Fingerprints are usernames, not passwords (2013)
blog.dustinkirkland.com
blog.dustinkirkland.com
This is a much more pragmatic take on it by Troy Hunt, the person behind “Have I been pwned?”: https://www.troyhunt.com/face-id-touch-id-pins-no-id-and-pra...
> The first point I'll make here as I begin talking about the 3 main security constructs available is that they're all differently secure.
And agree that Troy's description is best as it takes us away from unhelpful metaphors.
Implementation matters more than what the sensor is authing with.
Like, say, middle - index - ring.
It would be doubly unique.
If you believe your fingerprint data has been compromised, can you change your fingerprint data?
It's not too difficult to get access to the full 50000-odd combinations (see https://support.apple.com/en-us/HT204587 for where that number comes from) Apple hardware can identify with a little work.
https://www.theguardian.com/technology/2014/dec/30/hacker-fa...
I'm usually let them tell their tale (out of my room, of course), ask a lot of questions, nod with them happily, and in the end I say thanks, but I'm sorry, I don't disclose my info, full stop. Their butthurt is sometimes too cool to watch without popcorn.
If I am who I say I am I should be able to answer all three without much thinking and answer naturally to my name.
[1]: http://www.theregister.co.uk/2015/08/10/htc_caught_storing_f...
1) lifted it off some surface. 2) got the right fingerprint when they did it 3) modeled a fake fingerprint well enough that it would fool touchID 4) Was able to get access to your touchID device while you weren't aware or unable to stop them
Most experts recommend that you instead use a pin-code of at least 6 numbers, or a password of at least 12 random characters using at least one number, and at one punctuation mark. In that case the attacker's algorithm changes to
1) Check for posted note containing password on computer monitor, or 2) Check purse or wallet for posted note containing passcode
Yep. I can use another finger. If all 10 have been compromised you probably have bigger issues.
Or you just turn it off.
biometrics make poor passwords.
Because security that people use is >> security people won't use
You can't change them, therefor they make poor secrets.
And the hassle of entering even a 4 digit numeric PIN was what Apple was trying to overcome.
Too many people were leaving their phones completely unlocked all the time.
2. Using passwords as a security measure increases the likelihood that a malicious actor will beat them out of you with a five-dollar wrench (and this does not mean that passwords are a bad idea).
Cutting off someones finger to access their phone is like using high explosives to blow up a door you can easily kick open. Criminals actually don't want to get caught.
So I'm pretty confident now that this argument is moot by now.
Yet we still don't have enough mileage to determine if face peeling will be a more likely issue with iPhoneX. But I could bet that "face offing" relatively is not more likely than finger cutting...
The psychological detachment required to cut off a finger significantly lowers the number of criminals that will unlock your phone against your will.
When the bolt cutters come out they are in. Sue me.
username • password
public • private
detachable • non-detachable
unique • arbitrary
A name has to be unique. But it can simultaneously be used as a password if it is impossible to detach (copy) it and associate with another thing. One way to do it is to simply hide it like private keys and normal passwords but in this case it cannot be used as a name. An alternative approach is to make it difficult to copy/reproduce (similar to normal car or house keys). In the case of fingerprints, they can well be used as a password (in addition to its role as a name) until it is impossible to create artificial fingers and attach them to other persons.[1] - https://www.nytimes.com/2017/04/10/technology/fingerprint-se...
Security design must take into account usability. Fingerprints (and now faces) make it easy to use stronger passcodes. If you don’t use biometrics, people use weak passcodes. That’s clearly a worse outcome.
Sure, it’s even stronger to not use biometrics and enter a strong high entropy passcode every time you want to unlock your phone. But to actually advise something like that as a better approach in a consumer device than TouchID is simply to advocate a guaranteed worse security outcome. Maybe you “cover your ass” as a security acolyte and blame the compromised user for not following your stringent prescriptions, but that’s not owning the outcome. You have to consider usability.
For this simple, pragmatic reason alone, a pass code will ALWAYS, 100% of the time, beat out any supposed biometric security advantage.
Usability only goes so far, otherwise we wouldn't even have doors on our houses.
Second, you’re missing the point. Passcodes do not “always 100% of the time beat out” biometrics if the passcodes are weak or nonexistent. Which was the case prior to TouchID.
[1] https://www.theverge.com/2017/8/17/16161758/ios-11-touch-id-...
