This seems a massive assertion that’s not qualified at all in the article. It was my understanding that biometrics in consumer hardware have always been easily circumvented and are largely about convenience.
This seems a massive assertion that’s not qualified at all in the article. It was my understanding that biometrics in consumer hardware have always been easily circumvented and are largely about convenience.
> In recent years, however, security researchers have demonstrated that it is possible to fool many, if not most, forms of biometric identification.
[0] https://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_...
[1] https://whatis.techtarget.com/definition/gummy-bear-hack
identification is more like a username, not a password, and should be used as such.
There’s no reason why biometrics can’t both Id and authn at the same time, as long as both functions have a high degree of confidence.
Multi factor auth is probably always going to have its place. Where the confidence level is low in the authn, it must be increased by adding additional vectors.
I'm willing to neglect the shoulder surfing attack vector as I feel I keep my phone sufficiently secure from pick pocketing and am not afraid of an "inside attack". Might definitely reconsider this, if I would have to carry a business phone with important secret information though.
[1] https://math.stackexchange.com/questions/634437/how-many-com...
I always liked the password alternative of showing the user a bunch of pictures or photos in random positions and have them select a number of them in sequence, perhaps showing a whole new set of pictures in between each selection.
Humans tend to have much better visual memory than verbal memory, so they're able to remember this kind of sequence better than a password, especially if the pictures they select are somehow meaningful to them. This is also very difficult for someone to shoulder surf effectively, as they'll be seeing these pictures for the first time and the pictures won't have any meaning for them.
I heard about this idea decades ago, but have never seen it implemented.
Android allows pattern unlocks without showing the pattern as you type it, only on error. That's a good trade off.
Not very imaginative. One of my brother's friends got into my brother's phone on the very first try by holding it up to a light and looking at the smudge pattern on the screen. A tapped-out 4-digit PIN would at least stop this method from working so easily.
Research like this, while ostensibly threatening an increase in false positives (due to unauthorized use of fake prints), will in all likelihood cause vendors to tighten the confidence interval, leading to greatly increased false negatives. If my print is recognized less than half the time I'm just going to disable the feature.
It also gets confused if there's any dead skin on my thumb, something that seems to happen pretty often (and I don't even play Nintendo anymore).
Why things posted from vice, vox and the likes are always shwoing up on HN I will never know.