11 ms·
Fingerprints Are Usernames, Not Passwords (2013)
- CyberMonk 12y agoI don't think many (outside of perhaps Apple PR?) have argued that fingerprint security is great, absolutely speaking. Relatively speaking, however, it is great, as many phone owners would otherwise not have any sort of locking security on their devices at all. Yes a fingerprint unlock is hackable, but it's a lot less hackable than your phone being open from the get go.
- chavesn 12y agoExactly. It's going to deter a lot of crimes of opportunity, which I would guess also make up the largest volume of unauthorized device usage.
- DanBC 12y agoSome lenovo thinkpads come with fingerprint readers and trsuted computing modules and more secure BIOS -- they pushed the security of that quite hard.
- th3iedkid 12y agoI used to be employed by a bank that gave me a such a system with TPM and secure BIOS with fingerprint reader.It was a dell one if i remember and used to take quite a lot of time with even simple things like booting.It was a specific project!
- lxgr 12y agoExactly. Touch ID (hopefully!) isn't designed to protect against a sophisticated adversary with time for preparations; it only has to hold out as long as it takes the device owner to realize that their gadget has gone missing. In the case of Apple Pay, they can then immediately disable the payment functionality. Of course, this doesn't help against a sophisticated attacker who is interested in the data on a device; in that case, a secure passphrase would be preferable. Unfortunately, it seems like iOS doesn't allow using different authentication methods for payments and for device unlocking; it would be really nice to be able to use Touch ID for the former, and a passphrase (or even a passphrase AND a fingerprint!) for the latter.
- Tyrannosaurs 12y agoI think Apple are pretty aware of the limitations - they don't accept TouchID on first login after a restart, for the first purchase after a restart, if it's been 48 hours since an unlock or for resets/major config changes. For that you either need the PIN or, if you've opted for more security, the password. Overall it feels that Apple's take is for day to day login it's better than a four digit PIN and it's better than no PIN.
- redwall_hp 12y ago>they don't accept TouchID on first login after a restart That's because the hash of the print is stored on an encrypted volume of some kind, which requires your regular password to decrypt after a cold boot. Once the hash is in memory, the fingerprint can be used instead.
- kosmopolska 12y agoI'm not sure I'm following what you're saying a 100%, but based on this [1] i don't think the fingerprint hash is ever in memory. The TouchID camera sends the fingerprint hash directly to the secure enclave, where it is compared to the one saved there, and then the secure enclave sends a yes or no to memory, at least that's my interpretation 1. http://support.apple.com/kb/HT5949?viewlocale=en_US&locale=en_US http://support.apple.com/kb/HT5949?viewlocale=en_US&locale=e...
- whafro 12y agoI believe he meant "once the [password] hash is in memory"
- mikeash 12y agoIs it because of that, or is it implemented that way because they wanted to ensure that TouchID couldn't be accepted after a fresh restart? I think you may have the causality backwards, since they could have easily stored things in such a way that your fingerprint worked after a fresh reboot if they wanted to.
- M4v3R 12y agoThis article is from 2013. While things didn't change a lot (this years TouchID was broken as well IIRC, though I've heard it got a little better), it's hardly news. Also, I don't think even Apple advertises its fingerprint scanner as a replacement of passwords. It is a replacement of 4-digit PINs, and for that it is far more secure. While members of CCC have the knowledge of lifting a print, most people do not have this knowledge or tools. And if you notice your phone is stolen, you can always log in to icloud.com (with your password, you cannot use TouchID there) and lock down/reset your phone immediately.
- adamlett 12y agoIn the case of Touch ID, please consider that in order to circumvent it, you not only have to be able to fool the Touch ID sensor, you also have to have physical access to the device.
- Raphmedia 12y agoDepends. If you use Touch ID on an app, you could use your own iphone and fool its scanner.
- adamlett 12y agoNo, you couldn't. That's not how Touch ID works. Apps never get access to the fingerprint or have any way to interact with the Touch ID sensor except to ask it to authenticate the owner of the phone, ie. yourself.
- IanCal 12y agoAs with many things, it depends heavily on what you're using it for. Not as pithy for a title though, I suppose. No amount of information entered into a computer fully proves it's you and not someone else. A fingerprint provides some information, as does a password. This sounds like a fairly useless distinction, but hopefully this will make sense: If all we're doing is trying to prove we're us and not someone else, why do we need a username at all? What added bonus is gained from having a completely public bit of information? Well that's because: 1. People are bad at picking passwords, if everyone picked a 2000 character random password and kept it secret we'd not really need anything extra 2. You can't inform people if they've picked the same authentication as someone else, so you prefix it with a per-user unique value which you let people know will be public I don't really see fingerprints as a username or a password. They're just another hint to the system that it's probably you, and you can use any combination of those three depending on what you actually care about. For example: I don't have a username on my phone to unlock it, just a password. I have a username and password for HN. I have a username, password and physical auth device for work-related logins. The latter two are fairly obvious as differences in how important it is that I'm verified to be me, the former is because I mostly want my phone to distinguish between me and my pocket. > But biometrics cannot, and absolutely must not, be used to authenticate an identity. This is incredibly context dependent. My pithy one liner: All absolute statements are flawed.