And to use your door metaphor, do we install doors to keep our the police? Is that really the average person’s concern?
You make it sound like everyone is a drug trafficker or some kind of mobster. I don’t lock my doors to keep out the police; I lock them to keep out criminals that want to steal my stuff.
Biometrics are used as the key that unlocks a device (or app or asset within the device). And like the house they require physical proximity. And, yes, just like the house key there's a decent chance that someone who lives near you has the same key type (device type -- apple/samsung/lg/etc.) and keying (fingerprint data points) on their front door (phone).
But those odds are basically irrelevant as an attack surface.
For a native app on a phone the "username" is proxied to the device id, once linked to the user.
I think the article being 4 years old reflects a 4-year-old fear of the new and misapprehension of where security problems would arise in the future on biometrically locked phones.
The reason that fingerprints are a username is that they're a static value associated with the identity of the person, which is later impossible to change.
There's no reason you can't also use a username as a password (though there are lots of reasons you shouldn't), but it's clear that fingerprints are closer to username than password.
By contrast, the key to your house is clearly a password -- it a changeable value used to authenticate to a mechanism that you're authorize to operate it.
Years of poor security have taught us that we need our authentication to be easily changeable in order to be secure. It's not true. Passwords need to be changed because they can be guessed. They can be leaked. Any person sitting down at any keyboard could type any random string of characters and, given enough time, figure out someone's password. It doesn't work the same for fingerprints. There is no number of times I can press my finger on your scanner and trick your scanner into thinking I am you. Your fingerprint only needs to be changed if someone steals your finger and keeps it in a state where modern fingerprint scanners will still recognize it. That is exceedingly difficult to do.
We need to get it out of our mind that "we change our passwords regularly, we should change our fingerprints too". Bad security advice led to routine password expiration, and that bad security advice lives on. It's still bad.
>it's clear that fingerprints are closer to username than password
That is not clear in any way, either in theory or in practice. The entire argument works on "fingerprints are publicly visible and cannot be changed" which would suck for a password, but fingerprints are not a password. That's why there's an entirely different name for it. Yes, I can see your fingerprint. But TouchID isn't going to be fooled by a piece of scotch tape lifted from your desk, so it doesn't matter.
Fingerprints are neither a username nor a password. They are a uniquely identifying attribute. Usernames and passwords are not. There is no comparison between the two authentication systems.
Or I could print random patterns on gel circles I put on my finger and try until one works, which is the equivalent of your password example. (There are digital equivalents of spamming fingerprint reader values to the security chips, which in practice are faster.)
It's exceedingly easy to try a fake fingerprint, and even if it weren't, it would still be possible to generate fake signals between the sensor and verification chip or fake signals to the sensor. There's no difference here between finger prints and passwords.
> Passwords need to be changed because they can be guessed.
lol, no.
Passwords need to be changed when they're compromised -- a good password is exceedingly hard to guess, to the point we should never expect it to happen, but they can be leaked through other means.
Similarly, you leave you fingerprints everywhere. So you actually leak your fingerprint values constantly while leaking password values only occasionally. This makes passwords substantially more resistant to capturing the value out-of-band than fingerprints.
> we change our passwords regularly,
This isn't best practice and isn't what most of us do; we change our passwords when they become compromised, which happens through a variety of mechanisms. (Or when we suspect that they may be compromised.)
> Bad security advice led to routine password expiration, and that bad security advice lives on. It's still bad.
Everyone knew this was bad, and NIST recently updated their recommendations against routine password expiration. However, that has nothing to do with what we're talking about in terms of username-versus-password status for fingerprints.
> it's clear that fingerprints are closer to username than password
> fingerprints are not a password
Well, I'm glad we agree.
> But TouchID isn't going to be fooled by a piece of scotch tape lifted from your desk, so it doesn't matter.
But it is fooled by easy-to-produce prints placed over my finger based on the Scotch tape lifted from your desk. This has routinely been demonstrated with fingerprint scanners, including on iPhones.
> They are a uniquely identifying attribute.
That's what a username is, lol.
I'm going to recommend you learn more about most of these things before you make security recommendations, because you were factually wrong a few times, and made erroneous conclusions based on that.
I'm wondering what you might say if you were living in the time when cars began to replace horses. Would you have said cars were a terrible mode of transportation because they won't defend themselves against a thief and don't consume hay?
