For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.
For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.
I've broken any biometrics recognising me in a dozen different ways, this year alone. Cut open my finger, changing my fingerprint. Head surgery for melanoma gave me a scar so facial recognition doesn't work anymore, blood vessel burst in my eye, so iris scan changed. And so on.
They're fine for a convenience, but that's it. They're nothing more than a pin, and you will have to fall back to password or authenticator or something else, sooner or later.
For remote authentication you use a private key accessed via the local system (which you are already authenticated to using biometrics).
That does not imply a pin or password for easy fallback. That implies something harder, that os self-destructive on use.
[0] https://www.abc.net.au/news/science/2023-11-01/ai-facial-rec...
With 99.99% chance you forget it before you ever get to enter it because humans forget things they never use :)
It'd be much easier for porn & social media ID laws to be enforced. Which could be abused by adtech and law enforcement.
I don't want a key limited to a single device I just want a strong key that can automatically login to a website. The technology has existed for longer than the internet it just needs to become the norm.