30 ms·
[edit for clarity] As someone who doesn’t specialize in security, one claim that has stood out to me for not using fingerprints is that you can't run bcrypt (o
by webel0 5y ago
[edit for clarity]
As someone who doesn’t specialize in security, one claim that has stood out to me for not using fingerprints is that you can't run bcrypt (or some other salting algorithm) on fingerprints [1].
I don’t see any discussion of that here thus far. Is that still the case? I feel like I would have heard about developments in this area if something had changed. But perhaps I've always misunderstood the criticism?
[1] https://www.rsaweb.co.za/fingerprint-security-fingerprints-are-not-safe/ https://www.rsaweb.co.za/fingerprint-security-fingerprints-a...
- tantalor 5y agoSays who?
- webel0 5y agoThanks for your comment. I have updated mine to include a reference. In short, I'm thinking about how fingerprints are stored.
- cool_scatter 5y agoFingerprints are stored as data, and data is hashable. As someone who doesn't know the ins and outs of fingerprint readers, that sounds ludicrous. I also don't see why it would need to be hashed, however.
- webel0 5y agoThanks for your comment. I have updated my comment to try to be more precise.