Fingerprints are Usernames, not Passwords (2013)
blog.dustinkirkland.com
blog.dustinkirkland.com
I think that fingerprints are fine for low security things, but I would never use it as authentication for anything that touches my bank account.
Biometrics, including finger prints, are human friendly, and that instantly makes them worthy of consideration as part of a system. Touch ID or the like can enable a person to use an extremely strong password that would otherwise be completely uneconomic, and the combination of a limited time, extremely fast biometric shortcut with a very strong core password, particularly if combined with coercion code use (only possible for now via jailbreak but something Apple or another manufacturer could and should implement at all levels), remote lockout (long available everywhere), etc., may be significantly better then merely a PIN code alone.
Threat models cannot be ignored for a security system, because they define the system. The greatest threat most people face are remote attacks, with the next greatest being scatter shots of various sorts (in other words, somebody was looking to steal or attack a device, not your device in particular). Persistent targeted threats are an entirely different situation and a password alone is not even necessarily better in a mobile scenario, because in a mobile scenario you often do not have even a modicum of control over your environment. A fingerprint might be possible to lift and use as the author links, but a PIN code or password can be taken, often even more easily, via shoulder surfing or cameras. In fact in the modern first world environment bird's eye view (ceiling/pole-mounted etc) surveillance cameras are becoming ever more ubiquitous and ever higher resolution. Are people going to seriously suggest nobody use their mobile device anywhere with a surveillance system? More and more, how will you even know that? Taking advantage of the ever increasing cost/performance/size/power improvements powered by the smartphone revolution, retailers are interested in ever more camera use not for thieves but for metrics, to figure out exactly what shoppers are doing down to precisely what they're looking at and for how long. The retailers of course have no interest in your phone info, and in fact an interest in not making people worried about that sort of thing. But if we're going to consider someone going to the specific trouble to rapidly spoof biometric identity for a specific device, then it's necessary to consider that once the cameras exist at all access for non-intended purposes may be just a hack or national-security-directive away.
Basically, it's frustrating to still see people pointing to "somebody broke into this security system!" as if it means anything without thinking about the time/resource cost and threat model. Biometrics absolutely have a role to play in general authentication for the general population for the foreseeable future. There are paths for improvement there just as in other areas, perhaps culminating in fusion technologies like security authentication implants wired into our brains someday, but we'll need functional authentication to get us that far and passwords alone do not cut for most of the population as currently implemented.
The key point though is that security tokens must be changeable/revocable and and bio-metric data is not-so-much.
If a password is leaked, you need to revoke it in order to mitigate the potential damage. If a fingerprint is leaked, do you need to do the same? No, because the security of the fingerprint is not tied to its secrecy. Fingerprints are not secret. They are just hard to reproduce.
Trying to equate fingerprints to passwords or usernames will inevitably result in absurd comparisons because fingerprints are neither of these things. They are an entirely different type of entity.
Fun fact: fingerprint access to banking info on your phone constitutes two factor authentication. Factor one is the fingerprint (something you are). Factor two is the phone containing the already-authenticated app (something you have). Arguably this is a more secure way to access your bank than the typical one factor username+password you would use online.
I think this is the key point. If fingerprints were like public-key authentication mechanisms, they'd be fantastic. If it was mathematically impossible or even just very difficult to fake them just by intercepting previous authentications, that would be incredibly useful.
That's not the case though.
They're easily reproduced in moments using putty[0] or play-doh[1]. Or duplicated using household materials, even from a fingerprint collected from the targeted iOS device itself.[2] Some teams have found difficulty using some of these methods against a MS fingerprint scanner, but still found success using a toy wax kit from Crayola.[3]
But the general point about revocation is this: you should imagine, whenever designing a security system, "what's my fallback when this fails?" Biometrics can fail for lots of reasons, not only due to adversaries.[4] You need to have some idea of how to recover from those failures beyond just insisting that those failures don't happen or are unlikely.
Revocation is a handy fallback in those situations for a lot of systems. It's so common that people probably wrongfully assume it's the only way to recover. Fingerprints can't offer revocation, but they may have other fallbacks. Maybe you have a guard checking photo IDs if a scanner doesn't work for entry to a facility.
Scanners for devices might need to simply fail to require usernames and passwords for some users after they've been compromised. That could still offer convenience for other users, but over time, fewer and fewer users would get that benefit.
Or maybe fingerprints are just not designed to be that secure, and maybe that's ok. Anyone can get through the standard household locks in seconds with about 30 minutes max of research on youtube. They're not perfect security and not intended to be, they just put a small barrier (mostly social) to prevent the most nuisance level entries.[5]
[0] http://www.puttyworld.com/thinputdeffi.html
[1] https://secure.marketwatch.com/story/this-company-hacked-an-...
[2] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren.en
[3] http://www2.washjeff.edu/users/ahollandminkley/Biometric/ind...
[4] See Yager and Dunstone on the Biometric Menagerie for an interesting classification system for the wide variety of failure cases you have to tune any biometric system against.
