3 ms·
Is it really so hard to believe that people who use biometric authentication might want to be particular about their security and privacy? Lots of folks who are
by notRobot 2y ago
Is it really so hard to believe that people who use biometric authentication might want to be particular about their security and privacy? Lots of folks who aren't tech super users care about that stuff.
- autoexec 2y agoSomeone who might want to be particular about their security and privacy could still use biometric authentication without knowing that it weakens both, but presumably someone "very security or privacy focused" would be aware that using biometric authentication exposes them to more risks and would avoid it for that reason.
- JohnFen 2y agoWhether or not biometric authentication exposes you to more risk depends on what your threat profile looks like. If it includes governmental action, then yes, biometrics are a weak spot. On the other hand, if your risk profile includes the government, then you should be taking much more extreme steps to protect yourself than a lockscreen, and using biometrics would really impact things much. If the cops unlock your phone (if you're comfortable taking the inherent security risk of even having a phone), they would still not find anything important that isn't encrypted separately.
- autoexec 2y ago> Whether or not biometric authentication exposes you to more risk depends on what your threat profile looks like. If it includes governmental action, then yes, biometrics are a weak spot. Even if it doesn't include the government biometrics still leave you much more vulnerable. You leave your biometric information everywhere you go. Your face is easily found in photographs. Fingerprints are left on everything you touch. Your voice is easily recorded and deepfaked. Attacks on biometric authentication are well documented and while some seem pretty impressive (https://www.bleepingcomputer.com/news/security/scientists-extract-fingerprints-from-photos-taken-from-up-to-three-meters-away/ https://www.bleepingcomputer.com/news/security/scientists-ex...) others are embarrassingly unsophisticated (https://www.marketwatch.com/story/heres-how-easily-hackers-can-copy-your-fingerprints-2017-05-25 https://www.marketwatch.com/story/heres-how-easily-hackers-c...). Unlike passwords your fingerprints can't be changed following a compromise either. I can also set a unique password for every device/service I use. Even if you managed to guess my hackernews password, that password would be useless to you for anything else. The face/voice/fingerprint that unlocks one device will forever be identical to the one that unlocks everything else someone has or will secure with it. biometrics sacrifice huge amounts of security for the sake of convenience and an appearance of being "high tech" and "fancy".
- JohnFen 2y agoyeah, all good points. I was just thinking that the average person's risk is going to be either casual snooping by people they know, or common theft for resale. In both of those cases, the weaknesses that biometrics present don't strike me as being a huge problem. They do exist, though.
- jessekv 2y agoBiometrics are effective at preventing snooping of your password. Before biometrics, I would eventually know everyone in my home's pin unless I made a conscious effort to always look away each time they unlocked their phone. I'd be cautious to use anything but biometrics on a crowded train.