Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I look at biometrics as just another category of of the 2nd factor: things you have.

You have your fingers. You have your eyes.

In fiction and movies, these things that you have which could be taken from you (your fingers severed, your eyes plucked out) and used for getting past biometric scanners.

In real life there are easier, stealthier, and less gruesome methods for getting those things: just copy them. (gummy bear fingerprints, anyone? [1][2][3])

[1] - http://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_f...

[2] - http://www.cryptome.org/gummy.htm

[3] - http://www.it.slashdot.org/story/10/10/28/0124242/aussie-kid...



Unfortunately biometrics are near to useless for remote authentication. The only context in which biometrics work is when the whole authentication chain (reader, cable, computer, network) is tamper-proof. When one of these elements can be tampered with (e.g. unplugging the fingerprint reader and sniffing to the USB traffic), it becomes "something you know, that anyone can collect, that you can reproduce with an HD picture, and that you cannot revoke without losing your physical integrity".

I think biometrics may have a place in tamper-proof devices like iphones (infamous error 53) or biometric smartcards (need fingerprint to unlock secrets).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: