- trumped 8y agonot really, because once it gets compromised, you are screwed because you can't really change it.
- Eyght 8y agoMaybe those people with facial tattoos are onto something.
- cornholio 8y agoYet, she can use 50$ kits to lift and scan a fingerprint from your belongings.
- UncleMeat 8y agoShe can, but the threat model here is so amazingly different than traditional threat models for username/pw that it is ridiculous to say that biometrics are usernames. Biometrics are biometrics. They are simply different. They have different threat models and failure modes than passwords. They are neither better nor worse.
- cornholio 8y agoIt's an analogy that captures the essence of the problem framed in a way most people can understand it: with biometrics there is no shared secret, just a high entropy, non-revocable and very public UID. Yes, public in a different model, with a different set of threats, but that's irrelevant to what the analogy is trying to convey. It's a human trait to evaluate and disseminate new concepts though existing concepts. Everything is unique, if you want to refine or disprove the analogy it's not enough to call it wrong repeatedly, you need to accept that specific frame of reference is suggestive to those who chose it, and formulate your arguments from that perspective.
- evfanknitram 8y agoSo it's more expensive than trying to guess which of my cats name I used as password then.