Apple's new Fingerprint Sensor
rothy.tumblr.com
rothy.tumblr.com
Please edit the post, this is just ghastly.
I would love something like this. I hate signing into apps (mobile banking, in particular, is a pain). It'll end up being up to app developers to integrate the new fingerprint APIs though, and I bet you my bank still decides that their stupid username, password, 3 random letters from a 'memorable word' scheme is more secure.
The iCloud aspect does bother me quite a bit though, particularly when combined with likely NSA backdoors.
I'm sure that there are open source projects out there that are just as bad. I don't use those. The ones I do use, like mutt, don't contain this level of blunder. It's not that we should expect software to be free of bugs. It's just that the nature of these Apple bugs suggest a cavalier attitude to software quality and a severe lack of testing. Combine this with closed source and a critical security function, and you have an explosive mixture.
It didn't happen. I would attribute it to two main frustrations: the readers only worked inconsistently due to particulate build up, and would occasionally have false positives. I think false positives are an inherent risk with fingerprint readers and in any case are not suitable for security as lifting a fingerprint from someone unwittingly is easy.
See the Mythbusters episode on stealing a thumbprint: http://www.youtube.com/watch?v=3Hji3kp_i9k
Having a stolen fingerprint is worse than a stolen password. For one, people tend to trust fingers more; for the other, it's impossible to change your fingerprint, unlike your password.
I really can't trust these kinds of consumer technologies until their designers use revocable biometric systems to protect the fingerprint template. That area of the literature is quite well studied, but everyone seems to ignore it.
You get ten revocations before you have to take off your shoe.
Any civil worker who takes fingerprints isn't going to let you put your foot on the fingerprint scanner to verify your identity, and the next customers certainly don't want to touch the device after you've had your way with it.
More details on WSQ format: http://en.wikipedia.org/wiki/Wavelet_Scalar_Quantization
Even if you just store minutiae points (lists of X,Y coordinates of "interesting" points in the image like ends, bifurcations, etc), recent research shows how to generate a plausible fingerprint image that has those same minutiae. Here's one work: http://www.cse.msu.edu/biometrics/Publications/Fingerprint/F... Take a look at the pretty figures. This was done four years ago; it's only gotten better since then.
"Led by Stephanie Schuckers, an associate professor of electrical and computer engineering at Potsdam, N.Y.-based Clarkson University, the researchers tested 66 Play-Doh copies of real fingerprints of 11 different people. The fake fingerprints were verified as the real deal 90 percent of the time."
http://www.informationweek.com/biometric-readers-fooled-with...
Mythbusters tested a bunch of fingerprint readers and they could break even a few of the ones with "life" detection.
It's no different from the windows SAK (ctrl-alt-del) or the Mac "administrative user" dialog box.
To sign on and off, I would enter my 6 digit employee number into a pin pad, then scan my right index finger.
It worked about 99% of the time, and mostly only failed because I worked in the meat dept. and often my hands would be extremely hot and wet from soap & hot water, or frozen and numb from handling meat all day. Then I would just use my left index finger.
It worked great in 1997, I see no reason it can't in 2013.
You may use a passphrase. But that would be as secure as using a passphrase alone.
Fingerprint is the public key. The private key would be your hand + your physical presence. However, since fingerprint itself is public, you can't rely on fingerprint to identify physical presence.
Unless, you make fingerprint private enough. For example, permanently attach something on to your finger. Instead of providing your fingerprint to third-party application, it generates a key pair based on your fingerprint, and use these keys for authentication.
and yes, we need this. convenience is the antithesis of security, so anything that builds a bridge for more users is welcome.
I'm sure Apple are aware that storing the "plaintext" equivalent of a finger print would defeat the entire purpose.
What's great is there is an NFC Yubikey that I just put close to my phone to get the phone version of LastPass to auth.
Bipartite biotokens do seem significantly more secure than naked biometrics, but I'm not sure I understand the benefit if security still boils down to user passwords, especially if one assumes that any static security component will eventually be compromised.
Using the password to salt the original biometric improves privacy and security, but there are a lot of other ways to compromise biometrics - people look at a lot of cameras and leave a lot of fingerprints, and existing biometric systems (while improving) are fooled by photocopies.
Boult and Scheirer, the author of the above paper, gave a great tutorial about these kinds of privacy/security issues at 2011's International Joint Conference on Biometrics (IJCB), if you're interested about learning more. Both happen to be my former advisors too ;)
Tutorial: http://www.securics.com/~walter/IJCB2011/
Slides, "Part I: An Overview of Issues Related to Biometric Privacy and Security" http://www.securics.com/~walter/IJCB2011/IJCB11-tutorial-par... "Part II: A Survey of Template Protection Technologies" http://www.securics.com/~walter/IJCB2011/ijcb-survey-templat...