https://www.newscientist.com/article/mg21128225-100-fingerpr...
Nevertheless it probably won't ever be completely reliable short of installing a hypodermic needle with the sensor to take a blood sample every time :)
now I just use the 8 digit pin to login
Usernames can be guessed remotely, fingerprints can't really.
Please demonstrate an attack that takes "a wee bit" of effort where you can use a fingerprint you found in the wild to auth.
[1] https://www.macrumors.com/2014/12/29/ccc-reproduce-fingerpri...
> fake fingerprints can be created by imprinting copies in rubbery gels or silicone plastic, says Marcela Espinoza of the Institute of Police Science in Lausanne, Switzerland.
Replace silicone with some other flesh-like material that's conductive.
Does this take just a "wee bit of motivation"?
FWIW, I don’t think anyone has done this credibly yet.
I don't recall seeing one. Do you have a link?
Just like "something you know" can have different strengths, "something you are" can too and changes in technology and threats will enable new options alongside new attacks as we go along. It's a process.
Not only can "something you are" change (in some instances), it can also be something that can be difficult for technology to not recognize correctly. A username or password must be correct (unless you're Facebook and do that goofy thing where you allow both the upper and lower case versions) but a biometric is more fudgable.
I'm somewhat surprised because it's definitely not new, I don't know what the exact genesis of that particular cryptographer's verse is but my vague recollection is I first heard it the late 90s, and the idea of extracting bits showing identity from physical qualities unique to a person certainly dates back a long ways. "Something you are" can cover a lot of possibilities too, and with vastly more variety and subtlety than I think a lot of people consider even in security fields. For example, there was recently a genuinely very interesting idea of measuring bottoms. As in, your actual behind/ass, via sensors in chairs. It should be unsurprising if you consider it, but of course the patterns of musculature/fat/bone structure are fairly unique to you for any part of your body if you have sensitive enough tools. It's a transparent measure for certain use cases like a workstation or the like since you're sitting down anyway, and hard to clone from afar since our butts are typically covered and subdermal is challenging without near contact. Another place if you want to look for cutting edge possibilities is advertising/surveillance. Near anything used for tracking fingerprinting could in principle be used for authentication too, and again there are potentially a lot of bits of entropy to be found there. Our gaits as we walk, our patterns of typing, our micro muscle movements, all sorts of things aren't so generic to a powerful enough system. "Biometrics" is to some extent at the stage of 80s or early 90s passwords, something to keep in mind in these discussions when people complain about them. 8-character alphanumeric passwords protected by crypt aren't exactly good these days either, but auth tech moved on even as tech benefitted attackers. In the future biometrics will undoubtedly consider far more than our current early generation systems, up to and including implants.
FWIW, I have (more rarely) seen a few other classes of factor suggested that do make sense, and are arguably distinct categories. One is spatiotemporal, ie., "somewhere/somewhen you are". This is used de facto by any sort of air gapping or "this system can only be accessed from this one place and console" or the like. It could though be taken advantage of far more thanks to more ubiquitous high resolution GPS and the like in our systems. Having certain kinds of data only become accessible in the right place/time could be very useful.
Another fuzzier category is "something you do", as-in observing the actions you take. I felt at one point that this was merely another way of measuring "something you are", but I can see the idea that it'd be distinct because it's about revealing your direct state of mind, whereas at least for the foreseeable future "something you are" tends to focus on more bulk matter aspects of your being. Technically state of mind is physical too, there is a specific vector state of axons and neurons and firing patterns that represent it, but it might make sense still to distinguish that from physical body structure or even implants. Whatever the case though it's still an interesting consideration, and makes a lot of sense in old school counterops. Sometimes the first sign of someone who "shouldn't be authenticated to use this" has been "they were 'acting funny'" after all.
And can be compromised without theft, coercion or any other trace.
> One can be swapped out if compromised or get lost.
Which makes something you are strictly worse than something you have.
> undergoes slow changes over time
You are lacking an argument for anything attached to this point.
> ...it makes sense to split it into two categories
So you are arguing that because something is strictly worse from a security standpoint, it should be categorised as a new category? Have I summed up your position correctly?
There are usability benefits which would exist similarly by attaching something which couldn't be easily compromised to your body. For example a chip under your skin or just carrying a watch on your wrist which you could authenticate with after putting it on and which would un-authenticate automatically when it is taken off. Nobody would argue that you are your chip or your watch.
Something you know is different because there are no plausible ways aside coercion and similar for extracting such secrets in idle, and the other alternative is to get compromised on usage. It's about the threat models.
Something you have can have strong copy protection like a yubikey and can be given away.
Of course, the something you are necessitates a biometric system that itself can be trusted to be secure.