You don't need to burn off your fingertips (and other biometric myths)
troyhunt.com
troyhunt.com
I'm not saying fingerprints are bad, just that there must be a process to support those that do not have them.
so, several years of corona may in the future have the side effect of many more people without finger prints.
After far too many unsuccessful attempts they pulled out the old ink roller and fingerprint card and called it a day with the first crack at it. At least the authorities had this option, what will happen when/if electronically scanned fingerprints are set as a hard requirement?
None of those will change your fingerprints, they'll grow back unless you took off so much skin that your fingers are scarred and the prints won't grow back. Which doesn't really help with the supposed problem that if someone steals your fingerprints, you can't easily change them to another pattern.
My kids, for one. They're sneaky little buggers and I could envisage them observing my password as I type it into my PC. I can't, however, see them having the sophistication to lift a clean print off a glass, melt down a bunch of gummy bears and create a prosthetic that could fool the fingerprint reader on my PC.
I think it won't be too long until they can dust your fingerprints, take a picture of it, then have it 3d printed on a substrate that will fool a simple fingerprint scanner.
I still think the author's main point stands, it's way easier for them to remember a pin that they observed and unlock your phone when you're not around versus the recreation of a "perfect" fingerprint
I'm struggling to find good references right at this moment - but I've seen reports/video of this being done using more basic means, years ago. But I may be misremembering details.
It seems that it's already possible to produce usable fingerprints using a laser printer, printable transparencies (i.e for overhead projectors), and some glue.
The idea is that you print the inverted fingerprint on a transparency. Because the transparency doesn't allow the toner to absorb in, it remains on the surface as a 3D structure.
You then apply glue to that structure, and wait for it to cure. After it cures it can be removed and trimmed to fit your finger, and then applied to your finger.
This apparently is reliable enough to fool basic fingerprint scanners, even ones with 'liveness' checks for conductivity/pulse because the glue is conductive and transparent enough for those basic checks.
Examples of similar things:
https://blog.lookout.com/why-i-hacked-apples-touchid-and-sti...
https://www.instructables.com/How-To-Fool-a-Fingerprint-Secu...
https://3dprint.com/271540/d-defcon-fooling-biometric-sensor...
[0] https://web.archive.org/web/20091008202313/http://www.ccc.de...
[https://www.universalhub.com/2021/facing-facts-police-say-th...]
Did I skip over this difference being discussed in the article?
The 4th amendment is intended to ensure (among other things) that the government can't search some locations for evidence without first proving they have a good cause for that search.
The 5th amendment is intended to ensure (among other things) that the government can't use force or threats to make you admit to a crime, regardless of if you committed or didn't commit that crime.
The distinction is that a court could grant the right to force someone to put their thumb on a phone, or look at a phone's camera, but they (in some but not all cases) cannot force you to type in your passcode.
The argument is that your fingerprint or face is not "testimony" but a fact of who you are, but your passcode is a testimony, a declaration that you have some specific knowledge.
A phone unlocking is equivalent to it saying "Yes that is my owner/user", and that is not that person testifying, it is the device testifying against that person. Similarly it would be as if someone kept a picture of them committing a crime that was found with a valid warrant, they could not claim that having taken the picture it is their own testimony and can't be used against them. Taking the picture is a past event and requires no compelling of testimony to be used as evidence.
Getting biometrics without a warrant is a contentious issue. There are situations where a warrant is not needed, and these have also been abused to gather biometrics in situations that should have required a warrant but it was denied.
What about voice- or movement-based biometrics? (These are just the first counter-examples that came to mind.)
But to your point, those require doing, which is the difference. Regular use in mixed environments (airport terminal, office, waiting for the train, etc.) is TBD. As long as I have a password backup for the days I’m in bed sick.
But it's easy to trick the user. Very easy. And because passwords tend to be difficult to use, users tend to pick easy ones, such that you don't need to trick the user at all. With bio, the user may opt to have the protection whereas with password they either may not, or it may be trivially bypassed. Bio systems can be engineered to be anti-phishing, anti-MITM, etc. Incredibly hard to do that with passwords.
By claiming that the user has to do something to use a password ignores the vast, vast set of vulnerabilities involved.
One is not really better than the other per se. It's very use case dependent and you optimize for a specific outcome based on the risks at hand. You won't perfectly get every possibility nailed.
And then I read this and I'm back to square one. Forest/trees man. He just sounds like he's trying too hard to hand-wave away serious flaws in biometrics by trying to reassure us "well, it's not likely to happen to you personally, so you shouldn't worry about it," which is always always the worst, and perhaps most dangerous privacy argument ever given -- because of its unreasonable effectiveness against the "common man."
Done with this guy, I am.
what’s the issue? he’s not advocating for you to stop using a strong password if you already are, he’s saying people who use nothing should be encouraged to use something… perfect is the enemy of good
Did you read the article? He is exactly saying that acquiring your password (however strong) is in most circumstances much easier than acquiring your fingerprints.
He's not just saying that biometrics are better than nothing, because of course everybody agrees with that - no privacy/security activist ever said 'the police could compel you to unlock your phone with a finger, therefore you should keep your phone unlocked'!
