4 ms·
Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2
by sunchild 15y ago
Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection?
I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.
- amock 15y agoYou can't change biometrics, so once someone forges your identity they will always have access to anything that requires only biometric identification.
- deleted 15y ago[deleted]
- sunchild 15y agoHow does one forge biometrics? (Notice that I'm not asking how to spoof biometric readers with insecure designs, e.g., the one mythbusters busted). Anyway, this is already the case – fingerprints are used as evidence of criminal liability. If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.
- ars 15y ago> How does one forge biometrics? At the end of the day a finger or an iris is a physical object you can make. Since it's impossible to keep the "key" secret, you can always copy it and make one - how hard you have to work to make it depends on how good the design is, but fundamentally there is no secret and without a secret it's useless for authentication. > If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory. Yes, they can, and sometimes they do. But it's not common enough for police to worry about it.
- sunchild 15y agoBut let's admit that there's no such thing as a secret, really, and it's more about how difficult a thing is to reproduce or reverse engineer. I mean, everything about security is just a big game of "hide the ball" and the question is how many hoops one must jump through to find the ball.
- ars 15y agoOf course there are secrets. What you are trying to say is that system will let you do many attempts till you guess the secret. But with biometrics there are no guesses - you know exactly what it should look like. There is difficulty in implementation certainly, but a basic principle of security is that each increment of difficulty in the securer (like a longer password) should increase the difficulty of the attacker by an order of magnitude. Biometrics does not have this properly.
- sunchild 15y agoThanks for taking the time to respond here and elsewhere. You make some really interesting points, and I understand this topic much better now.
- jpalomaki 15y agoDue to the limitations on mobile devices. Currently they have few hardware buttons, touch screen, microphone and maybe camera. Right now the options are bounded by these limitations. Fingerprint or iris recognition would require additional hardware. Most of the customer probably would not be willing to pay extra for these. Also they might be difficult to implement well on mobile device. And the unlocking must be very easy to use and reliable.
- JoyxBen 15y agoI'm curious too. Japan has had fingerprint scanners on phones for a while. E.g. http://www.nfcrumors.com/11-15-2011/fujitsu-launches-nfc-phones-authentec/ http://www.nfcrumors.com/11-15-2011/fujitsu-launches-nfc-pho... Would be a great feature to have on my iPhone. At least in Apple's case, perhaps the problem is the added cost of the scanner combined with Apple's one-size-fits-all model (as opposed to offering different models, so fingerprint scanners only for those who need the extra security and don't mind the added cost).
- sunchild 15y agoThis is why I asked this question. Fingerprint scanning in Japan is so convenient.
- ars 15y agoBecause biometrics is the least secure and easiest to copy method of security. There are three types: What you know, what you have, and what you are. What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.) What you have is very secure - except that it's possible for it to be lost or stolen, and possibly without the person even realizing (at least not at first). What you are is the least secure - all the detected features can be copied remotely without the person even knowing that someone copied them, and can not be changed once copied. Biometrics sounds very secure - but is actually very very insecure.
- sunchild 15y agoThis is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?
- Djehngo 15y agoLets say someone took your fingerprints off a glass or a light-switch or your car, is there any reasonable way to prevent this? Lets also say that you somehow become aware of them having a copy of your fingerprints and you remember that your phone requires your fingerprints to unlock; what do you do? It's the fact that you can't permanently change your fingerprints nor restrict access to them which make them bad for authentication. Those two qualities also make them good for forensics.
- sunchild 15y agoIsn't that assuming that the system will accept a copy of a fingerprint? Are you telling me that I could easily spoof the fingerprint readers in immigration control simply by applying some kind of copies of another person's fingerprints over my own? Anyway, if copying fingerprints is possible, then they are useless for forensics, contrary to your final point.