edit: The original headline before being changed, "Web standard brings password-free sign-ins to virtually any site", and contained a paragraph espousing fingerprints in place of passwords.
edit: The original headline before being changed, "Web standard brings password-free sign-ins to virtually any site", and contained a paragraph espousing fingerprints in place of passwords.
Consider a simple fingerprint USB vault which stores your keys:
* Factor 1: You must have physical possession of my vault.
* Factor 2: You must be me or have a convincing fake of my fingerprint.
Before we even think about a password I've already prevented almost all of the attacks I'm likely to ever encounter against my accounts.
* I have made it impossible for someone to casually break into my accounts/device.
* I've created enormous distance between myself and remote attackers.
* I've eliminated password reuse and contained the effect of data breaches to the service that was breached.
* I've made it much more difficult for network operators to carry out MitM attacks since tokens are origin bound and the challenges are real-time with replay protection.
Yes in a forum of nerds you can point out that lifting fingerprints is possible but if everyone switched to this simple U2F device the world would be far far more secure. Passwords optional.
Then if you're worried about a more sophisticated attackers like corporate espionage or governments you can add a password.
[1] https://scroll.in/article/857274/now-even-the-fingerprints-o...
And you can't easily change them.
I don't remember how/if it was demonstrated that the fingerprint was a useful copy in any way (and certainly not on that official's iPhone).
https://www.theguardian.com/technology/2014/dec/30/hacker-fa...
https://www.youtube.com/watch?annotation_id=annotation_26842...
I think for most people convenience remains a win over the marginal increase in risk — someone who can get that close to you can also use a hidden camera/drone to watch you enter a password, steal your wallet/bag with two-factor codes, etc.
How does registering and unlocking another phone show that it would work on her phone?
I really don't think TouchID is at all riskier than even a 6-digit passcode. I really still wish Apple allowed multi-factor unlocking though.
So you really have Factor 3: You must have the password to power on the fingerprint reader.
The fingerprint isn't being used as the password.
Both your fingerprints and the vault can be taken from your person without your consent; a password much less easily.
Only because you have to lift and then manufacture them from scratch from glue and silicone and stuff. If someone automated the process it would require little to no effort. In theory it would be possible to manufacture a device that could present any given fingerprint when scanned with a popular scanner. You leave them everywhere, even on the scanner itself.
It is also a limitation of biometrics that you can only use them once. It might make sense for a phone, but after you have given Google your fingerprints, they can in turn use them for other purposes. It's like reusing a password that's also tricky to rotate.
You can't replace passwords with fingerprints, as you still need a backup to update said system.
You know this how? There has not actually been in real studies done, and the FBI and Law Enforcement resist any efforts to do studies on how Unique Fingerprints really are.
It is the bedrock of criminal prosecution many centuries, but they do not want any public analysis into how many people share similar prints..
Print Reading, even by a computer, is more of an art form, a massive guess, than it is a science.
Same could go for websites. A simple biometric factor like fingerprints is easy and friction free enough to log in users on previously seen devices. My password can then also be much longer and the website can impose stricter rules (longer passwords, no breached passwords, etc.) without increasing user friction that much either since most people will probably only log in from 4 devices at most (desktop, phone, tablet and some library computer)
2. A fingerprint hash isn't a cryptographic hash because you need to be able to match to nearby matches. A small variation in input needs to have a small variation in the hash so a distance function can be applied.
Those are terrible properties for a password.
Would you create a rubber stamp of your passwords, slather it with oil, and then go around stamping it on everything you own and everywhere you go?
Many builders/carpenters/etc will tell you this is not true. People who work in abrasive environments sometimes without proper protection often temporarily have no fingerprints as they are "warn off".
Many injuries can effectively modify or remove the too, at least temporarily.
This makes them bad usernames as well as bad passwords.
Do they come back in the same form as they previously were?
Additionally, I was under the impression that some fingerprint readers looked at the blood vessels rather than the actual prints. Not sure how that would be affected by abrasion. Perhaps this is a misunderstanding on my end.
I'm struggling to remember the protocol from a sci-fi novel where two secret agents who (separately) had their minds transferred to new meat sacks reconnected in a new (hostile) environment.
I think it had three parts: What you have, what you know, what you are.
We verify the server's identity though it's public certificate that's signed by a certificate authority. The server can verify the client's identity via a public client certificate that's signed by an authority the server trusts. It's already possible to do this over a TLS connection.
If the finger print is what you are, and password is what you know, then what is the "what you have"?
Mostly I'm curious if that sci-fi books' "three factor auth" scheme (because I don't know what else to call it) is a feasible model.
One possible form of "three factor auth" would be to use a passphrase for the private key, the client certificate to connect with the server over TLS, and a username/password login at the application level.
The certificate/certificate fingerprint is what you have, the password and passphrase are two things that you know. I don't know what would fit under the "what you are" category though (unless you're considering some sort of biometric based method).
A machine can obtain Certificates from a CA which show the CA validated its identity, and use Public Key Cryptography to prove this is its certificate. This is how HTTPS works when you connect to a remote web site, but it can be mutually authenticated too, that's just not how web browsers use it.