Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a "something you are" authentication factor, since it is presumed that the cost of faking a fingerprint is too high to be worth it in those cases.


https://www.schneier.com/crypto-gram/archives/2002/0515.html...

"He used $10 of ingredients you could buy, and whipped up his gummy fingers in the equivalent of a home kitchen. And he defeated eleven different commercial fingerprint readers, with both optical and capacitive sensors, and some with "live finger detection" features."

That article's a little old now and the tech may well have improved since but I wouldn't put too much faith in fingerprint readers. (Also: other attack vectors exist).


The sensor is pretty good at detecting real finger since it's tuned to the capacitance of human skin, possible to fake but not particularly easy.

If they'll move to the new optical sensors the the refracted IR ones can sense the flow of blood in the veins of your finger.


They (including Apple) told us once too often that their new fingerprint sensor will now really, really, finally solve all issues. With every new generation they tell us that all flaws of all previous generations have been solved. And once too often, they we proven to be wrong.

So I agree with zwp (not sure why he was downvoted):

I wouldn't put too much faith in fingerprint readers.


My point is that this is still more expensive than harvesting knowledge factors with phishing and stealing dbs where people use the same factors.


Yeah, I'm not an international spy: even if it is 'easy', nobody is going to spend a few hours faking my fingerprint just to get into my phone or my laptop. And if they are so motivated, then there's a much bigger problem at hand.

There are plenty of people still using 4 digit passcode (especially simple ones like 0000 or 1234) which is easy to 'steal' by watching somebody unlock their phone before pickpocketing them.


The bigger issue in my mind is revocation and separation of identities. I only have one set of fingerprints. What's more, I may not want my biological identity connected to online identities. It would be like having to give every website your SSN/National ID to identify yourself rather than merely a unique ID. You are giving out a huge amount of info with your fingerprint.

Now some of the above issues aren't specifically in play with this particular app: It's locally owned/controlled hardware only. Also, as you say most of us aren't international spies (though I do find that getting a bit close to 'I have nothing to hide').


As you point out, there's a right way to do fingerprints, which Apple did. Only the key pair stored in the secure enclave is tied to your online identity.

There is a missing link in the trust chain though, which is attestation of that secure enclave (how do we know it is a legitimate and uncompromised one?) However, privacy preserving attestation mechanisms such as DAA [1] require somewhat expensive crypto.

[1] https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation


A sensible approach would be to have a master token which is unlocked using your fingerprint and used to generate one-time tokens for identification - perhaps like Apple Pay.


I wonder how much the cost will be reduced though considering that you will most probably be able to find a matching fingerprint on the same keyboard.


Use your thumb print.


Lift the thumbprint off of the TouchID sensor itself? That is, assuming the premise of the grandparent comment is valid and fingerprints lifted off of the keyboard would be enough.


You only use your thumb on the space bar, and when you do, it's the side. But when you scan your thumb, it's the face of the print, ergo, impossible to lift thumb print from nearby key.


Slide, rather than raise, your thumb off the sensor.


When I hold my phone, I use my opposable thumb to hold the front of the phone. Anyone can lift it off there.


I guess I like the trade-offs of something-you-have/something-you-know even if the cost of faking them is actually lower.

I am probably in a minority.


When done correctly, fingerprints are both something you are and something you have: The fingerprint data should reside in and work only to activate an HSM that then proves possession of an attested key pair. That way the HSM (and the device it sits in) is your something to have.


Could you setup your system to still need "something you know" when logging in, but use your TouchID for additional authentication (like sudo) once already in the system?

That seems like the best of both worlds there.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: