Selfie-based authentication raises eyebrows among infosec experts
theregister.com
theregister.com
https://www.tumblr.com/intj-explained/10233359295/the-death-...
But aren’t all those checks just running against videos? Why can’t those videos also be stolen/mocked?
All in all: yikes.
They will come next.
If someone identifiable has to physically be at, say, a police station, or DMV, it cuts out 95% of the complexity involved in all the security stuff we’re dealing with.
Just from an attack scalability perspective.
In my opinion we logically end up needing something that looks like a pre-arranged Proof of Identity (Aadhaar, Clear) or Proof of Humanity (World Coin, etc.)
The place has lots of activities for kids to run around and do, but Mexicans are scared of child kidnapping (rightly or wrongly I do not know).
So upon entry to the restaurant, the whole family has to take a selfie (on their device), and they need to show it when exiting. So in theory kids can only leave with the people they came in with.
Of course, the staff doesn't really check the timestamp, so I suppose a kidnapper could just take a selfie with the target kid, rendering the whole thing useless... but I nonetheless find it interesting how businesses in emerging markets roll their own half-baked, low-tech security solutions.
The photo would be taken by me, on my device, and no data about it ever enters the control of any other entity. It's hard to fault.
I agree that it would be improved if the staff also required the photo to have a timestamp attached and actually confirmed the time on exit. But even just the photo alone probably gets you 98% of the benefit. Security is never 100%. The main point of any security system is to increase the difficulty of doing the bad thing, and this system does that.