24 ms·
I've said it many times before. Biometrics should be used as usernames and not as passwords. You should be able to change a password.
by dhmiller 7y ago
I've said it many times before. Biometrics should be used as usernames and not as passwords. You should be able to change a password.
- eganist 7y ago> I've said it many times before. Biometrics should be used as usernames and not as passwords. You should be able to change a password. This guidance isn't unique, though it is certainly accurate. Case in point sourced from 1999 when the differences between identification v. authentication in a biometric context were being hammered out: https://web.archive.org/web/19990508102505/http://biometrics.cse.msu.edu/info.html https://web.archive.org/web/19990508102505/http://biometrics...
- travisjungroth 7y agoYou could use a gut biome sample for a password. It changes slowly over time, so you’ve got rolling built in. And you can do a reset with antibiotics.
- SomeOldThrow 7y agoWhy?
- travisjungroth 7y agoBecause it’s funny imagining taking a stool sample to log into Snapchat.
- noneeeed 7y agoI like that if you eat a healthier and more varied diet you end up with a more complex password.
- DerpyBaby123 7y agoIs this sarcasm? I have accounts I haven't logged into for years, but still need access to. Losing access over time is not a good feature. And a 'reset' with antibiotics doesn't make sense for a bunch of reasons. Also, password diversity is a good thing. I don't want $COMPANY_A's data breach to expose my password to $COMPANY_B
- travisjungroth 7y ago> Is this sarcasm? Yes
- papreclip 7y agoGut biome actually changes pretty rapidly. IIRC some grad student did some kind of sequencing on his stool for a year, the the populations of different strains of bacteria would completely flip when he ate a salad one day and a cheeseburger the next. His name was Lawrence David, but I can't quickly find the writeup that illustrates the point I'm making.
- chocolatebunny 7y agoIt's going to be difficult to keep the sensor completely clean for the next person to use.
- amelius 7y agoI already use it as my signature.
- GhettoMaestro 7y agoOr, we can develop solutions based on existing [proven] cryptographic primitives, with a focus of abstracting authentication / signing / encipherment functionality to an external key or secure-device. Example: iPhone (and Andorid) both have "secure enclaves" where cryptographic keys are stored. However when you step into the basic PC/Linux realm the concept of a secure-device for key storage (TPM) is pretty non-existent outside of corporate players. We can do better, without totally going pie in the sky.
- aflag 7y agoAnd you can share your password with the rest of your family with a fecal microbiota transplant.
- tomp 7y agoWhy? If you can reliably determine that a fingerprint actually belongs to a person... it's not as if I can make my fingerprint mimic yours if I happen to come across a photo of your fingerprint... Of course, simple sensors such as phone fingerprint readers can easily be tricked, but that's an issue with that specific implementation (similarly to how you can sometimes see greasy traces of unlock pattern on phone screens), not of the general idea...
- HenryBemis 7y agoPeople keep forgetting that there are two parts that ought to be (as) secret (as possible) in authentication. This is why major organisations don't allow usernames to be name_surname or nsurname. They pick random usernames. I remember when I was a student my username was a random string with characters and numbers. This makes it more difficult to hack my account (without prior knowledge, shoulder surfing, etc.) since it was highly unlikely you could guess my username and my password.
- JeremyBanks 7y agoIs this any more secure than just making the password longer?
- sigstoat 7y ago> This is why major organisations don't allow usernames to be name_surname or nsurname. They pick random usernames. I remember when I was a student my username was a random string with characters and numbers. sounds more like an artifact of early garbagey email systems than any sound security policy. certainly i've seen nothing of the sort from any organization since a VM/CMS system in the early 90's. > This makes it more difficult to hack my account (without prior knowledge, shoulder surfing, etc.) since it was highly unlikely you could guess my username and my password. this doesn't make any sense. if i generate my passwords by a perfectly reasonable, robust procedure, and then prepend them with the string "password", and disclose this fact publicly, they become no less secure. the username is just like a publicly announced string prepended onto your (hopefully) securely generated password.
- HenryBemis 7y agoAuthentication includes both username and password. In a bank I used to work my username was a random 10 digit number. Very annoying to type all the time. The good thing is, if you want to use my account, good luck guessing both my username and my password. Does that make sense? I do not imply that password should not be complex etc. I am merely pointing out the benefits of having a difficult to guess username.
- Tagbert 7y agoAt least in the iPhone implementation, the finger print is neither user name nor password, it is more like a session key. You have to authenticate with username and password, then you can use your fingerprint (or faceID) to access that session for a multi-day period after which you have to reauthenticate with your password.
- ShteiLoups 7y agoGood explanation of a good implementation. Thanks for bringing my attention to something that's been right in front of me for years but I didn't know about.
- simonebrunozzi 7y agoAbsolutely 100% this. Been saying the same for a long time.