I absolutely want any so-called security expert to always also include the big picture or shut up forever. There's too much confusion and too at stake for people as big as him to isolate personal security from big picture privacy.
“It’s okay - you’re not worth hacking enough to worry about weaknesses in biometric security” seems like a better title for the assertions made here.
Maybe that's true or not, but that's never been conclusive.
What has happened was that after the 3/11 attacks in Madrid , an American was suspected because his fingerprint was misidentified, partially because of this reasoning.
http://www.latent-prints.com/images/Final%20OIG%20Executive%...
IMO biometric auth will never completely displace passwords unless it can beat the user experience of a password manager.
But, as it may be obvious, I really don't understand how the biometric stuff works.
Physical presence isn't needed, a photo is enough. https://www.dw.com/en/german-defense-minister-von-der-leyens...
And then try to argue it wasn't you who unlocked your phone and made the expensive purchase because someone stole your fingerprints.
Why call the statement "absurd" only to essentially agree with it by the end of the paragraph?
"Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT." -- https://www.usenix.org/system/files/1401_08-12_mickens.pdf
Good passwords and biometrics help if your adversary is not-Mossad.
Anybody who thinks biometrics or encryption or anything short of "Magical amulets? Fake your own death, move into a submarine?" is going to protect them again a nation state level adversary is kidding themselves.
But pro-tip if you are being apprehended by police is to furiously click on the side button as the phone will require pin code after that.
Apparently that won't work on Android -- though there's a lockdown feature (that will disable biometric-unlock) that you can access after long pressing the power button.
Throw someone in an MRI or whatever. Continuously scan their brain, while their eyes are taped open, and display a changing character on the screen. Meanwhile, play a sound file with someone saying "password" in the background constantly, so diversionary mental tactics won't work.
Soon, the first character of their pass will appear, a part of their brain will respond, and you have the first char. Continue until the entire pass appears, and "despair" alights in their brain.
Success! Drink champagne and rejoice.
I have plenty of passwords memorized. I could think of my email password from 2002 (yes, I remember it), or any of my work passwords, or my Steam account password.
It's going to take a lot of MRI sessions.
I think this is quite interesting and would not only work for passwords if it does at all. i would love to read more about this :)
You do however, have close relatives, family, friends, things you own, people you care for, your own life, that can be used and threatened for you to give out your password.
Don't kid yourself. Torture methods exist for a reason: as horrible as they are, they work, no matter the person. And they won't stop until they get your vacation pictures.
My fingerprint reader on my smartphone is so fucked up that if I just quickly move my finger on it, I had to many attempts and its disabled. Then it requires whatever you use else (PIN, password, ...)
No, you’re leaving out one very important class of actors, which I will call the NSA: The NSA, and others like them, unlike Mossad, are not after you personally, in that they don't want to do anything to you. Not immediately. Not now. They simply want to get to know you better. They are gathering information. All the information. What you do, what you buy, how you vote, what you think. And they want to do this to everybody, all the time. This might or not bite you in the future. You seems to imply that since nothing immediately bad is happening by using slightly bad security, then it’s OK and we shouldn’t worry about it, since Mossad is not after us. I think that we should have a slightly longer view of what allowing NSA (et al.) to know everything about everybody would mean, and who NSA could some day give this information to, and what those people could do with the information. You have to think a few steps ahead to realize the danger.
(This has been a partial repost of a comment written a year ago: https://news.ycombinator.com/item?id=23572778)
The vast majority of people need to worry about ransomware operators and phishers. Biometrics are great for defending against those.
Distance or not, biometrics are part of a totalitarian future, and as such are to be avoided. The conversation about passwords will be moribund before you know it.
I'm worried about someone using my hand while I'm unconscious, or by physically forcing me to do so.
Bio-metrics are convenient though. I use them with my password manager. For things where it matters, use multi factor authentication. Long term, multi will have to be more than 2. The more factors, the harder it is to break through. For example, I use a separate tool to store my 2FA secrets than my password manager (which can do this). That's almost (not quite) an extra factor. You might call it 2.5FA
YES! Both Android and iOS insist we re-type our password at random times when using biometrics, and of course "random time" is always the worst possible time (in the subway, on a plane, etc.)
I don't understand this. Why force me to type a password at the risk of divulging it? What's the point of this?
The essay mentions this as an absurd argument, but then completely fails to explain why it's an absurd argument.
He does make a strong case for the use of biometric authentication with the group of people who aren't willing or able to spend any energy on security, but he didn't make the case for why people who are so willing and able should use it.
(edit: wrong link)
I personally used a pin code on my second phone because I was fearful of the biometrics chatter but this article convinced me that using the fingerprint scanner is safer in most scenarios than otherwise.
Back in the real world, we saw civil unrest (of varying types) in the past 12 months, but the rule of law is still there. See how the case against Backpage for sex trafficking is being re-run.
a lot of that civil unrest because cops rolled up on people and killed them?
https://www.popsci.com/technology/article/2009-12/chinese-wo...
> "Use biometrics. It incentivises people to secure more things, it's resilient to all sorts of risks passwords are not and as an added bonus, it makes your digital life a whole lot easier"
The articles conclusion sums up IT well, people being clever talking about the problems with biometrics are the problem.