Goodbye, Password. Banks Opt to Scan Fingers and Faces Instead
nytimes.com
nytimes.com
"What you are" (fingerprints / faces)
"What you have" (a token/card)
"What you know" (a password)
are different things, that you should adds up for improved security, not trade one for the other
http://www.theatlantic.com/technology/archive/2016/05/iphone...
Great, so now they can use those fingerprints to log into every other system that also requires my fingerprint. I guess I'll just have to change it... oh wait
The problem is the scanner/input-device. Unlike a password, the "input" is not always constant in what it gives you. So the resulted "hashed" value is not something you can "hit" again in order to do matching.
Obviously this salt must be shared among all installations of the driver for the results to be consistent.
However the end result is that you are not storing raw minutiae but its salted variant.
Why not do 2 factor authentication and require fingerprint + temperature sensor (has to be the right heat signature?
I guess answer is hardware isn't built that way yet, but I don't see why we can't get enough trust mechanisms that it has to be a real finger.
The result is a password you don't know, but one the app or the bank can leak that you cannot change. Thus, this lowers security.
While the article you linked to points out correctly why they aren't good as passwords, they also aren't good as usernames (though they may be good as an alternative by which a username is looked up, with a fallback to using the real username), since they can be destroyed.
The best system is:
1. User inputs username.
2. Fingerprint is used to confirm username.
3. User inputs password.
(It's the new "get off my lawn!")
For phones, things aren't as advanced, though a bank manager told me that fraud happens more often when online banking is used on the computer, not on the phone. The phone is, in fact, often used as the second factor for online banking in the computer.
If you want to ALLOW me to authenticate with biometrics, fine. But please for the love of security don't FORCE me to do it... And certainly don't make me use it without a second (non-biometric) form of authentication!
I wonder how many of these banks currently have low character limits on their text passwords.
1. Collecting any high-quality selfie I find on the internet
2. Preserving the fingerprints of anyone I "meet"
All in the name of art, of courseI mean both of these things were left in the public domain, no one would mind if I saved them...
Also what do you do if you're in a fire?
- Me in the future
First, most of us need access to our phones (no USB reader) and our computers (no NFC). Yubikey have a combo device, but it costs $50.
Second, they cost way too much given that most of us probably need two or three tokens in case we lose the primary one. $50 is fair enough for employees of large banks, but until they cost under $5 I doubt they'll take off for personal use.
If anyone knows of good value combined USB/NFC tokens, please enlighten all of us.
Passwords suck. But virtually everything else sucks far worse.
Biometrics, as many have already noted, 1) aren't passwords, 2) are usernames, 3) aren't universally present, 4) aren't immutable, 5) retain the problem of having to be stored as data to be verified, 6) aren't replaceable, and 7) can still be stolen, copied, faked, or otherwise misrepresented. At the very least. (Is there a "Myths programmers believe about biometric identifiers" page yet, because there needs to be one?)
Attesting to identity is a long-lived problem, though one that's changed through the ages largely in the scale of how many people it applies to and in what priveleges are granted based on attested identity.
Absent some alternative of a convenient, replaceable, inexpensive, repudiable, and effective portable token of some sort, I don't think the identification problem is ultimately solveable.
Electronic data are fundamentally different from data-on-physical-media. Electronic information tend, as Quinn Norton noted, to deleted or public -- those are the only possible end-states.
(Arguably paper-based records do as well, though the ratio of deleted to public is far higher.)
Electronic information lacks mass, and the attributes of mass. It has no, or very, very little, inertia. It can be transmitted around the globe in a fraction of a second. Multi-gigabyte, approaching terabyte storage, is now possible on fingernail-sized devices.
Data transactions unlike financial ones aren't reversible. It's possible to reverse or undo a financial transaction. The seen cannot be unseen, the heard cannot be unheard. Backing out data disclosures is not possible.
The World Wide Web was created as an information distribution system, specifically for academics. It's been extended far past that, but the fit has quite often been very, very poor.
There's a strong benefit to in-person physical transactions. There's a very high locality cost: getting to, and being present in, a specific location will cost you. Current rates are approximately $0.50 per mile traversed, plus other considerations. Being present in multiple locations simultaneously (or even in brief time) is exceptionally difficult to arrange. Physical reality has high attack costs.
Data presents low attack costs, and increasingly, highly appealing targets.
Devices, systems, users, administrators, vendors, and more, all exhibit exceptionally poor practices.
As one comment on this thread states, "If this replaces passwords, I am quitting this industry to raise chickens in a cave." To which I respond: stay out of my cave.
Because I'm already there.
It's still not as good as the nearly infinite number of potential passwords, but it's not like there's only a single possible fingerprint for you to use.