6 ms·
Your bio-metrics - your face, your voice, your fingerprints are your login, not your password. You cannot change them, you leave this data everywhere and this
by altmind 7y ago
Your bio-metrics - your face, your voice, your fingerprints are your login, not your password.
You cannot change them, you leave this data everywhere and this data can be snooped and replayed easily.
Moreover, this data is singular for a person - its hard to assign yourself multiple roles or have multiple sets of credentials with different permissions or for different services.
We collectively should stop revolutionizing the access control sphere and use boring scheme with passwords, pins and tokens.
- dominator008 7y agoNow that they have a radar on-board. Gestures could be a viable alternative.
- mattmanser 7y agoLike "secret" questions, it's going to take a decade or two before big companies have this sink in and they realize how stupid they are being using them as logins.
- koolba 7y agoAnd before that we’ll have people grimacing or laughing into their phones to make “secret expressions” Actually that’d be a cool idea for an auto wipe feature! If you blink a Morris code SOS it should send out a 911 alert with your location and then permanently lock the phone.
- datapunk 7y agoGesture controls are tricky, only a few applications of them make sense (like hand-to-fist for camera). Something like this would be the modern version of butt dialing 911, back when users would speed dial 911 unintentionally from sitting on their phone.
- keanebean86 7y agoI remember hearing the idea years ago that reasonable security needs these 3 somethings: 1. you know - password 2. you have - device/usb/etc 3. you are - bio-metrics Is this still a thing? It sounds decent to me. Most auth usually uses 1 or 2 from the list but rarely all 3.
- cogman10 7y agobio-metrics is really just not a good security measure, it is an extension of number 2 (You have fingerprints, your face, etc). You'd be in just about the same place if instead of saying "you need biometrics" you said "You need 2 devices". Even number 2 can be done wrong. 2 Doesn't work if the thing you have is a knowledge based thing. 2 only works if in the case that it responds correctly to a stimulus. Think things like RSA.
- dwaite 7y agoBiometrics are not an extension of #2. You really are categorizing authentication factors by their weaknesses: - Knowledge factors can be discovered/guessed and duplicated - Possession factors should protect against guessing and duplication, but can be physically stolen - Inherence factors should protect against guessing, duplication and physical theft, but cannot be replaced Writing down a password doesn't make it an effective physical factor, just like embedding an NFC chip in your arm doesn't make it an effective biometric.
- throwaheyy 7y agoFace print and fingerprint are definitely #2, something you have. Both can be easily copied. #3 would be your DNA sequence perhaps. Similarly, SMS authentication is not #2. The mapping of your phone number to your phone is not something you possess, it is sitting in some phone company system somewhere and it can be changed.
- dllthomas 7y agoSomething you forgot, something you lost, something you were.
- inetknght 7y agohttps://csrc.nist.gov/glossary/term/Multi_Factor-Authentication https://csrc.nist.gov/glossary/term/Multi_Factor-Authenticat... > MFA > Definition(s): > Authentication using two or more different factors to achieve authentication. Factors include: (i) something you know (e.g., password/PIN); (ii) something you have (e.g., cryptographic identification device, token); or (iii) something you are (e.g., biometric). See Authenticator. > Source(s): > NIST SP 800-53 Rev. 4 under Multifactor Authentication
- dwaite 7y agoBiometrics are not a password, as they are not 'something you know'. Neither are they like a username, as the implementations for challenging biometrics often cannot guarantee either uniqueness or lookup capability. They are rather one of the three classes of authentication factors, all of which have fundamental drawbacks. This is why you should always require more than a single class of factor as part of your authentication. For example, mobile devices typically require both physical possession as well as a knowledge or biometric challenge. Leaving fingerprints on your device is why fingerprints aren't the best factor for mobile devices. Captured biometric data being snooped and replayed is why remote biometrics are weaker than biometrics done locally. You can have a Web Authentication authenticator (e.g. FIDO 2 key) act as multiple different credentials, all unlocked with the same biometric. Biometrics being tied to a single account (or an account being tied to a single biometric) is an implementation detail, same as having only a single account per email address on a site is today. A good portion of the revolutionizing is trying to optimize the UX, not authentication. The core fundamentals of authentication have been known for a while, to the point we have government standards such as NIST 800-63b. Of course, some of the revolutionary UX turns out to not implement the fundamentals correctly, because it's the tech industry.
- Spivak 7y agoThis stance is a little silly from tech circles. Something you are is the perfect form of authentication. If you had a guard sitting at a door with only biometric information about the people they’re supposed to let in: faces, fingerprints, DNA samples, voice samples, etc. you could not fool them. Why? Because they can authenticate that the reading is coming from the actual person. This is the revolution. If your phone can with good enough accuracy determine that it’s looking at a real alive attentive human face or a real finger then it’s game over. It’s an auth cred that can literally only be used by you, it can’t be copied, stolen, hacked, phished, and can be totally public while being useless to an attacker because they can’t mint a live human with real matching fingerprint. If you think of biometric auth as “present a picture of your fingerprint” and not “present your actual finger” then of course you arrive at the conclusion that they’re useless as a credential.
- scarejunba 7y agoIn general, I'm on board with what you're saying, but there's a thing with security credentials: it's important for me to allow me to give them away to the guy with a knife. If knife guy comes for me and says "Your phone and password or your life" I can give it to him. It's kind of important that I can or else he'll take my bloody finger with him and body integrity is way more important to me than any amount of my data. Literally, I prefer my fingers attached and you can clear my bank account rather than the alternative.
- Marsymars 7y agoThe solution here seems to be some credentialing solution that can neither be given away voluntarily nor taken by force. Is such a thing possible?
- munk-a 7y agoI disagree, I don't think there is any need for proof of identity to not be voluntarily relinquishable. I think relinquishable credentials are quite useful for a number of delegation related uses - but if they are relinquishable then they need to be expirable as well.
- stordoff 7y agoIn terms of security vs convenience though, I'm not going to enter a decent passphrase into my phone many times per day. A short passcode can trivially be shoulder-surfed, so FaceID is still better security than what I otherwise would be using, even if it's not perfect. The convenience also lets me have more apps individually locked, meaning I can hand an unlocked device to someone knowing they still have somewhat limited access.