5 ms·
> user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity Citation
by philipodonnell 8y ago
> user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity
Citation needed? A fingerprint can absolutely be used to generate a hash that functions as a pointer to primary keys.
- xoa 8y agoAre you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? That you are going to just refer to other people (whether IRL or online) by "fingerprint"? That people choose their fingerprints based on what they think will be a good one? That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? Because all of those apply to user IDs.
- opless 8y agoNot trolling, but pouring more oil on the fire... TLDR yes, biometrics are the closest thing to a user ID > Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention. > That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but computers might as well do, much as you identify someone by their face. You might refer to someone by their public key fingerprint too (also similarly non-collision resistant) > That people choose their fingerprints based on what they think will be a good one? People rarely choose their names, nicknames, or usernames. Why is choice an issue here? > That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? People find it difficult to arbitrarily change their face, most are reluctant to change their given names - and indeed there's significant pressure from 'the system' to make it difficult for you, and also what about the many who find it annoying when their preferred username is unavailable, etc. I can't see what your point is here? > Because all of those apply to user IDs. A user id, isn't a primary key in the real world - only when it comes to a particular computer system. Finally your fingerprints do change over time, though not necessarily in a manner which will confuse current matching techniques
- xoa 8y ago>TLDR yes, biometrics are the closest thing to a user ID No, tl;dr stop trying to cram things you don't understand into random other categories you do and make analogies that actively cloud understanding. They simply have nothing to do with each other. Yet again, there are three basic classes of common authentication factors: something you know, something you have, and something you are. Biometrics belong to the "something you are" class. All auth factors impose an energy cost on an attacker trying to successfully utilize them, with that cost varying depending on the threat scenario. They also all impose costs on the user to varying degrees, depending on the specifics of how they are implemented and use case. Good security involves finding usable balances between value of information being defended to user cost of defending it and the time/resource attack cost. Names/user IDs/handles are simply symbols, and public information, that humans use as pointers to other things. Often the whole point of authentication is explicitly to authenticate a user ID, to provide a positive assertion that yes the claimed user ID does maintain correlation to what it is pointing to. >A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention. Uh, no. Most polities have processes by which you may change the name which the State refers to you by ("legal name") to whatever (non-socially disruptive) one you wish. And even beyond that you are claiming ("everyone refers to you by it[given name]") to have never heard of the concept of "nicknames"? Wow. >People rarely choose their names, nicknames, or usernames. OK so "nickname" isn't an entirely alien concept to you despite slipping your mind the previous paragraph. But on the contrary people commonly choose their handles. Or was "opless" assigned to you by your parents or manager? All the rest of what you have to say is just bunk too. Every single thing a computer "knows" about a UID is just a string in a database. Policies or individual reluctance to change it has nothing to do with difficulty of doing so or policies for disclosure.
- tinus_hn 8y agoA fingerprint cannot be used as a hash to encrypt keys. All you can do is store some data and compare the fingerprint to see if there are enough matches. That is why secure fingerprint systems always involve some ‘secure’ hardware that stores and compares the fingerprint to the stored data and then releases some key. Systems that try to do this in software are always trivially circumvented because you can just change the software to allow ‘not enough matches’ instead of ‘enough matches’. The key is necessarily in the device and software can’t protect it.