http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
Biometric information is a means to verify identification. A username and a password is also a means to verify identification. A fingerprint is no more a username than a password is a username. In the case of a username/password it's the combination that's required to verify the identity.
Is it really? I think if I send you an email at colinbartlett@whateversitehostsyouremail.com I've verified your identity as much as I need with only your username.
A username and password is a case of identification (username) and authentication (password). Authentication is proof. When you have authenticated identification (like a username and password) it's proof that the person is why they say they are.
The reason people conflate identification with authentication is that we typically use the two together. But there are lots of cases where we only care about one or the other.
For example, many systems (such as routers) implement administrative tasks with an administrative password. You don't care who performed the task, you only care that they had permission to do it. That's authentication without identification.
Similarly, there are plenty of cases where you don't care about authentication, you only care about identification. For example, anyone can send you an email. On many systems you can send people messages anonymously: there's no authentication necessary, no proof of anything necessary to be allowed to send the message. The only thing necessary is the identity of the receiver. That's identification without authentication.
Fingerprints are identification. They are used as authentication because the difficulty of collecting the identification gives a small barrier to falsifying authentication, but they're pretty terrible for that purpose. You leave your fingerprints all over the place: it's like if you just went around writing your bank PIN everywhere. There are already proofs of concepts of people constructing fingerprints from polymers; this is a simple case of privilege escalation, where gaining one level of privilege allows you access to a higher level of privilege. Given that most people give everyone access to their fingerprints that's a pretty low point to allow escalation from.
Sure, a fingerprint might be one of several factors for authentication at secure sites, but that is rarely the only thing. It usually coincides with badge readers, photo-ID, etc.
Ok. Neither the argument nor your counterargument really make sense. Yeah you can argue a very long username, something like a UUID might as well be a username and password all in one in some circumstances.
But stepping back, this is kind of a dead end argument. It doesn't help with security. Biometric information and username/pass both have enough cons that you really want both.
Basically you need both:
* Something you know (your username/password)
* Something you have (some kind of a card, your finger, you retina, some physical token).
[Ok some researches say "biometrics" is something else not just "something you have" it is inherence -- something you "are". But well, I cut your finger and now it isn't something you "are" anymore. It is something _I_ have]This is the classic multi-factor authentication, most commonly used version is 2FA (two-factor authentication).
Fair enough. I agree that it should be, and that perhaps saying "they're usernames" is not really the way to go.
But would you set your password to something you leave on almost every surface you ever touch?