It's worked for years against a variety of scanners, and is likely always going to be viable because of how scanners work -- a thin overlay can be made of things that are indistinguishable from a finger surface to the scanner, but which triggers the critical points.
If you think that's changed in the past few years (which you seem to), I would appreciate something a little more substantive than your random comment on HN.
One very important property that I expect any private identifier to satisfy is that it can be changed once I believe it has been compromised.
My fingerprint data cannot be changed, once compromised. Therefore it cannot be a private identifier. Thus this is not a password. What is not private should be considered public by Kerckhoffs' principle. Thus fingerprint data should be considered to provide the same level of security that a username provides.
That's where comparison with user names or passwords breaks.
Your face is your username, not your password.
Use it like you use your username. But never as something secret, personal, unknown like your password.
The same goes for any biometric. Fingerprints, voice, iris, gait, DNA, etc. No matter how much they try to sell you authentication through biometrics, it's total b.s.
@DustinKirkland
As people age, or are otherwise disfigured, does their username change?
Biometrics are good for unlocking X if the persob who cares about the security of X is the person who oversees the registration of the biometrics.
In this case you are the person and X is ... the phone. That's it, the phone.
You should not be using biometrics-derived data for any passwords except to unlock your phone (or that place with the security guard making sure you registered your face the first time). Because REPLAY ATTACKS.
After that you're supposed to use challenge-response by some auth app on a device. So your fingerprint IS a password for the device but not for external services.
Passwords in general are vulnerable to replay attacks!
Your face or fingerprint is neither your username nor your password. It's a form of identity. The combination of username and password is another form of identity. A certificate chain is another form of identity. Not all forms of identity are separated into two components like username and password. And different forms of identity have different properties and applicability.
Trying to shoehorn a form of identity like a face or a fingerprint into the username/password template is counterproductive and will only add unnecessary confusion. Please stop. Dumbing down security and removing the nuance is how people get it horribly wrong.
Security is very dependent on context. Authenticating with a phone is very different from authenticating over the internet which is very different from authenticating in a situation where you're physically present with another human being (credit card, bank teller, etc). Authentication schemes need to be designed for the specific use case in which they're used and no rule is universal.
In your article you wrote how incredibly easy it is, so why haven't I heard about it happening?
My face is not my password, it is my face.
This kind of weak analogy you're trying only weakens the discussion.
Oddly enough, from a trust calculus standpoint usernames are not particularly valuable; we could do away with them entirely and the logic of authentication wouldn't change (though usernames add some very nice logistics that from a practical standpoint we don't want to give up).
At a very basic level, a single token suffices to authenticate: something you have, know, or are does prove you are who you claim to be (usernames just give a convenient handle to that). So, a 1TP from a fob, a password, or a fingerprint at a very basic level is enough.
If you just uttered the magic word to a service logon page, anyone uttering the word gets in.
You see the weakness in this type of scenario with Touch ID. If my wife's fingerprint is on my phone, she can access my Touch ID enrolled banking app.
Right. That's how a speakeasy works. It's the most basic form of authorization
The tradeoffs inherent to this are well-described elsewhere: a lower degree of absolute security in exchange for a higher proportion of users with any security at all; in lieu of the convenience offered by biometric authentication, enormous swaths of users leave themselves wide open. And since biometrics are just a convenience, anyone who does require absolute security can easily choose to forgo them entirely.
A fingerprint can be used against your will; it is significantly harder to be forced to use a password that exists only in your mind.
I mean, when someone identifies themselves through biometry, there's clearly an element of intent. And if they write down passwords on sticky notes, or anywhere else really, it's about as available as a fingerprint is, if not more.
The scene I'm reminded of is the on in Minority Report(?) where the main character is walking through a bank of bio-sensing ad displays, and has to not look at them to make sure they can't identify him from his iris/retinas.
As an analogy, imagine you take a picture of someone at an antifa vs. alt-right protest that turns violent.
All the picture tells you is they were there; it doesn't tell you whether they supported antifa, or supported the alt-right; it doesn't tell you if they were there as a police officer trying to keep the peace, or if they were simply trying to get in the front door of their apartment building when a clash broke out outside.
The biometry reveals their presence - it doesn't reveal their intent.
Sorry for not making myself clear at first, but what I mean is that passwords aren't a sufficient guarantee of intent either. If anyone has access to them, they can spoof someone's identity. I reckon that this doesn't really fit a civil rights discussion, because we haven't (I think) reached such a point yet, but government-backed attacker might spoof someone's identity in order to either infiltrate or hijack a civil organization. Essentially, a virtual mole.
