5 ms·
Biometrics are an username, not a password.
by prettyStandard 4y ago
Biometrics are an username, not a password.
- acchow 4y agoExcept on hundreds of millions of iPhones around the world. Apple has shown that the distinction is more nuanced. There are cases where biometric use is legitimate. Signing into an account on a remote server? Probably not. To access the secure enclave on a device that is with you for 100% of your life? Probably fine.
- TacticalCoder 4y ago> To access the secure enclave on a device that is with you for 100% of your life? Probably fine. The notion, however, that a device shall be with you for 100% of your life is not fine at all. It's totally dystopian.
- a_subsystem 4y agoI think op means with you, rather than someone else.
- tinus_hn 4y agoIn a sense it’s two factor authentication with the other factor being the phone itself
- joe_the_user 4y agoThe only "nuance" here is that weak security is "probably fine" in many situations. It should still be acknowledged as weak security. Most houses don't have locks appropriate for bank. Many people do get by with weak passwords in many situations. But acknowledging the weakness of this sort of security is still important because a given person has to consider the threat they face (activists who may face repressive state should what good and what bad security is still) and because new exploit method can appear.
- hansvm 4y agoMost banks don't have locks appropriate for banks.
- jbverschoor 4y agoIt doesn’t work like that.. you always need your password
- guru4consulting 4y agothis is the best one-line explanation I have come across.
- prettyStandard 4y agoAll the people above you are going on and on about things that can't be captured in one line. lol.
- O__________O 4y agoTo me, even that’s a poor comparison, since usernames can change per platform, multiple usernames can be created per user, etc.
- IshKebab 4y agoI wish people would stop saying this because it is clearly wrong. Biometrics have different security properties to both usernames and passwords. They're another category. They aren't the same as usernames. In some cases they are totally appropriate as passwords. For example fingerprints & face recognition for building access. (And before you say "but someone could copy your fingerprint from a glass and wear a prosthetic mask that looks like you!" think about how you would break into "password" style building security - PINs and access cards.)
- lcnPylGDnU4H9OF 4y ago> [Biometrics are] another category. They aren't the same as usernames. If one still finds themself disagreeing with this, consider the difference between what it means to choose a new username and what it means to choose a new face.
- Aardwolf 4y ago> For example fingerprints & face recognition for building access. Huh, why is that fine for building access? Someone can enter your house by just having a copy of your fingerprints or face data?
- IshKebab 4y agoI didn't say all buildings, but in any case someone can enter your house by smashing a window or copying your key or picking the lock or breaking the door or... Don't imagine that all security has to be mathematically perfect, especially in the real world.
- abrookewood 4y agoThis 100%. I really wish this was more widely understood. Imagine having a password that you can not change? What happens when it is compromised? Biometrics should NEVER be used as passwords.
- Nathanba 4y agoimo they shouldn't be used as usernames either. What if I have an accident and burn my fingertips off? Or even worse, I have a facial injury that ruins the username?
- abrookewood 4y agoHadn't thought of that to be honest, but it's a good point.