4 ms·
I've read several articles and discussions about the topic, but I'm still a little fuzzy on where biometrics fit in the context of authentication: username, pas
by SloopJon 7y ago
I've read several articles and discussions about the topic, but I'm still a little fuzzy on where biometrics fit in the context of authentication: username, password, just another factor? What is the role of the fingerprint in the case of this key?
- kovek 7y ago"Something I know, something I have, something I am". I think "something I am" is difficult to achieve.
- jolmg 7y agoSomething I know: The PIN (password) Something I have: The Yubikey (hardware key) Something I am: The fingerprint (biometrics) So this Yubikey enables 3FA.
- xaduha 7y agoPINs and passwords are not the same though, PINs are for devices and usually not intended to be sent anywhere else, unlike passwords. PINs are also protected from bruteforce, that's why they are usually just 4 numbers.
- jolmg 7y agogpg and the OpenPGP card spec calls it PIN, but it's not restricted to numbers and can be quite long, though I don't remember the limit. Passwords are normally also protected from bruteforce. Many places lock you out for some time after many failed attempts. The "PINs are for devices" seems kind of arbitrary.
- xaduha 7y agoYet nobody uses 4 digit passwords. https://en.wikipedia.org/wiki/Personal_identification_number https://en.wikipedia.org/wiki/Personal_identification_number
- jolmg 7y agoBut they can if they want. Fundamentally, I think PINs in the traditional sense are just passwords with a tradition of particular password requirements. You can also mention passphrases and say how they're different from passwords, but you can put passwords in fields labeled passphrases and passphrases in fields labeled passwords. They're all functionally the same. EDIT: From the Password Wikipedia article[1] > In general, a password is an arbitrary string of characters including letters, digits, or other symbols. If the permissible characters are constrained to be numeric, the corresponding secret is sometimes called a personal identification number (PIN). [1] https://en.wikipedia.org/wiki/Password https://en.wikipedia.org/wiki/Password
- xaduha 7y agoNot sending PIN over the network is the most important distinction between a proper PIN and a password. https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-why-pin-is-better-than-password https://docs.microsoft.com/en-us/windows/security/identity-p...
- jolmg 7y agoFrom the Wikipedia article you shared: > In common usage, PINs are used in [...] internet transactions or to log into a restricted website. EDIT: Also, the IRS uses PINs online[1]: > Your IP PIN will be displayed to you online once we verify your identity. A new IP PIN is generated for each filing season and can be retrieved starting in mid-January of each year by logging into the account you create. They even allow you to enter it on paper[2]: > Paper Return: [...] Enter your IP PIN(s) as applicable in the boxes marked "Identity Protection PIN" in signature area of the return. EDIT 2: There are also many employee time-clocks that use PINs to authenticate the employees, like this one[3]. You can connect to them through the network to export some nifty reports that includes everyone's PIN, like this one[4]. I'm sure use of PINs is also common with ERPs and POS systems (to authenticate a cashier supervisor authorizing some action), and those are also networked. EDIT 3: On the Microsoft link you provided, they're talking specifically about the PINs in Windows 10. I wouldn't take that page as talking about all PINs in general. [1] https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin https://www.irs.gov/identity-theft-fraud-scams/get-an-identi... [2] https://www.irs.gov/identity-theft-fraud-scams/frequently-asked-questions-about-the-identity-protection-personal-identification-number-ip-pin#q10 https://www.irs.gov/identity-theft-fraud-scams/frequently-as... [3] https://www.alliedtime.com/Compumatic-XLS-21-Badge-Time-Clock-System-p/compumatic-xls21.htm https://www.alliedtime.com/Compumatic-XLS-21-Badge-Time-Cloc... [4] https://www.alliedtime.com/v/vspfiles/assets/images/pdfs/compumatic_reports.pdf https://www.alliedtime.com/v/vspfiles/assets/images/pdfs/com...
- Uehreka 7y agoI think a lot of people are questioning whether “something I am” is even a good target to aim for at all. As other folks in these comments have mentioned: if your fingerprints/retinas/DNA are compromised, you can’t change them the way you can with a password.
- roblabla 7y agoThat's why you combine them. Nobody is saying auth should purely be based on biometric. It's all three: Something I know, AND something I have, AND something I am. If your DNA is compromised, you still have the thing you know and the thing you have to keep you secure.
- CaptainMarvel 7y agoPlenty of people are saying it should be purely biometric. For example, iPhones. (Though they do it better than the vast majority of implementations!)
- roblabla 7y agoBy nobody, I meant here in this article. Also, just a nit, iPhones aren't purely biometric. You have to input your pin after reboot or a long period of inactivity. I'll agree it's still a bit too close to being a password for comfort though.
- bradknowles 7y agoSo, they make you write the password down. Then they take the Yubikey. Then they take your eyeballs and your fingers. I'm not so sure I want to encourage them to do #3.
- roblabla 7y agoI mean, if someone is forcing me to login at gunpoint, I'll gladly oblige - no need for them to gouge my eye out. This is not the threat model being used here. This feature is meant to protect you when you forget your yubikey on your laptop while on lunch break, allowing any co-worker from logging in/using the GPG keys stored within.
- ehsankia 7y agoOther factor, this is 3rd factor auth.