Tentative agenda: Overview of the product
- what is it, how it works
- deep dive in tech
- security
- comparison to other solutions
- Addressing individual concerns from HN comments- Q&A
23 karma · joined July 4, 2016
Tentative agenda: Overview of the product
- what is it, how it works
- deep dive in tech
- security
- comparison to other solutions
- Addressing individual concerns from HN comments- Q&A
As for the "overall impressions", It is usually recommended to try something first and then form an impression. Otherwise, it's just an opinion
Early on, we've conducted a handful of end-user interviews - knowledge workers, various industries, fluent with computers. We conducted a series of hour-long video calls, recorded them with permission to re-watch them later, and asked the questions like - how do you think about privacy? How do you think about the performance of faceID or similar? How do you think about biometrics and privacy? Will you be open to try a solution that uses your biometrics from an unknown vendor? Etc.
The result, somewhat surprisingly, boiled down to a few bullet points: 1. Performance- "If it works and I can log in, that's enough assurance." 2. Privacy and data - "Have an FAQ section or show in me onboarding that you don't sell my data for surveillance - that's good for me."
We've been prepared to answer the "SOC 2 Type2 -style" question regarding performance and data privacy, but no one really cared. What users did care about is "can I add this app to my account?" and other feature requests.
-> Fingerprints are just more convenient. Apple, for example, argued the false positive rate way too high. For me, as a user, I'm more concerned about the false-negative rate. I think Apple just wanted more screen real estate. They could've easily put the sensor on the back (eg like the Samsung Galaxy S8).
I agree, a matter of fact fingerprint sensor on the back of a phone is arguably the most efficient way to unlock a phone. With desktops, it varies quite significantly.
-> - Masks!
for what its worth, one user told us that they have successfully logged in while having a green mint facial care mask on..:)
-//-
By no means Entry is the best tool out there, nor we claim it to be so. Here are a few known flaws:
- if someone has two or three monitors and it is unclear where the camera is, it requires some time to get used to, which may be annoying - to your point, Entry will not work in a pitch-black room - Entry is by no means "fingerprints-fast": as a factor, Entry competes with the time it takes to reach a phone and click on push notification. For example, mean time to verify using Okta Verify (default mfa solution for okta sso) is ~21 seconds. For Entry it's 30 seconds. We still need to work on that (although our users still choose Entry over Verify, we ask to have both factors set up :) )
They detect mask-attacks, replay attacks (put the phone with video into the camera; highjack a webcam input and send a pre-recorded video faking to be real-time from zoom for example), and, of course, still images.
Give it a try!
In reality, the production-grade security comes from a compound effect of three components: face-recognition, antispoofing for face recognition, and traditional controls of industry-standard protocols like SAML 2.0, OIDC, etc. Taking one of three out of the equation renders security nonexistent.
For SSO, Entry can be added as SAML 2.0 Factor today. I agree if we would not have solved the spoofing problem, taking the Auth0-style route for native platforms is the way to go.