- icebraining 12y agoI think that's all irrelevant. Passwords can be compromised and must be changeable - that alone makes fingerprints a bad choice.
- adamlett 12y agoA bad choice for what? Your fingerprint can only be used to access a particular device in the case of Touch ID. It is worthless if you don't also have physical access to the device. And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply remote wipe it. To reiterate: Possession of your fingerprint alone does not allow someone to access your bank account or log into your webmail.
- higherpurpose 12y agoHow about the user gets the option to add NFC pairing so strengthen the security of the fingerprint. Once the user sets both up, then he won't be able to login until both are recognized for authentication. It should be hassle free if that NFC pairing comes from a smartwatch or smart-band and he just picks up the phone with that hand. The NFC authentication should happen automatically without thinking about it. The NFC would essentially function as an OTP 2nd factor (or FIDO U2F if that's better) to the fingerprint being the "password".
- ccozan 12y agoWhy not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can use it immediatelly, if you see my finger, there is a long way ( in terms of steps) until you can use the fingerprint attached to it. And btw, I am not defending Apple here.
- raesene4 12y agoyou might want to review some of the literature around bypassing fingerprint readers before making that kind of statement... A large number of readers are easily fooled by copied prints. Also there's the False acceptance/false rejection rate tradeoff to consider. Once of the major issues with biometrics is revocation. If compromised it can be difficult to change!
- brador 12y agoThere's also the glossy fingerprint attracting screen of the iphone. Creating an artificial fingerprint from what you've left on the screen would be non trivial but far from impossible.
- 4ad 12y agoA fingerprint is trivially stolen and duplicated, and once they have physical access to you it's trivial to coerce you to use it too.
- zimpenfish 12y agoPeople have been saying this kind of thing since the 5s debuted - is there any evidence that it's actually happened outside of the fevered imaginations of Whatif Warriors?
- massel 12y ago
- unknownBits 12y agoGood post, this is so true. Fingerprints should only be used as id, if at all. Like 'icebraining' said: Passwords can be compromised and must be changeable.
- ggreer 12y agoHis argument proves too much. If he thinks fingerprints are too insecure to be allowed, then he must think the same of low-entropy passwords. Yet I don't see him advocating that Ubuntu force users to choose high-entropy passwords and rotate them regularly. If he's fine letting users choose a low level of security by picking simple passwords, why not also let them choose to auth with fingerprints? Also, I think he misconstrues the purpose of Touch ID. It's not meant to completely replace passwords. There are three categories of authentication methods: 1. Something you know (password, combination, challenge responses). 2. Something you have (crypto token, phone, key). 3. Something you are (fingerprint, face, DNA, etc). Methods can be combined for added security. All three have advantages and disadvantages. Passwords are typically chosen by users, making them weak. Good crypto tokens are hard to copy, but loss or theft can mean getting locked-out. Biometrics are convenient, but can't be revoked. Also, some activities can make them hard to read.[1] Apple uses all three authentication methods in the iPhone. Touch ID is for basic access. The passcode is for admin-level functionality like erasing or restoring the device. Lastly, physical access to the phone is required to decrypt important data such as Apple Pay's Device Access Numbers. This gives typical, non-technical users a sane combination of security and convenience. If thieves and scammers start copying fingerprints, Apple will change their auth mechanisms. 1. I love Touch ID, but it takes a while to work again after I rock climb or lift weights.
- gldalmaso 12y agoNot disagreeing with you, just going on a tangent and extrapolating the point from the article, the third method group, "something you are" might jump into the "something you have" if it can be extracted or copied from you which might be the case of fingerprints. You are the original source of fingerprint, but you leave copies of it everywhere, so then there are several sources to mimick from and they work just as well on these technologies.
- richmarr 12y ago> Yet I don't see him advocating that Ubuntu force users... He doesn't have to for his point to be valid.
- 12y ago
- shittyanalogy 12y agoWe know, apple knows, everybody knows. Marketing. This feature gives them some great marketing, and it works.
