6 ms·
Fingerprint, iris, and voice are identifiers not authenticators. Their perceived security comes from their perceived scarcity and difficulty in emulating their
by rabbyte 12y ago
Fingerprint, iris, and voice are identifiers not authenticators. Their perceived security comes from their perceived scarcity and difficulty in emulating their presence, barriers that are being removed as technology gets better. In the future the device will know who you are identified as by detecting these markers but you'll still need to prove you are who you are presenting yourself to be.
- jakobegger 12y agoFingerprints are still a better authenticator than a 4 digit passcode in practice. Nothing is infallible, it just needs to be good enough. Biometric security things can be very good at preventing 99% of the problems with 1% of the effort.
- LunaSea 12y agoBiometrics is horrendous as a single point of identification in security systems. Fingerprints and a password, sure, but fingerprints only is the worst idea possible.
- jakobegger 12y agoI disagree. Yes, fingerprints can be faked. But it is much harder to fake a fingerprint than to discover a passcode of a casual user by just watching them type it. I'm absolutely sure that a much smaller percentage of fingerprint protected phones are accessed by unauthorized persons than passcode or password protected phones.
- LunaSea 12y agoActually it's not, if you have the physical device you more or less already cracked the fingerprint scanner. You could also be compromised by your glass in a bar, a handshake, the door handle of your car or your house. Passwords can be changed but you can't change a finger so this sums up why fingerprints are shit.
- jakobegger 12y agoLook at the procedure required to create a fake finger: http://istouchidhackedyet.com http://istouchidhackedyet.com Most importantly, it requires a perfect finger print image. Random smears from your phone screen or a glass won't work. The process is so complicated that only a very small percentage of the population is able to do it; anyone can peek over your shoulder when you unlock your phone (which most people will do dozens or hundreds or hundreds of times per day). Last, remember that you only have limited attempts with your fake finger; in the demonstration video they only show unlocking a freshly trained phone in a controlled setting, they don't actually unlock a phone "in the wild".
- LunaSea 12y agoThe process is very easy, I did it multiple times in high school for a project. Legally, scanners are only allowed to save a certain amount of key points in your fingerprint, not the whole fingerprint. False-positives are thus likely as are fingerprint collisions (like hash collisions). And you still can't modify your finger once it has been hacked a SINGLE time.
- jakobegger 12y agoClearly we seem to have a different idea of what constitutes "easy". I'm not claiming that biometric authentication is a good idea against a targeted attack. But I do think that they offer adequate protection against opportunistic attacks. It prevents random thieves from accessing my data, and it's convenient enough that people actually use it. It will significantly increase security on average. If someone is targeting you specifically, neither a fingerprint nor a (usually short) passcode is adequate protection.
- LunaSea 12y agoBut I can change de passcode and even use a longer passphrase if I feel the need to have a higher security standard.
- EliRivers 12y agoI'm not convinced. To get someone's passcode, I have to watch them type it in; something that happens in few places, at few times, and when they do it they will be aware of the need to not let me shouldersurf. To get someone's fingerprints, I can simply wait until they touch something, or if I don't want to do it that way, I can take a picture of their fingers. I could do this from a distance without them ever knowing. Sure, once I have their passcode, it's a lot easier that making the physical fake fingerprint, but getting a copy of their fingerprint is easy.
- bglazer 12y agoFingerprint as part of 2 Factor Auth is nice. Instead of getting a text and copying it into a text box, I just swipe my finger. It's much more convenient and provides even better security.
- chrismcb 12y agoBiometric security is one of the worst things to happen to security. Personally I hate passwords, but biometrics aren't the answer. How do you revoke the privilege when they are compromised? How do you give the keys to someone else? What happens when there is a life changing event that render your biometrics obsolete? Can you still you a gumi bear to fool a fingerprint reader?