How Apple and Google will kill the password
computerworld.com
computerworld.com
http://www.id.ee/public/Mobiil_ID_animation/ <<< This clip shows how it basically work.
EDIT: http://www.ria.ee/27525 <<< some more info, if anyone is interested.
Only problem, and one preventing this becoming a real solution is the fact that people lose and forget their phones. If I can't have access to my daily services and devices without my phone then I am stuck in a worse position than I was before passwords.
The solution to access and protection shouldn't come from a change in the key, but a change in the lock.
On the same kind of note... the keys to my apartment are the most important thing I need to grab before I leave. Yet, once every 6 weeks I leave w/o them. Any system has to recongize that the keys will be lost and make them fairly easy to replace.
Many thanks for the links, I'll certainly aim to do something like that if I ever get an iThing. Know if it encrypts the contents of your phone too, or if they do this by default? Otherwise, I'd think you could just dump the flash memory.
- Biometric scanners can be outfoxed with a piece of play-doh. And what happens when you just want to loan the thing to your SO?
Authentication is best implemented when it combines what you have (a debit card) with what you know (a pin). Putting biometrics on your phone is just stacking two things that you have (your finger and the phone) with nothing that you know. No, the password, as a concept, should stick around.
Good point on combining what you have with what you know. I did not think of that. But wouldn't the PIN on your phone be as effective as your credit card PIN?
Sure, something extra you could do with a phone would be wrapping the payment system behind some sort of on-phone authentication before the phone "allows" you to use it, but then that's only as secure as the phone's debug access, so ultimately you end up with a bank-side activation/pin scheme, which puts you back at square one all over again.
To prevent the phone from getting a signal, put it inside a faraday cage (wrap it in aluminum foil).
1) The article spoke mostly about the phone being used for authentication. This doesn't necessarily mean that the authentication system has vast amounts of PII.
2) If the authentication system does become the repository for vast amounts of personal data, then the concern is really for consolidation. You've already surrendered vast amounts of data to Visa, Amazon, Google, Apple, NetFlix, etc. Seems you're worried about it being consolidated.
I agree there is nothing that necessitates a phone based authentication system requiring vast amounts of PII. However, there are strong incentives toward collecting it and both companies have a history of doing so whenever possible.
My only concern in both of these cases though is what happens when my phone runs out of battery? Nobody seems to have an answer for that.
Biometric systems are much less usable than passwords. Users often fail them by doing things like putting their fingers in the wrong place on the sensor or by not looking directly into the camera.
I think probably that users will need to be somewhat trained in order for this to work well. Probably the hackers will train themselves too.
Stealing fingerprints from someone at a bar? Not so farfetched.
The Biometric portion is a little bit sensationalist at this point because the less invasive Biometric techniques are not accurate enough to verify with 100% accuracy that you have your phone in your pocket. If I have to take a photo of my eye to complete the purchase using my phone, I think I'd rather enter a password.
I think the easiest way around the biometric thing is to put an NFC chip under the skin to handle a public/private key exchange. This is the best way to verify your identity because even a DNA test would not prove that you are present in any way.
http://consumerist.com/2007/08/how-to-de-rfid-your-credit-ca...
Mobile phone theft rose 1200% in 2014, is the password the way of the future?