https://www.dw.com/en/german-defense-minister-von-der-leyens...
-
The core problems with biometrics are that:
1) Not revokable (unlike compromised credentials)
2) Not a secret
3) Usually trivial to reproduce and spoof (even "liveliness" tests)
https://www.dw.com/en/german-defense-minister-von-der-leyens...
-
The core problems with biometrics are that:
1) Not revokable (unlike compromised credentials)
2) Not a secret
3) Usually trivial to reproduce and spoof (even "liveliness" tests)
… is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them.
See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.
Nothing like a secret token that can be reliably guessed using only your birth month+year and place of birth!
- The first set of three digits is called the Area Number
- The second set of two digits is called the Group Number
- The final set of four digits is the Serial Number
Certain geographic areas get certain "Areas Numbers", then Group Numbers are assigned consecutively, then Serial Numbers are assigned consecutively. This entire system of consecutive assignment makes it trivial to guess pretty well, or even exactly, what someone's SSN is.
From a security professional perspective, this is at least somewhat of an improvement, even if the entire thing feels like it's held together with a wish and a prayer. I would really like if there were a means to just institute an entirely new system. Essentially having one's entire life ruined, on the chance a bad actor can guess a four digit number is...not great.
From a genealogist perspective though, this is horrible news. Being able to trackdown people based off of rough geographic assumptions can help narrow down if someone is "lucky" enough to have a common name in a specific region. Of course, this change to SSN isn't nearly as disastrous as the death of paper - especially newspapers - but I really do not envy anyone who is going to try and do historical family research in two to three hundred years. It makes me cringe just to think about how much valuable information, how many life changing moments, are going to be lost to encryption, bit rot, and the constantly changing standards of software and hardware.
https://www.popsci.com/social-security-number-equifax-leak/ https://www.forbes.com/sites/suzannerowankelleher/2019/08/01...
I think the current crusade against passwords is primarily motivated by different providers to advertise their ID schemes. Even needing a cert for something like Github is too much for me. I have no high profile repos and it might be reasonable in those cases, but I hope MS doesn't repeat the mistakes they made with their API access. The logistics of authentication is far too complex.
Aside from that I have seen people handling their keys that make you wish they would just use a password and cert logistics isn't trivial at all. No, you should not copy your key to our corporate file server... This is just the nerd way of gluing your password under your keyboard.
Can biometrics be spoofed? Absolutely. Is it likely to happen to the average person? Not at all. For a typical everyday user, a fingerprint or face scan is probably more secure than the common alternatives of "sticky note" passwords, easily guessed PINs, or no authentication at all.
Biometrics are a compromise between security and convenience. Before iPhones got Touch ID, it was not uncommon for people to just not put a lock on their phone out of convenience. Now it is impossible to find an iPhone out in the wild that is not fully encrypted. The average level of security on consumer devices that hold sensitive information has increased dramatically thanks to biometrics.
I believe biometrics aren't necessary to establish security and in the worst case reveal unnecessary information.
This obviously not as secure as a system when you must use your credentials frequently to maintain access, but it seems entirely appropriate for the level of security needed by most individuals on their phones. Especially as the alternative is often a super simple password or even no password at all. TouchID makes a moderate level of security palatable enough for people to actually use.
So far I haven't encountered a device where a fingerprint was used to unlock disk encryption, so your objection is actually implied, I think. Especially, with the increasing uptime of Apple's new hardware, a running session is what you more often than not got these days.
No matter how you twist it, biometrics are fundamentally flawed and not even Apple can magically fix that. At least one component of access needs to be a secret, which cannot be extracted without cooperation, or "cooperation".
Someone can use their smartphone to film other person as they type stuff in, no need for printing fake print. They can steal phone/laptop as soon as they are done filming.
This is the case that fingerprint sensors are preventing.
Pointing out problems is useless - as people don't have alternative that would be "all-mighty secure without flaws".
