4 ms·
You appear to be suggesting that the real security benefit would come from off-loading the authentication process onto a third party, but we can already do that
by robtoo 15y ago
You appear to be suggesting that the real security benefit would come from off-loading the authentication process onto a third party, but we can already do that with password authentication by using OpenID / Facebook Connect / whatever.
It's not clear how using iris fingerprints rather than passwords really adds anything other than to increase the risk of a false negative, and introducing a third party dependency.
(I do take your point about storing a hash of the iris fingerprint, though. How this would intefere with the matching process is, I guess, outside of both our areas.)
- jbri 15y agoThe real security benefit, I guess, is that people don't need to remember any passwords. The biggest weakness of password schemes is that most people choose weak passwords that they can remember, rather than strong passwords. If you could consistently derive a password from biometric data, then that sidesteps the entire issue (there are no "weak fingerprints"). And if you could consistently derive the key from the biometric data entirely on the client, then you wouldn't even need an authentication provider, instead transparently treating the resulting authentication token as a password.
- robtoo 15y agoIf you use a biometric fingerprint instead of a password you will soon find that passwords can be changed, but biometrics can't. If a password database is compromised, you have a problem, but you can change everyone's passwords. If an iris database is compromised, you really have a problem. Biometrics are also susceptible to replay attacks, where sort-of-alternatives (such as tokens) aren't.
- jbri 15y agoWhich is why, as I mentioned, you don't store the biometrics. You don't even send them to the remote service. Hash + Salt on the client, submit the result. Unique salt for each remote service, and you can change it for a particular remote service if it turns out they do stupid shit with it.