5 ms·
Because in most people’s threat models, it’s still a win. Biometrics do three things: - It greatly reduces the friction of “showing” who you are. - It moves
by FakeComments 8y ago
Because in most people’s threat models, it’s still a win.
Biometrics do three things:
- It greatly reduces the friction of “showing” who you are.
- It moves the mechanism into an “off-main-CPU” chip, while the main CPU just sees limited APIs, and strong crypto which can be rekeyed. You can’t rekey your bio-signature, but this architecture is better in a number of ways.
- It creates a non-digital interaction as part of the auth flow.
I personally subscribe to somewhere between “not a wrench” and “not Mossad” security: most things I’ll tell anyone who will hit me with a $20 wrench, and I’m definitely not in the business of trying to stop Mossad reading my papers.
From that perspective, my security doesn’t need to be better than biometric on almost anything, because that’s good enough to make a wrench (or a warrant) a cheaper option — so I don’t care there are exotic attacks like copying my vein pattern, printing a fake hand, and touching things.
It also stops my main concern from the government: warrantless mass-surveillance. There’s a scaling limit on using fake vein prints to break into things. And the non-digital step forces an actual interaction.
Frequent, low-friction requests also allows for minimizing credential caching and for non-digital requests for confirmation before proceeding. This helps a lot against malware and escalation attacks.
Note: every power cycle and few days, as well as “major” actions, I have to use an actual password — I mind this less precisely because I don’t have to use it as often. So the biometrics are also only a low credential auth when the device is already authenticated through a better mechanism. Is this perfect? No. But again, it’s a numbers game.
So in most people’s usage, biometrics are a huge solution to a tricky set of trade offs, while even in the really secure setting that you’re worried about fake hands, it remains a useful part of multi-factor because fake hands are complicated to make and deploy.
- marcosdumay 8y ago> It creates a non-digital interaction as part of the auth flow. Well, that's not correct. You may have an analogical sensor somewhere to collect the data, but all the data, communication and storage is still digital. You can always bypass the data collection.
- FakeComments 8y agoYou can’t digitally do so, no. You would have to physically interact with the device to change how the circuit operated, or else the only way for the CPU to access the cryptographic data is by allowing a different specialized circuit to unlock a value based on analog input. You can’t meaningfully “bypass” that digitally, unless you already know the secret. So if the auth flow depends on that secret, it can’t bypass the analog sensor feeding in the values to unlock it. The bypasses we see are where you can, eg, attach a debug cable to feed in values without going through the sensor (which is a non-digital interaction). Or bugs in correctly implementing the logic, eg, the crypto chip accidentally exposes information. It’s much the same protection a yubikey left in the side of your laptop provides: someone physically at the device pushed a button, with a cryptographic witness that’s hard to fake.
- pdpi 8y agoOP meant non-digital as in “meatspace interaction”