[5] If you want more about this philosophy / interpretation of locks and security, or even if you don't, there are fewer better ways to spend an hour than by listening to the brilliant Schuyler Towne at RVAsec on the history and social function of locks and lock-making. No seriously, it's amazing. https://www.youtube.com/watch?v=3nROJz_UNQY
EDIT: moderated my views in the last two paras, sorry for any whiplash.
Second, and more important, we need to stop pretending that passwords actually work well when we have these sorts of conversations. The reality is that most people reuse the same passwords everywhere and when they are forced to use secure/unique passwords they cope by doing things like writing them down on sticky notes attached to their monitors. The reality is that most people are probably using a compromised password for their bank access because they used the same password on a dozen sites that have been compromised. When we compare fingerprint security to passwords, we need to stop comparing it to the mythical unique passphrase because essentially no one is using that.
I'll also point out that copying someone's fingerprint when they cooperate by taking a clay mold is quite different from lifting a fingerprint off, e.g., a glass. But nonetheless, I do not dispute that it is quite feasible to clone fingerprints.
The next step is revocation and reissuing credentials.
You cannot revoke someone's fingerprints. Or at least they'll probably object once you fire up the blowtorch.
Are you familiar with the biometric menagerie? http://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=4...
Sorry that's gated, but tl;dr, there are marginal cases in biometric systems where some individual's data doesn't work well, or messes with the recognition/exclusion of others.
There is certainly such a thing as homomorphic encryption (https://en.wikipedia.org/wiki/Homomorphic_encryption), which allows one to perform transformations on encrypted text without being able to decrypt it. As long as one of the transformations that can be performed is a measure of closeness (which is certainly the case for fully homomorphic encryption (https://en.wikipedia.org/wiki/Homomorphic_encryption#Fully_h... )), and as long as you know the ciphertext of the possible numerical responses, then you can read off closeness without being able to decrypt the hash.
The emphasised bit is a drawback, but it demonstrates the theoretical possibility; and, although I don't know of an implementation, nor do I see anything inherently contradictory about a (non-reversible) system designed intentionally to reveal closeness information.
The stronger you make the "closeness" guarantee, the weaker the function becomes to this kind of thing.
Look folks, maybe as part of some second or third factor it might be okay...but you still need a password.
I'm rather surprised. To me, this seemed like a longstanding given (in this community).
No, you didn't. There is nothing in your history regarding this subject, except for this post.
Heck, I've done it, since it's probably not the best to create a digital repository of all my opinions!
https://news.ycombinator.com/item?id=11440951
https://news.ycombinator.com/item?id=11377425
I mean if you are going to accuse me of being a liar, you may want to at least check to see if I mentioned having other accounts first.
Also, you may want to consider the OP was posted in 2013 to HN and I've said publicly I've been around on and off since 2010.
(I guess if you have a human watch someone use a tamper resistant fingerprint reader you have accomplished some degree of authentication)
Repeatable? (Not typo-hunting; I'm honestly not sure.)
"I presume your handprint will open this door whether you are conscious or not."
Soon enough computers will be able to check every possibility for passwords as big as we can remember them. With good algorithms predicting what is likely to be a valid password, maybe they already can.
Even though I agree fingerprints aren't a good solution, passwords aren't either. Any ideas?
Maybe we could have some kind of card that would have big keys stored on it.
EDIT: Fixed missing word
I do this on a regular basis because I have an entire sentence as my LastPass passphrase.
Usually.
I should never become a spy, my security technique is laughable.
You could probably make a list of 256 common, short words that are distinguished by their first two letters[1], but to encode 128 bits of entropy, you'd need 19 words, (or 16 if you managed to get use 512 words). Even if you picked only the first two letters, that's best case 32 characters. It's a lot to type blind, it's a lot to remember, it's complicated to cycle the phrase.
So it's better to not have to remember the password - use a password manager. Or, if you could somehow avoid the possibility of off-line attack, and guarantee solid rate-limiting -- much less entropy might be needed. A 4-digit pin is probably on the low side (consider that on a site with ~100.000 users, if you tried any set of three pins, you'd probably compromise many accounts, assuming uniform distribution of pins).
Another way, is to continue using a shared secret, but prove knowledge in a different way: eg using TOTP[2]. On the other hand, TOTP shares some of the disadvantages of unsalted passwords: the secrets are stored in plain text both on your one-time token generator (your insecure smartphone), and on the server. On the other hand, they're harder for most users to re-use than passwords are (users typically don't know the secret used to generate one-time passwords).
But all these have another problem: how to you protect your secrets? You could use full disk encryption... protected by ... a password?
Still, the idea of using a fingerprint for authentication, especially on a device filled with your fingerprints seems like a pretty bad idea. Never mind the fact that once compromised they can never be changed.
As for your last point, I do think the combination of something like a yubikey neo[3] along with NFC is probably the sweetspot for practical security right now. You can use it to unlock your smartphone, and your computer.
[1] (26^2=512, but not all combinations are common, fitting 256 should probably be possible, even if the more common combination of vowel+consonant is only ~6*20=120. Possibly in combinations with the numbers 1..99)
[2] https://en.wikipedia.org/wiki/Time-based_One-time_Password_A...
[3] https://www.yubico.com/products/yubikey-hardware/yubikey-neo...