If I grab your finger and press it to your device, so that I can access your data, the intent is mine, not yours. Ideally, an auth method works with the intent of the user and only the user. That's his point. You can't grab/cut a passcode out of someones brain and place it on the scanner.
Yes, but it only exists in the world during user intent. This isn't the case for an auth method which is entirely based on physically having something within your proximity. If I stand close to your, you auth method is now in my proximity, available for me to use, or possibly even take.
That's debatable, but it's also significantly easier to steal or guess a password than it is to steal or guess a fingerprint. The evidence for that is how many password breeches we've had over the years compared to the number of fingerprint breeches.
But it doesn't matter because it's trivial to put a gun to someone's head and force them to give up their password. As soon as you're open to using physical force, there's not much you can't do.
All this article offers is:
> For authentication, you need a password or passphrase. Something that can be independently chosen, changed, and rotated.
Okay, so fingerprints aren't passwords, but what we need instead are passwords, which we know don't work either. Best practices for password security are ignored by consumers because they're onerous, and biometric authentication seems to be insecure by default. What's the solution then?
We're really fighting human nature here, so maybe the solution is psychological, rather than technological.
As always, relevant xkcd: https://xkcd.com/936/
For many services, I have a few 'default' words or phrases that I'll use as a base for the password to build up length, followed by a word or two that tie to the specific service; to make up an example, for Twitter it might be "extrawordsthensocialchirpynoise".
Of course then the symbol/number/upper/lower rules become a pain in the arse - unless you build them into the extra words: "3Xtraword$thensocialchirpynoise".
Though all that said, I can't actually remember what my HN password is...
Any duplicates would result in fewer than 100,000,000 lines.
All fifty trials had no dupes.
Took most of a week to run that, on an older box :)
Previously mentioned:
More features can, but not always, improve the model. As pointed out by Tim Cook it goes from 1 in 50000 odds of duplicate result to 1 in 1,000,000. And that's 1,000,000 that would need to try on your phone.
FBI is probably running load tests now to see if they can brute force.
The problem with the third factor has always been a balance between cost, inconvenience and how easy it is to turn it into just another something an attacker has.
Retinographic analysis is gold standard but it's hellishly expensive. Fingerprints can be copied. Easily. Facial and behavioural analysis sit somewhere in the middle, with too much scope for false negatives.
So fingerprints aren't a username or password because they're not that factor... But used alone, they can be as weak as a username, in many senses.
a biometric is a username and a password
- yes, i know the purpose is to say that the biometric should be used as a password, but that changes the declarative statement quite a bit in my opinion
IE. You can change your password, you can't change your thumb/face/biometric (easily).
At best, a fingerprint establishes identity, therefore it has more in common with a username, drivers license, social security number, etc. than it has in common with a password.
Ideally you have a user name, a password, some sort of 2FA and also biometrics.
But the alternative for iPhones was leaving them without even a PIN because entering a 4 digit numeric pin was too much hassle for most people... so Apple lowered the bar and increased security with biometrics.
They are trying to do it again.
If you want ultimate security ,then you can have a very long alphanumeric password, and turn off touchID and faceID
Nope. At best a fingerprint establishes identity in a unique and authoritative manner. My name is an identity, and anyone can say or write my name. My SSN is an identity, and anyone can say or write my SSN. No one else can speak, type, write, or otherwise express my fingerprint. That is far beyond simple "identity".
Neither can you. You can only show your fingerprint for inspection - and so can anyone else.
And, unlike SSN or even your name, you leak fingerprints (and facial info) everywhere, all the time.
That's the point. It's not something I know, it's something I am and only I am that thing.
And unlike a password, if you want my fingerprint you have to be physically near me, and if you want to authenticate as me you need my authentication hardware. A Brazilian hacker isn't going to unlock my iPhone without first flying to the US and then locating me in both space and time to gain access to my fingerprint and my phone simultaneously. But with a password, they could easily go to www.gmail.com and type whatever they want from the comfort of their own home.
So to educated the audience security wise, one would need to raise the eyecandy value of good passwords.
though I use fingerprints on my laptop, I'm quite aware that it's really easy to leave any fingerprint anywhere
(I use it because I type slow)