- Karunamon 12y agoSomething I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedicated spy agencies, a fingerprint login strikes a very good balance between usability and security. Consider the alternative - either requiring a standard alphanumeric password on unlock (just about zero usability), or a 4 digit pin code (less usable than the fingerprint while providing identical, maybe slightly less security than that option), or more likely than not, no password of any kind, the whole touch ID thing is a massive jump forward in the security posture of the average iOS user. Most iOS users I know have it enabled simply because it means they don't have to keep re-keying their app store password.
- jrochkind1 12y agoSo this article is a year old, I don't know if Apple has managed to improve things since then. But if it were as easy to get access as the article suggests... I agree you take the right approach by identifying adversaries. And I agree that it's relatively reliable against kids or random people randomly screwing around. And not against governments. But there's a whole bunch in between that. Business competitors? Ex-partners or personal enemies, motivated enough to hire a private detective or similar that can easily do this? I think the line of "reasonable defense against" for this technology is actually probably _just barely_ above random people screwing around with your phone because it was just lying there. And there's a whole lot above that but below national intelligence agency.
- merijnv 12y agoI remember reading the original article on cracking Apple's fingerprint ID and the crackers mentioned that, while definitely crackable, it requires a certain level of sophistication and thus they considered the addition very worthwhile as a way to protect against robbing, etc.
- therobot24 12y ago
- baffledbysmall 12y agoI always get the sense of cognitive dissonance when I read security researches and advocates write about passwords and fingerprints. If you have access to my device, you have access to my physical person, and my physical person will freely give up any password because no secret I have is worth my life. This isn't Hollywood, I'll give up my password with even the hint of physical violence that could maim or otherwise affect my quality of life. Fingerprint readers, as Apple uses them per device backed by a strong high entropy password, are good enough for securing the average persons access to a device. My physical security, something much more dear to me than my secrets, is protected not by keys and tumblers, but by a 1/4 inch of glass that can be cut through in seconds with $5 from the hardware store. Even the key and lock can be circumvented with a rubber mallet and a bump key, or a set of picks. So why use them? Because locks keep honest people honest, and those looking to cause you harm will cause you harm, regardless of what digital security you use.
- Someone1234 12y agoYou cannot say that without linking to this: https://xkcd.com/538/ https://xkcd.com/538/
- astazangasta 12y agoJake Applebaum was detained routinely during border crossings in the early wikileaks days. They (FBI?) demanded he decrypt his hard drive for them. He refused. As far as I know they never managed to get inside. This works, at least some of the time.
- jrochkind1 12y agoI think you take the right approach to true security risk analysis. But there are all sorts of cases you leave out. Someone might very well have access to your device without having access to your physical person. Because your device was lost or stolen. Someone may very well not be willing to threaten you with physical harm, but be willing to hack your device. (Not every adversary is from a Hollywood movie either!) Law enforcement agencies may not be legally allowed to compel you to reveal your password, but legally allowed to hack your device. Etc.
- 4684499 12y agoPasswords are not passwords, they are usernames. It's a part from the combination to identify you, while unlike usernames, it's hidden by design. Fingerprints are like passwords, they can't be easily copied and be reused somewhere else, for now.
- noko 12y agoI came to say essentially the same thing, but not quite. Fingerprints are not like passwords. You can't reset them or change them. Something you know: Username/password Something you have: security key/phone Something you are: fingerprint/facial recognition Those are three factors of authentication. Can anyone think of others?
- clubhi 12y agoI think fingerprint should still require a password after a duration. I'd be fine with using my fingerprint to login if I have recently logged in in the last few hours.
- dschiptsov 12y agoJust no. Since old times fingerprints were used as a unique signature, not an unique id. Unique id could be something as silly as sha256(concatenate(full-name,date-of-birth,place-of-birth)) or just any unique number, like cell phone number. Again, a fingerprint or an image of a retina is a signature or password not an id or username.
- phantom784 12y agoCan a fingerprint even be used as an encryption key? I'd imagine that the reader doesn't generate the exact same data on every scan, and to get a "yes/no" requires seeing if the scanned print is within a certain margin-of-error of a stored print.
- mrcwinn 12y agoEverything about this article is well-intentioned — and wrong. "much as a your email address or username identifies you, perhaps from a list." Your email address or username may identify you, but it also may not. Your fingerprint absolutely identifies you and only you. "For authentication, you need a password or passphrase. Something that can be independently chosen" A password is a secret phrase. We're used to thinking about passwords in terms of strings, but anything secret that I know about would serve the definition. In fact, like a character-based string password, I can even make a copy of my fingerprint password and store it somewhere if I wanted a backup. A fingerprint is both a username and a password. Trying to hold some analogy between Touch ID and traditional username/password combinations doesn't hold and it completely misses the point of the innovation. That's why it's convenient, and skepticism of civil liberties aside, convenience means better security because people will use it.
