The barrier to break would be the "liveness check" - ensuring that you aren't presented with a molded prop, but an actual eye. I'm not sure what the state of the art is with respect to this.
The difference I see between fingerprint and retinal scan is that a fingerprint is readily visible - as this hack proves. I don't think you can capture a reliable retinal scan unless you get within centimeters of someone's eyeball with a scanner.
Additionally, since we're essentially talking about a specialized camera, the system could combine gait recognition (distance), face recognition (mid-distance) and finally retinal recognition (face on scanner). Beat that.
As always, authentication is just about authentication - you are who you "say you are". It has nothing to do with duress, etc.
actor plus doesn't allow for injury to the authentic person.
> face recognition (mid-distance)
photograph or prosthetics + makeup
> retinal recognition
photograph or prosthetic model iris built to beat "aliveness" check
None of these are hypothetical, all have been demonstrated (though perhaps not simultaneously)
To my knowledge the only biometric that hasn't yet been fooled or broken would be a scan of your brain whilst you invoke muscle memory of an action which itself is unknown to anyone but you. I wouldn't wager even that couldn't be scanned and copied in some manner.
[1] Which kind of makes the rest of the system moot. Also, good point about gait recognition.
It wouldn't need to be a real iris. Extant aliveness checks typically look for: reflections, pupil dynamics (contractions etc), frequency/resolution - these are all designed to look for digital forgeries (image on screen or paper); this leaves them open to a prosthetic model of an eye mimicking those effects (think a very sophisticated mannequin or doll's eye) backed by a generated retinal image.
Ultimately (if you want to talk absolutes) as long as the scanner can't differentiate between the original and a cloned + transplanted eye, it can never be considered unbeatable :)
As convoluted as all these sound, they're conceivably within the grasp of technology. It's worth remembering that many commercial scanners currently deployed don't implement any aliveness checks.
I was asking if you are aware of such a thing existing.
In my thinking about this problem from the IoT space lately, I've been thinking about servers assigning credentials to devices, rather than devices telling you their creds. Assign a UUID and let the device generate their password/key, and the pair gives you a multiplicatively large space.
Your notion is interesting. Anything that automates the client-side is good. People are terrible at managing a security contract 'by hand'
{edit} really, this superstitious notion that random numbers are 'not good enough' is embedded in our programmer culture. Folks continue to use lame solutions instead of just buying into the uuid-as-foolproof-identifier. It totally eliminates whole classes of problems and bugs. And you should be more concerned your computer will be hit by lightening, become self-ware and win the lottery 7 times, and molecularly reorganize into a teacup, before that uuid will be duplicated anywhere/anywhen.
Security is always done in layers, though, and while you're correct that it is extremely unlikely, the chance is nonzero. As such you have to prepare for that and design your system to be resilient to these types of things. In castle terms, you trust that no one will ever breach your wall, but that doesn't mean you don't have guards and an armory inside for the unlikely event it does.
EDIT: So does Kinect for Xbox one.
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
Biometric passports with fingerprint data are common in many EU countries. The fingerprint is used to verify a person's identity, so in a way it's used as both a username and password.
Allowing the state to capture and store something very private to every individual is not without controversy. A few years ago, a German man called Michael Schwarz had his application for a passport rejected when he refused to have his fingerprints taken. He took the matter to the European Court of Justice (ECJ). In October 2013, the ECJ ruled in favour of fingerprinting for passports. The ECJ agreed that fingerprinting was a privacy intrusion but that this was outweighed by the need for security and protection against fraud. Strictly speaking, the fingerprint data should only be held in the passport, not in a central database.
Whether you agree or not with fingerprint capture will probably be influenced by how much you trust the authorities in your country. And of course, many countries collect fingerprints from visitors entering their country.
I trust that if I had enemies that needed my fingerprint for something, that could get it easily. I touch enough objects on a daily basis that the likelihood is extremely high. I mean, someone could simply lift them from my front door, or follow me waiting for me to drop a coffee cup in the trash.
Therefore fingerprints are not a good tool when there is a lot of time for the attack, and the value is very high. However when the attack value is low, and the time available is short, they are currently a useful check.
One day, we will probably have a portable fingerprint cloner that changes the economics of this, but until we do, fingerprints are useful.
Since you dismiss biometrics as 'useless', what alternative would you suggest?