Fingerprints NEVER Trust them

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • irneb
    Gold Member

    • Apr 2007
    • 625

    #1

    Fingerprints NEVER Trust them

    Was in two minds as to which forum to post this to. Either tech or spam ... but I thought this might be a better fit:

    The world’s most powerful companies want you to log in with fingerprints and eyescans


    Probably the most stupid thing in the world is to make use of your fingerprints as a pass key.

    The 2 major flaws are:
    1. Inability to change your fingerprints - so after a database is compromised that's it (and face it many sites have been compromised in the past and they certainly won't be the last). You're stuck with 10 chances for life, unless you want to start using your toes or get a finger transplant
    2. The more scary version: Using your fingerprints as a pass key is worse than tattooing your password on your hand. You're basically making a physical copy of your pass key on everything you ever touch. It's more like writing your password down on everything around you, ever, throughout your entire lifespan. Are you going to keep wearing gloves?


    And that's not even trying to consider any further problems like the level of hashing - the stronger the hashing the more finicky the password scanner becomes. The more usable it is the more chance that someone else's fingerprint might be recognized as yours. Or even worse - you're now using the same "password" for everything from your bank account to your facebook login to the password for this site.

    So fingerprints (contrary to actually making a better pass key) has all the problems of passwords (e.g. forgetting which finger you used and at what angle you pressed), but adds some scary ones of their own.
    Gold is the money of kings; silver is the money of gentlemen; barter is the money of peasants; but debt is the money of slaves. - Norm Franz
    And central banks are the slave clearing houses
  • CLIVE-TRIANGLE
    Gold Member

    • Mar 2012
    • 886

    #2
    You also have an outstanding chance of having said finger forcibly removed in good old RSA.

    Comment

    • irneb
      Gold Member

      • Apr 2007
      • 625

      #3
      It seems we're going to be forced to use this absolutely inferior "passkey": http://businesstech.co.za/news/softw...st-sa-economy/

      Looking forward, he said that the fingerprint technology will see users making use of their fingerprint to make online mobile payments, purchase merchandise offline and sign into online banking, without making use of codes or credit card details.
      Wow! So instead of giving just your ICV number to the one party you're purchasing from, you give your fingerprint to every one who walks past the same lamp post you touched. That's soooooo "intelligent" isn't it?
      Gold is the money of kings; silver is the money of gentlemen; barter is the money of peasants; but debt is the money of slaves. - Norm Franz
      And central banks are the slave clearing houses

      Comment

      • adrianh
        Diamond Member

        • Mar 2010
        • 6328

        #4
        Some companies take all ten prints and ask for a specific one at random...

        Comment

        • Justloadit
          Diamond Member

          • Nov 2010
          • 3518

          #5
          What they are not considering, is that a number of the population will have a huge problem being identified, as their finger prints on many occasions are worn down by the kinda work they do. One which immediately comes to mind is brick layers, the handling of bricks acts like sand paper on the fingers. Also many of the other manual type of work, which requires the handling of material will also affect the finger prints.
          Victor - Knowledge is a blessing or a curse, your current circumstances make you decide!
          Solar pumping, Solar Geyser & Solar Security lighting solutions - www.microsolve.co.za

          Comment

          • irneb
            Gold Member

            • Apr 2007
            • 625

            #6
            Originally posted by adrianh
            Some companies take all ten prints and ask for a specific one at random...
            That makes the cardinality 10 ... with a very "insecure" password of 3 letters all upper-case alphabetical the cardinality is 26 x 26 x 26 = 17576. So then someone just has to go to the tread-mill you've just finished with at the gym and they've got all 10 your "passwords". Even if they then figure out that someone screwed up by not noticing which finger went where - and they tried all 10 ... it's still impossible for YOU to change those.

            Originally posted by Justloadit
            What they are not considering, is that a number of the population will have a huge problem being identified, as their finger prints on many occasions are worn down by the kinda work they do. One which immediately comes to mind is brick layers, the handling of bricks acts like sand paper on the fingers. Also many of the other manual type of work, which requires the handling of material will also affect the finger prints.
            Very good point also! I had this with a clock-in system at work. Was doing some house repairs over a weekend and on Monday the reader wouldn't accept my print.
            Gold is the money of kings; silver is the money of gentlemen; barter is the money of peasants; but debt is the money of slaves. - Norm Franz
            And central banks are the slave clearing houses

            Comment

            • pmbguy
              Platinum Member

              • Apr 2013
              • 2095

              #7
              What about finger/hand tsotsi's? Not for me thanks
              It is not the strongest of the species that survive, nor the most intelligent, but the one most responsive to change. – Charles Darwin

              Comment

              • Houses4Rent
                Gold Member

                • Mar 2014
                • 803

                #8
                Is it really that easy to lift a finger print and make it usable? How woudl one do that? I remember when the cops brought their "specialist" I ended up with a royal mess from all that black powder and no usbale finger print harvested. I decided there and then that I will never allow that again as the cleaning up is just too much hassle. It even went into the wood grain of my old furniture.
                Houses4Rent
                "We treat your investment as we treat our own"
                marc@houses4rent.co.za www.houses4rent.co.za
                083-3115551
                Global Residential Property Investor / Specialized Letting Agent & Property Manager

                Comment

                • lewskannen
                  Full Member
                  • Feb 2011
                  • 38

                  #9
                  Originally posted by Houses4Rent
                  Is it really that easy to lift a finger print and make it usable? How woudl one do that? I remember when the cops brought their "specialist" I ended up with a royal mess from all that black powder and no usbale finger print harvested. I decided there and then that I will never allow that again as the cleaning up is just too much hassle. It even went into the wood grain of my old furniture.
                  Yes, it is.

                  We actually tried this on a laptop. We had the owner drink from a tin of coke. We lifted the fingerprint, processed and printed it. We managed to log into the system without any issues.

                  Normally, this software identifies a couple of unique features to a fingerprint. It is these same features it uses to authenticate the user. As long as you lift and print the fingerprint in almost the same size, you will gain access to the system.

                  For some time now fingerprints alone have not been a secure method of authentication.

                  Here is a nice DIY for doing just this - http://www.instructables.com/id/How-...stem-As-Easy-/

                  Comment

                  • irneb
                    Gold Member

                    • Apr 2007
                    • 625

                    #10
                    And a new update on this: http://www.computerworld.com/article...he-future.html

                    WTF? Really? So now it's you face they want to recognise! I.e. everyone ... go tattoo your current password on your forehead and from now on you're not allowed to change it ever again!

                    I can't believe these guys. Can't they even just think slightly further than "Uhm ... everyone has a unique face / fingerprint / iris / etc. don't they?"
                    Gold is the money of kings; silver is the money of gentlemen; barter is the money of peasants; but debt is the money of slaves. - Norm Franz
                    And central banks are the slave clearing houses

                    Comment

                    Working...