It should be defense in depth not - and that is already there for example banking apps - you need fingerprint to unlock the phone and banking app requires its own specific PIN. Getting those 2 things makes it much harder for bad guys to do something like money transfer. Yeah they might get your photos and other stuff - but probably there are secure store apps that would encrypt your photos if you have ones that you really want to protect.
They aren't. Your parent post already mentioned that they were extracted by filming.
Passwords don't have the other 2 problems, and I'm not really sure what is gained by not talking about them.
1) did not write what are needed parameters of the photo or quality of left fingerprint
2) it does not look like they used photo from an angle of the screen as in article but some other closeup
3) somehow unlock stuff with thumb where most people use index finger
4) then they use index finger to operate "thumb" print
5) who touches screen like that with thumb, who touches back of the phone like that
In the end with PIN I can look over someones shoulder and not even have to make a video.
I agree with the premise of what they say that people might think fingerprint is "super secure" while it is not...
But it is secure enough for most of the people and more secure that typing in PIN or short password or for people using 0000 or 1234 as PIN.
https://www.dw.com/en/german-defense-minister-von-der-leyens...
I just don't follow the timeline and geometry. Seems theoretical only maybe.
https://media.ccc.de/v/31c3_-_6450_-_de_-_saal_1_-_201412272...
You assume 'old' strictly implies outdated, or bad, which isn't true. E.g. good passwords are still undefeated. And security protocol redundancies surely can make intrusion impractical, even if individual components fail.
I assume, military hard- and software to be made meticulously, double checking everything, on literally battle tested chips and gear. I mean, I really had no contact with anything military ever, so that's a guess based on aircraft and space development, pictures of überfunctional UIs and the ridiculous finances of the US military.
I don't mean to diss W2k in general, Its an OS that is well understood by now - weaknesses, mitigations, etc. Slowmoving entities like the government accrue so much cruft that it makes it exceedingly difficult to move to newer (and possibly better) platforms to take advantage of newer security tech.
And for W2k, I wasn't merely suggesting it's well-tested, but also a different, better thing than say WindowsXP. At least, I got the impression operating systems folks reference it for a "many good ideas" kinda thing.
Sorry, I don't have any expertise in any of this and talk mostly out of my ass.
It is like a highly distributed backup of that fingerprint.
In which states? The only thing I have been fingerprinted for is in the US is The Global Entry program.
One state I lived in gave me the option of not having a RealID-compliant license if I wanted to. Another didn't, so fingerprints were compulsory.
[0] https://www.biometricupdate.com/202101/real-id-law-quietly-p...
https://duckduckgo.com/?q=which+states+require+thumb+print+f...
Fingerprints are not required as a part of Real ID implementation. Real ID seems like it would be the main driver for feature parity between licenses of different states. If fingerprints aren't required by Real ID, then it seems like it would be incorrect to assume that all states require fingerprints - and thus also incorrect to assume that driver licenses in the USA are used as honeypots for fingerprints.
Perhaps landemva should have specified which states are using driver licenses as honeypots for collecting fingerprints?
A few years ago I had top tier frequent flier status, and the airline kept offering to pay the Global Entry fee for me. Sit for a lame interview and provide a bunch of info to power-starved snooping Karens? No thanks.
I don’t think this was intentional but they managed to demonstrate (or at least for-shadow) the incompetent police force of the future this way.
The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing human.
- Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand.
- Shit: A camera that compares pictures.
The entire industry is about making an autonomous system that gets as close as possible to perfect. It's fine to say that you don't think it's good enough right now but "oh no I lifted a fingerprint from a photo" isn't some security breach.
And yet, it can be reproduced. So it seems like the entire point is... invalid.
Your phone should probably be a little loose but the retina scanner at the datacenter of the dod will be a lot stricter.
Well, the argument some people are making is that this might be no better than a human checking your ID. Yes, there the guard can verify that there is some real human there, but both the ID and the fingerprint could be faked (e.g. a fake fingertip mold which matches the victim's "known" fingerprint).
