OPM now says more than five million fingerprints compromised in breaches
washingtonpost.com
washingtonpost.com
Consider: you can't repudiate your fingerprints. So all the Chinese or Russian authorities need to do is to look for these fingerprints on folks entering the country and they can identify anyone with a US security clearance -- and in particular look for the other characteristics indicative of a CIA or other human intelligence operative. Such as, oh, a set of prints matching someone with a US security clearance attached to an authentic but definitely-not-in-the-same-name passport.
Spies are going to be so much a thing of the past ...
Foreign governments know that people that work at the embassy are often spies and generally the know which ones are spies (used to be the case that the passport officer was almost always a spy).
Not that this won't hurt, but it won't be a death blow. The real danger comes from the fact that handlers, and more importantly their superiors, are vulnerable to blackmail because OPM stored VERY personal information (affairs, drug addictions, etc...).
* CIA does have Non-Official Cover personel (NOC), this will hurt them more. Then again fingerprint readers are not impossible to fool and even before the OPM hack NOCs were facing increasing exposure risk due to biometrics.
> Foreign governments know that people that work at the
> embassy are often spies
That's not true. Perhaps you meant: "there are often people working at the embassy who are spies".The CIA, largely appears to have been shielded from damage, especially for employees who have never worked at any other agency, officials said.
Evidently, CIA has its own, separate OPM-like entity.
I bet some unsung officers had to fight tooth and nail to keep the CIA out of OPM - one would hope that the DCI is properly grateful.
But even beyond that, the Russians and the Chinese already know who works for the CIA officially, just as we know who works for the FSB and the Chinese analog. The people who can hurt you, i.e. actual undercover spies, are not going to be in these databases.
Why do you think we've got spy kids?
I guess it would make it harder for an attacker to manufacture and plant false fingerprints?
That assumes you can get a consistent description of a fingerprint though, or have some scheme for fuzzy match with hashing. Now I want to find a paper on this...
For example, here's a paper from 2005 about a scheme for secure storage of fingerprint templates. http://www.cse.lehigh.edu/prr/Biometrics/Archive/Papers/Tuyl...
I don't know much about this scheme in particular; it was just the first search result for "biometric authentication template". But this shows how people have been working on this topic for a long time now.
While I would not consider it a simple problem, I would think that given enough resources something similar can be made for fingerprints. The problem is that, to my knowledge, nothing like this currently exists and you are not likely to get the needed budget approved for building it, especially in the land of government contracts.
Apparently many of the biggest online services, including MS and Facebook, are using it to scan images uploaded by their users.
The Henry Classification System is one such algorithm and it's been used for more than century[1].
Even in the 1940s and 50s, before digital computers, you could fingerprint a suspect and through a manual application of the algorithm obtain a unique ID ("the same stream of bytes" as you say). You could then do a look-up to see if he had a criminal record.
[1] To be precise, the Henry system uses all ten prints, but single finger classifications also exist. https://en.wikipedia.org/wiki/Henry_Classification_System
Part of non-repudiation is that you've established authenticity absolutely, or as near to absolutely as makes identification reliable.
I worked at a place with biometric hand geometry scanners, same deal pretty much. Technically it was two black boxes, the dumb reader couldn't open doors directly and supposedly stored no data locally in case someone smashed and stole it, or smashed and shorted the control wires (I believe it was RS-485 line level protocol WRT wiring) and a black box inside the secured area that contained our biometric hash data, logs, and a normally closed relay that could toggle and unlock the door when it felt like it.
Anyway if the protocol and connection between the two black boxes could be monitored without breaking the DMCA, then you could verify the box outside does hashing and only 24 bits of data or whatever transport to the other black box that unlocks, rather than entire hand pix. Assuming there's no ATM-skimmer grade camera taped on the scanner recording the geometry of every hand for later abuse.
The nature of security theater or snake oil is apparently unfixable failure modes don't indicate lack of effort or knowledge, they indicate the product sucks.
"HTC stored user fingerprints as image file in unencrypted folder"
http://www.theguardian.com/technology/2015/aug/10/htc-finger...
The terminal listens on telnet or ssh, is easily compromisable, and stores the last fingerprint image (the full picture, not just a hash) as well as last face picture as bmp in /tmp.
You just can't rely on devices being designed such that they are secure.
https://www.eff.org/deeplinks/2015/09/little-fanfare-fbi-ram...