- patsplat 12y agofingerprints aren't secrets. you leave a copy on everything you touch.
- matt_kantor 12y ago> Your fingerprint absolutely identifies you and only you. The whole point of the article is that this isn't true. Fingerprints are trivial to obtain and copy with sufficient fidelity to beat modern fingerprint readers. - http://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid http://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid - http://www.heise.de/video/artikel/iPhone-5s-Touch-ID-hack-in-detail-1966044.html http://www.heise.de/video/artikel/iPhone-5s-Touch-ID-hack-in... - http://www.discovery.com/tv-shows/mythbusters/mythbusters-database/fingerprint-scanners-unbeatable.htm http://www.discovery.com/tv-shows/mythbusters/mythbusters-da... - http://www.instructables.com/id/How-To-Fool-a-Fingerprint-Security-System-As-Easy-/ http://www.instructables.com/id/How-To-Fool-a-Fingerprint-Se...
- BoppreH 12y agoA fingerprint is not a password because it can't be changed. If a database containing your password is leaked, you can just choose another one. What happens if a database containing your fingerprint is leaked? And fingerprints will leak, as we are using them more and more.
- mikeash 12y agoFingerprints aren't passwords. They also aren't usernames. They're fingerprints, and they have different characteristics from both usernames and passwords. Rather than try to shoehorn fingerprints into our existing terminology, let's look at what fingerprints can do and what implications they provide, and then use them accordingly. The article sadly fails to do this.
- dlwj 12y agoI agree with the below comments. These types of papers are always emphasizing rigor over actual experience. Many types of "100%" security fail because of this disconnect. Forced rotating passwords or long ones with required symbols and number? Most people choose to have easy to remember ones (e.g. pass1, pass2, pass3,) Or it's so difficult to memorize that they'll write it down somewhere nearby. The points are important, but they're directed at consumer products. I wonder how the same person would look at bike-locks...which even with the most expensive locks are only a deterrent given the right tools.
- linuxhansl 12y agoTypically security involves three things: * Something you have (like an access card or badge) * Something you know (like a password) * Something you are (like a fingerprint, iris scan, or a simply a photo) Fingerprints are bit weird as you do in fact leave them around everywhere. Like iris scans I would qualify them as better photographs.
- tigereyeTO 12y agoDustin Kirkland gets it. Simplifying his post, there are 3 reasons biometrics are terrible for authentication: 1. Every piece of biometric data is inherently public. (Fingerprints, facial geometry, hand geometry, even DNA) 2. Biometrics require an error threshold as our bodies are always changing (that's like typing a 20char password and having only 15 of them be correct. That's fine! Let them in anyways with 5 incorrect characters) 3. Key revocation. I can change my passwords and locks if you get a copy of my passwords or keys... but once you have a copy of a biometric identifier I cannot use that again for the rest of my life. Well done, Dustin.
- GhotiFish 12y agoI actually like 2. I wish more things used 2. My keys are plenty strong, but when I mistype a strong key (which is plausible seeing as I can't see what I'm typing) then I'm fine with sacrificing some strength to just accept it. My key is already well beyond practical attack anyway. That said, if you WERE to use something like 2, you'd have to be much more diligent about enforcing good passwords, also you'd have to come up with some kinda scheme that could work with "close enough" and not reveal information about the password.
- dysfunction 12y agoEven assuming 2 is a good idea, I have no idea how that could be implemented. A major desirable property of a good password hashing algorithm is that slightly differing inputs should produce wildly differing hashes, and the login authenticator should only ever know the password hash and not the password itself.
- GhotiFish 12y agoI know. I've being thinking about how to do it, currently it involves having N hashs where you generate them like: echo -n "password" | md5sum 5f4dcc3b5aa765d61d8327deb882cf99 - echo -n "assword" | md5sum 297dbe7699dcfa60609bf9e667e2e4dc - echo -n "pssword" | md5sum 537319a7934aea9825d1af85df588fde - echo -n "pasword" | md5sum 22e5ab5743ea52caf34abcc02c0f161d - echo -n "pasword" | md5sum 22e5ab5743ea52caf34abcc02c0f161d - ect, then check the submitted password by testing it against these hashes by removing characters in the same fashion. Just as an early idea. I think it's a good idea, what if you could encourage users to use stronger passwords by telling them that "the system will forgive near misses, so don't be afraid"?
- specialp 12y agoFingerprints are not bad for local authentication. For instance if phones become more used for payment I would expect my phone to contain a secret key for payment that is unlocked easily which a fingerprint could do. So in order to compromise this they would need to get both my private key and my fingerprint. If my private key were compromised, I could then get another key. The article is right though that fingerprints should not be used as the sole means of auth though for the sheer reason that it cannot be changed.