Anyone who has had their fingerprints taken by the FBI knows that there is a solid procedure that will detect fakes. The idea is to replicate this near perfection, not bolt on some revocation system for fingerprints (ouch!)
If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that.
So, like all other identifiers, revocation is an important trait. Even if successful reproduction is difficult and rare, it would be utterly devastating to those affected unless there's a way to revoke.
> Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand.
Not at all perfect. Can that human guard really see if you're wearing a fake fingerprint? I doubt it, unless he's closely examining everyone's fingerprints first. And even then...
All encryption will eventually be broken therefore what’s the point is a pretty bad security posture. But like no it won’t. Even if you can fake every other metric (good luck with eyes) a fresh blood sample taken by a guard with hypothetical futuristic instant DNA sequencing will never be broken. If your threat model is someone cloning you, the you have bigger problems and they still can’t clone your fingerprints!
You’ve got revocation completely ass-backwards. If someone successfully tricks a biometric system you don’t need to revoke someone’s fingerprint, you revoke the reader! That’s the thing that actually provides all the security.
The point of the guard is that a human has absolutely no trouble determining whether they’re taking a reading of a real hand, scanning a real eyeball, to taking a real blood sample. Maybe in mission impossible movies but you’re really really overstating the resources required to make a convincing hand to someone specifically looking for fakes. Yes social engineering is a problem which is why an autonomous system with the detection quality of a human would be nigh unbeatable.
When a given crypto scheme is broken, you can change to one that isn't. When your physicality is compromised, you can't change to a new body.
The procedure at the USCIS to get my green card was remarkably thorough. The guard manually and visually checked each of my fingertips carefully to ensure I had no fake print overlayed on top of my real print and I had to keep my hands within a small area with a camera on it for the entire process or they would restart everything.
Lost/stolen cryptographic keys or ID cards could be revoked and would require a trip to your a certified biometric verification facility where a thorough in-person inspection would confirm that your fingerprints are real, you aren't using a fake eye, etc. Then you'd be issued new keys/cards at that location. Loss of ID is inconvenient, but not catastrophic. Leaking your biometrics is irrelevant.
Is it an infallible system? Certainly not, but it should be able to uniquely identify someone and not allow faking biometrics.
> biometric verification facility
sounds expensive.
"Perfect" is too strong a statement. This is only true if the guard very carefully checks every fingertip to ensure nothing is glued over your normal fingertips, and even then it's possible to distract the guard or rush them with a socially-engineered premise. Or just bribe or blackmail them.
Biometrics are not the weakness. Current implementations are.
However, they are showing their attack working on a Macbook Pro with touchid, which uses this sort of reader. So it's easier to fake in practice than it is in theory. Whatever material you lift the print off of should have to mimic the capacitive behavior of the finger and this looks like it busts Apple's claim that it can read the lower layers (or it tells us their default sensitivity is set too low for convenience)
The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.
Nonetheless, we still lock our doors and thieves often break in, even though picking the lock is both safer and less likely to arouse suspicion.
Your argument makes sense, but we humans aren't really rational
On the rationality of having locks when criminals can very easily break a window, the old saying that locks keep honest people out rings true. Locks do serve a purpose even if they do very little to slow criminals down. To bring the analogy full circle fingerprint readers always seemed like windows to me in how easy they are to bypass, luckily they're more of a luxury than a necessity. :-)
That is why they aren't carried around any more.
And that is not taking into account that most locks can be defeated without lockpicks, a steel ruler will do.
It's just sad when people that don't know a bit about the trade boast about "regulations" and how they are relevant. They are not.
Four hours have gone by without comment on this and I feel the offense should be recognized.
Law enforcement can force you to use biometrics to unlock a phone. They have used dead bodies to unlock phones.[0] What they can’t do is make you remember a code/password which you have “forgotten.”
