Project Abacus: Google's plan to kill the password via biometric tracking
engadget.com
engadget.com
Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense.
If you trust the authority, it's no big deal. And, I trust Google... today. But do I trust Google tomorrow? I don't yet know tomorrow's Google.
Google yes/maybe. But when you talk to Google who else is involved? Which governments are granted access, with or without google's knowledge? How many 20-something analysts at three-lettered agencies have access? I would like to trust a large publicly-traded company, but the reality today is that they seem in little more control than the individual. We've seen their logos on too many leaked documents.
To quote the boss:
"Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist."
And I'm not sure what your quote adds to the point.
Google is now so large that 'trust' is impossible. Google's attack surface is now so vast, the data so valuable, and cross-talk of personnel with government so common that the likelihood of another undetected breech is too great to ignore. (Same for apple/facebook et al).
It's not as if it took a great feat of imagination to suspect that data flowing between datacenters would be tapped.
Google has been penetrated before, and Google has had to comply with government agencies, and legislation has passed legally shielding Google from complying with orders later found to be unlawful.
Now you're saying that Google can't be penetrated again, and can be trusted with user privacy. Nobody is saying that getting Google to lawfully turn over user privacy, or that penetrating Google is easy. But Google is a massive organization, and it's not surprising that the USA or China can penetrate it -- lawfully and unlawfully.
Even so, security is a road, not a destination. If people want to argue that you should put your data anywhere, I'll buy it. But of the places your data can go, right now I think good is the best steward. And that certainly includes just keeping it yourself.
So, Mr. Owl, I'm afraid that your insurance premiums are going up. Why? Because of that slip on the ice two days ago; our monitoring indicates that you have injured your back. Yes, I know you haven't even seen a doctor yet, but there's a 62% probability that you will be making a large claim shortly, so up with your premiums!
Edit: Downvotes? Prisons and corrections would love this thing for checking convicts identities. They already use fingerprints and mugshots which are cruder biometrics. This is just taking it to the next level.
The bad part is when the account disappears completely and you only have the option to use the biometric data.
So there is a middle ground.
> And, I trust Google... today.
I don't. Todays google is the google I saw coming quite a few years ago and it is as bad as I feared it would be and too large to be able to get around without losing out on valuable participation. Facebook, Microsoft and Apple are a lot easier to avoid than Google.
This is really hard problem for our society. A lot of people say 'nothing to hide', most people don't have a problem with gov. surveillance, only because we live in a semi-democratic countries and a lot of them were not hurt by communistic governments. People in Germany and Poland look differently at such things, they still remember Stasi (Ger) and SB with WRON(Pl). Clearly our governments want more power and information and it's not for our safety, this situation is reminding people that communism can be turned into democracy, and democracy into communism, very quickly.
Also, I imagined "contracts of morality", where corporations are enforced into ethical behavior, if they choose to, so they can be 'trusted' on a longer scale, to be 'good' beyond the common law. I understand it's not easy to define.
For the password, I think it could end like Facebook, anonymity sacrificed. It just gives you an edge. It's a form of tragedy of commons. It gives you an edge until it doesn't. (but I trust it'll be worked out)
Fingerprints are SO EASY to imitate that I taught a group of 10-12 years old to do it successfully with something as simple as a drinking cup, superglue an smartphone and a SLA printer.
You can cheat the Iphone sensor with no problems.
Everything you touch has your fingerprint on it. Secure! Ha!
A fingerprint taken from you works today and works tomorrow and it will work forever.
I prefer passwords or tokens that I could change, that you very much.
What Google wants it to do surveillance on everyone all day long. Their interest are different from ours.
So Verily would be automatically sharing information with Abacus to modulate its user identification, and they feel can just start doing that because it's also an Alphabet company.
This sets off alarm bells in my head. Is this the attitude toward privacy and data isolation at Alphabet/Google? How long until these health records are also shared with Google's advertising department? It tells me that they have no business managing health records at all.
It is a Twitter remark by an ex-Googler who had nothing to do with Abacus and never worked at Verily. That is, some combination of snark and wild-ass speculation.
Taking it down to the device level is just acknowledging the danger of loss or stolen second factors. Further, frameworks like tensorflow may allow the learning model to run directly on your phone, alleviating a lot of the concerns enumerated in this article.
Aaaaand there goes the article's credibility. A pity, because there's a real need for a cogent debate about this panopticon-as-password program.
The weird part is how unnecessary the Mission Impossible stuff is: replacing passwords is a legacy hassle so if you're going to do that there's no reason not to do so with a flexible public key design which doesn't make assumptions about the client hardware and can be patched when it's compromised. (Biometrics might be a fine usability option for the client store)
Instead of using biometric properties as a second factor, I find user-friendly and reusable hardware tokens to be very much preferable. Fortunately Google is also a backer of FIDO U2F, which outlines a standard for hardware tokens the size of a thumb — but unlike your actual meaty appendages, it is replaceable and not quite as bloody to lend to someone in case he or she has a valid reason to access your accounts for you. These work with USB, NFC, and Bluetooth LTE, on any OS, with (soon) any modern browser (currently only Chrome supports it, but Mozilla is committed to implement this technique in Firefox as well), and can be used for an infinite number of services; without the token being identifiable across services.
Succeed in making having one of these tokens on your (physical!) key-chain as common as having the key your front door there, and use the economy of scale to make these tokens as cheap as a happy meal; that would be an acceptable way to beef up security for Joe Sixpack and privacy conscious netizens alike, but leave my body alone.
Furthermore, how high a level of security is needed depends on the situation. Sometimes passwords guard fairly trivial risk exposure, like belonging to some newsgroup to make occasional comments. Hardly any personal info to leak in such cases and simple measures will do just fine.
OTOH my health records needs to be protected far more vigorously, but why would I trust that security to a third party entity like Google? I'd much rather have security for the EHR managed within the EHR system itself, and whatever is adopted, I doubt it would look a whole lot like what's proposed in the article.
Relax. We'll chip anyone without a smart device companion.
I would trust Google's security team over most EHRs. I base this on finding a few sql injection flaws and single DES usage in one I worked on but I don't have broad experience in many EHRs.
I think the problem trusting Google might not lie with their "security team" (they probably have a number of such teams), but rather with privacy policies and guarantees. IOW Google is no doubt capable of providing security, questions arise about enforcing constraints necessary to assure the high level of privacy required by EHR systems.
There's certainly a tradition of academics without security experience pitching that concept but it'd be surprising for it to get very far at Google given how many qualified security people work there and the actual YouTube video makes it sound like this is just being pitched as an alternative phone unlock mechanism.
I don't see anything in there suggesting that it's being pitched as a replacement for either network passwords or two-factor authentication. Has anyone seen another source for anything that leaves the device or is this just a reporter jumping to conclusions?
Basically, OSes should come with a password manager app by default, but users can download their own to replace it which would replace the default one. Much like how you can set your default browser on desktop OSes.
aka optional, local and circumventable with a password if my fingerprint isn't recognized?
I've tried telling google it was me attempting access, but no luck. They still forbid access.