6 ms·
Why bother when you can pick them up from any doorhandle, coffee cup, pen, table surface, or just a photograph at super high-res. Biometrics are form of (dubio
by nonrandomstring 3y ago
Why bother when you can pick them up from any doorhandle, coffee cup,
pen, table surface, or just a photograph at super high-res.
Biometrics are form of (dubious) in-person identification, and their
use for access control belongs in the all-time stupidest ideas in
computing list.
- tommiegannert 3y agoThe nice thing about fingerprints is that if you refuse to give it to an adversary, they'll just cut the finger off. If your fingerprint doesn't work, you're clear. If you refuse to give them your password, there's virtually no limit to the possible extent of the torture. You can't prove that further torture is pointless. /s
- nonrandomstring 3y agoOf course, but people who indulge in torture are not seeking information. They're seeking satisfaction.
- hn_throwaway_99 3y agoI'm pretty sure that people who indulge in torture often want information.
- nonrandomstring 3y agoSure they may want it. But let's talk about Afghanistan and Iraq and how that worked out.
- SushiHippie 3y agohttps://xkcd.com/538/ https://xkcd.com/538/
- nonrandomstring 3y ago{{Alt-Text: Actual Actual Reality: Nobody really cares about his secrets. (Also, I would be hard pressed to find that wrench for $5.)}} If you're browing with javascript on and without text-only, you're missing a lot on the web ;)
- GrinningFool 3y agoYou can get the alt-text from hovering over the image. Even when js is on and text-only is off.
- SushiHippie 3y agoAnd for xkcds you can also find it on https://explainxkcd.com/wiki/index.php/538:_Security https://explainxkcd.com/wiki/index.php/538:_Security
- CRConrad 3y agoAnd on the mobile site (like https://m.xkcd.com/538/ https://m.xkcd.com/538/) the text "alt-text" itself is a clickable link that toggles display of the alt-text on and off. (Not reachable by tab key, though, for some reason.)
- whythre 3y agoActually successfully pulling prints(and getting more than smudgy partials) and then translating those lifted prints into something useable is somewhat time consuming and is not a trivial skill. Like most security measures, biometrics are typically ‘good enough.’
- nonrandomstring 3y ago> is not a trivial skill. True. Today. Tomorrow you will still have the same fingerprints.
- dpig_ 3y agoOh whoops, I cut my thumb and it will never be the same.
- suprjami 3y agoThat isn't how skin works. Surely you've suffered the inconvenience of a small paper cut or kitchen knife nick on your unlocking finger. Even if you cut large enough to create a scar, you'd just re-register the new print and you're (allegedly) vulnerable to this attack again.
- giantg2 3y ago"Why bother when you can pick them up from any doorhandle, coffee cup, pen, table surface, or just a photograph at super high-res." Most of those require being loated in the same area and generally even at a similar time (for high use areas). This would be more like the photo attack where you can be located far away.
- anigbrowl 3y agoBecause you don't always know where your subject is.
- nonrandomstring 3y agoAha, blind fingerprinting (literally) via audio? Yep that's a vector that wasn't on my mind. If you have a database could ID a remote user from swipes. That's a LE win. Fair do. I also discovered (about 2016 while working on audio phone apps) that we could already ID users from their tap patterns, finger length, style etc - but there's no common database of that, so less useful.
- M95D 3y ago> Why bother when you can pick them up from any doorhandle [...] Can you imagine how much it costs to pick fingerprints from millions of users by your method? Sound can be recorded over the internet. This enables web sites to identify users in a very cheap way by simply adding a slider and sound recording on a web page overlay: "Slide to unlock contents".
- nonrandomstring 3y agoAbsolutely. The potential for mass (and covert) gathering of sensitive data via smartphones is astonishing. If an attacker has control of your phone they can now trivially get your voice, face and iris scan to clone. And now your fingerprints. Smartphone security is not going to get better any time in the next decade. All of which lends weight to my argument that biometrics as access control is the single most ignorant idea in the history of computing. I am genuinely hard pressed to think of anything dumber.