[0] https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...
2. Nobody claimed to then want to withhold the feature "from the masses"... so this is a strawman.
3. "hypothetical actions of an agency"... I think it's pretty clear that these types of methods are not hypothetical, and are being used already
4. "will stop short of torture"... I also think it's clear that many LEO's, especially the closer to federal ones, have been found to torture already.
I agree with gp, biometrics on phones are a bad idea all around, for a lot more reasons that have been said. I don't know why you are protesting this idea as you do.
They might be able to with an FMRI machine.
TLA person: Give us the code or we put you the MRI machine!!
Victim: Can't you just use a $5 wrench instead?
There are still plenty of places where polygraph examinations are used legally.
But they can lock you up for not supplying it.
From your https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...
Isn't that what Cancelable Biometrics e.g. [0] is about [0] https://ieeexplore.ieee.org/document/7192838
In 2008. "fingerprint of then interior minister and current Finance Minister Wolfgang Schäuble" was sourced from a glass:
https://freerepublic.com/focus/f-news/1995935/posts
In 2014. "A speaker at the yearly conference of the Chaos Computer Club has shown how fingerprints can be faked using only a few photographs. To demonstrate, he copied the thumbprint of the German defense minister" Ursula von der Leyen
https://m.dw.com/en/german-defense-minister-von-der-leyens-f...
I wonder if you could use CRISPR or “lab-grown meat” techniques to do the same with DNA evidence…might be something that would get you a contract with the CIA/NSA.
Didn't a woman in France already have a face transplant?
I'd like to see Mission: Impossible type transplants, or even masks like the ones they use, for that matter.
Of course that's not really surprising when you look at the kind of Halloween masks you can get if you are willing to pay [2]. I imagine if you could special order them to perfectly fit your head they would be very convincing to the casual observer and to software.
For all of those outraged by the media storm, it is free advertising to those actually interested in the service. All of the pearl clutchers feigning shock and outrage over shady service mean nothing to the company providing the service, as these were never going to be their customers in the first place.
> Using several close-range photos in order to capture every angle, Krissler used a commercially available software called VeriFinger to create an image of the minister's fingerprint.
The tests also have varying accuracy rates, but people misunderstand what it means. If the test is 99.99% accurate, that doesn't mean that there is a 99.99% chance that the defendant is the perpetrator. It means that in a region with ten million people, you've whittled your suspect list down to a thousand people. If you pick one of them at random there is only a tenth of a percent chance it was them.
This especially problematic when dealing with "DNA databases" because then with a large database you have a high probability of finding a false positive match and the true perpetrator might not even be in the database.
But even then, people use percentages as if everyone's DNA was independent. Which it isn't. Blood relatives have similar DNA.
The one thing DNA is really good for is excluding people. If you have the rapist's DNA and you accurately test it against the suspect's DNA and it doesn't match, it's not them.
The law has to operate within a practical compromise and err heavily on the side of reducing false convictions.
This is antithetical to the concept of serving one’s time. Guilty people deserve to go free once their debt to society has been fulfilled.
https://en.wikipedia.org/wiki/Blackstone%27s_ratio
Does a law system let some guilty people got free to avoid incarcerating the innocent, or does it incarcerate the innocent to avoid letting some guilty people go free?
My opinion is to lean towards letting the guilty go to avoid incarcerating the innocent, but other people in other places can lean the other direction.
That is an article I was reading today. I don't know what is wrong with America.
(On a side note, the state of biotechnology and life science knowledge on HN is utterly deplorable, repeating buzz words does not reality make.)
In the context...
It's already trivial - $500 consumer grade resin printers have sufficient resolution, and creating the model from photographs is super easy.
Same for facial recognition - you can do Mission Impossible style masks, and the most significant investment is in time spent learning makeup and wig work.
Biometrics are not secure, just like a vast majority of locks. All it takes is tools, knowledge, and motive to bypass them.