My voice is my passport
sixcolors.com
sixcolors.com
His main point is not that it will be fast/secure/good.
Fingerprints and a password, sure, but fingerprints only is the worst idea possible.
I'm absolutely sure that a much smaller percentage of fingerprint protected phones are accessed by unauthorized persons than passcode or password protected phones.
To get someone's fingerprints, I can simply wait until they touch something, or if I don't want to do it that way, I can take a picture of their fingers. I could do this from a distance without them ever knowing.
Sure, once I have their passcode, it's a lot easier that making the physical fake fingerprint, but getting a copy of their fingerprint is easy.
You could also be compromised by your glass in a bar, a handshake, the door handle of your car or your house.
Passwords can be changed but you can't change a finger so this sums up why fingerprints are shit.
Most importantly, it requires a perfect finger print image. Random smears from your phone screen or a glass won't work.
The process is so complicated that only a very small percentage of the population is able to do it; anyone can peek over your shoulder when you unlock your phone (which most people will do dozens or hundreds or hundreds of times per day).
Last, remember that you only have limited attempts with your fake finger; in the demonstration video they only show unlocking a freshly trained phone in a controlled setting, they don't actually unlock a phone "in the wild".
Legally, scanners are only allowed to save a certain amount of key points in your fingerprint, not the whole fingerprint.
False-positives are thus likely as are fingerprint collisions (like hash collisions).
And you still can't modify your finger once it has been hacked a SINGLE time.
I'm not claiming that biometric authentication is a good idea against a targeted attack.
But I do think that they offer adequate protection against opportunistic attacks. It prevents random thieves from accessing my data, and it's convenient enough that people actually use it. It will significantly increase security on average.
If someone is targeting you specifically, neither a fingerprint nor a (usually short) passcode is adequate protection.
e: and yes, I believe the default phrase for the voice login option was "my voice is my passport."
It was actually "my voice is my password" not "passport."
I have a pretty severe cold today. My voice is unrecognizable. But I can still remember a password.
All future technology has, apparently, been predicted by 1980/90s sci fi.
/off-topic
In the same fashion, voice identification doesn't seem to be so secure, since it could also be recorded... and if it were commonly used, there would probably be enough incentive to build on top of current text-to-speech and speech synthetizers, to emulate a voice, given enough sample data.
Like Bruce Schneier says... "The lesson is that biometrics work best if the system can verify that the biometric came from the person at the time of verification. The biometric identification system at the gates of the CIA headquarters works because there's a guard with a large gun making sure no one is trying to fool the system."[1]
[1] https://www.schneier.com/blog/archives/2009/01/biometrics.ht...
ie. Google Glass fiasco where you could say, 'OK Google, porn,' behind people who are wearing Google Glass.
Actual voice identification works in a similar way to how apps like Shazam do: they build a "fingerprint" of your voice. This is why it still works if you have a cold, or for some reason the pitch of your voice changes.
It's not designed to be an authentication feature, of course.
Of course if you have a secure pass-phrase you're not gaining too much there. It's already very difficult to break. But ho-hum, it's not automatically a terrible idea.
Someone could record you saying it, but on the one hand I don't think that you're as much at risk from someone around you recording your password as you are from someone trying to guess it, and on the other this is a vulnerability that other forms of password share too - though I grant with a slightly different recording procedure.
It also just doesn't matter for a lot of cases. A lot of the systems people often think of as super important and secure and permanent (like banking) have a fair amount of wiggle room for rollback in the event of fraud/crime/etc, and policies/processes to minimize the extent to which you can carry out irreversible transactions. Security is imperfect, so there's value in a system which is robust to security failure.
http://www.phonelosers.org/2008/05/pla-radio-episode-17-voic...
That was in 2008.