2 ms·
Every time biometrics is on HN i end up losing karma cause people disagree with me. I did my PhD on biometrics and while i've transitioned to a different field
by therobot24 5y ago
Every time biometrics is on HN i end up losing karma cause people disagree with me.
I did my PhD on biometrics and while i've transitioned to a different field since graduation, i'd like to think i have some insight into the field (which i still try to follow through journals like IEEE TIFS or conference proceedings from ICB/IJCB). Fundamentally, a biometric is both a _username_ and a _password_ at the same time. It identifies who is logging in (username) while authenticating them (password). There is some literature to address the elephant in the room about 'changing the password' where the key created and stored from the biometric can be changed. But again, fundamentally, the goal should be about how to treat the data like a username/password pair that's just as sensitive as something like a SSN. For law enforcement, i completely agree that it's useful, but for digital access i have yet to see proof that system architects are acknowledging that relationship when thinking about cybersecurity and any ramifications of a breach.
edit: LOL this just hit my RSS feed from HN -- https://news.ycombinator.com/item?id=28314993 https://news.ycombinator.com/item?id=28314993
- natpalmer1776 5y agoI don't think people are having a hard time understanding what biometrics are. I think the issue at hand is that while getting your SSN requires some kind of involvement with you or someone you've given that information to, this particular biometric data can be gathered without your consent or knowledge. I don't want to support the use of biometric data when anyone can grab it and use it for whatever they want by virtue of me existing in "their" society.
- roflc0ptic 5y agoWell. I think the SSN analogy is actually really damning: because of the ubiquity of data leaks and of people asking for our SSN as "identification", we have vanishingly little control over who has access to it. Likewise, if someone is able to get a copy of my "password" by taking a picture of my face, then it's a terrible password, because it ain't private.
- natpalmer1776 5y agoSure, and that is definitely a separate issue that should be addressed. The point of contention is that with data leaks of SSN-esque data, we have the theoretical ability to hold an entity accountable for that violation of privacy and trust. If you're scanning my face with a discreet, pinhole security camera and then sell the data you gather to a 3rd party who then loses that data in a leak, what theoretical recourse do I have when I didn't even know the data had been gathered & subsequently lost in the first place? Edit: removed some text that was poorly thought out and not representative of the point I'm trying to make.
- andrewmcwatters 5y agoI don't think it's specifically an HN thing. You just shouldn't argue with people on the Internet. We all do it, but it's widely a waste of time. Especially when you have domain knowledge to share; everyone is an armchair expert.