5 ms·
I think security via fingerprint may be a mistake. What happens if someone gets a copy of your fingerprint, what do you do for security at that point? get a new
by mrt0mat0 13y ago
I think security via fingerprint may be a mistake. What happens if someone gets a copy of your fingerprint, what do you do for security at that point? get a new fingerprint? The NFC Ring is a better idea than fingerprint security. i think the idea will fall short of good security quickly. This is all speculation, and I am by no means an expert on security.
- wmf 13y agoMany people have proposed using biometrics to authenticate people to servers, but that's not what Apple is doing. Your fingerprint only authenticates you to your phone. So someone would have to copy your fingerprint and steal your phone to commit fraud. And if your phone is stolen, the fingerprint just needs to secure your phone long enough until you can remotely wipe it.
- smackay 13y agoA stolen phone is likely to be covered in fingerprints. A small piece of sellotape and the thief has your world at their fingertips.
- r00fus 13y agoI'd really like to see how such an exploit would work before losing sleep over it. Fingerprint tech has moved a long way forward in the past few years. If it doesn't work, we don't need to use it.
- iand 13y agoOnce your fingerprint is compromised, you can never rely on it again.
- swamp40 13y agoBut you have ten fingers...
- NTDF 13y agoAll of which have an impression on the phone, that someone could duplicate.
- swamp40 13y agoThe scanner scans subdermally, so it's a little trickier than just lifting fingerprints. I don't deny that it's replicable, just saying that the hacker would probably only have info on one finger.
- aetch 13y agoAll of which that 'someone' would need to pick out of the thousands of smeared / other people's fingerprints on the same phone's surface.
- iand 13y agoSo over the years of use I have to remember which ones have been compromised? Unlocking the iPhone with the ring finger of my off hand defeats the whole point of the convenience this is supposed to bring.
- swamp40 13y agoIt would make for a good conversation starter, though.
- fluidcruft 13y agoWho says you have to actually use your finger? Why not something disposable you keep on your keychain/ring/necklace/tie/earlobe that looks like a finger to the reader?
- minor_nitwit 13y agoI just imagined a world where everyone is carrying around lopped off digits on their keyrings.
- mrt0mat0 13y ago"What the fingerprint sensor may actually deliver is the biggest leap forward in mobile payment technology that we’ve seen since the credit card." This article is saying that though that's all it does now, it will be the new payment process. I just don't see that happening.
- iamshs 13y agoThe sensor is epi-dermal, which means reads underneath the skin, so it does not solely rely on seeing the prints. There is a steel ring, which probably senses capacitance. Will there be exploits? Probably. Are Apple engineers incompetent to think of obvious exploits? I would put my money on NO. In any case, I would like to see the evolution of this tech.
- hornbaker 13y agoThe prefix "epi" means above or on top. Perhaps you're thinking of "hypodermal," which means underneath the skin.
- iamshs 13y agoTrue. It should be sub-dermal, but I do not know the workings of sensor and epidermal was mentioned on Apple's slide.
- ars 13y ago> Will there be exploits? Probably. Not just probably, but definitely and easily. > Are Apple engineers incompetent to think of obvious exploits? I would put my money on NO. They may have thought of them, but they didn't solve them for the very simple reason that it's impossible to solve them. A fingerprint is only secure for causal use (someone picking up your phone), but it's worthless for any more security than that. It's like the face recognition on an android phone - good for causal use, but easily defeated.
- ris 13y ago"Are Apple engineers incompetent to think of obvious exploits? I would put my money on NO." They certainly didn't seem to test whether a phone would get acceptable reception if held in a rather common way.
- stock_toaster 13y agothis likely came out of their purchase of AuthenTec last year.