6 ms·
Fingerprints were never supposed to replace passwords, they're more analogous to usernames. I like fingerprint scanner as a quick way to unlock my phone, it's
by wjoe 7y ago
Fingerprints were never supposed to replace passwords, they're more analogous to usernames.
I like fingerprint scanner as a quick way to unlock my phone, it's at least more secure than the 4 digit passcodes or patterns I used before that, and more convenient than that or face recognition. But I wouldn't want to use fingerprint to replace entering a password for making payments or accessing any secure data.
- dsr_ 7y agoVehemently agreeing with you. Fingerprints are identification, not authentication or authorization.
- sokoloff 7y agoGenuine question: in what way are fingerprints not authentication? (to a ~1:500K uncertainty)
- consp 7y agoA few issues: First of all because they cannot be revoked. Unless you count cutting tools and torches. Just as well as they can be easily used without the user's consent (e.g. sleeping) without them being aware of it. Note: this does not require stealing anything as in the passphrase case. Additional problems are the high false positive rate. They just identify the user, not an action of authentication/authorization; i.e. a mental action like remembering a password and actively approving something. See it this way: Your bank card identifies you, you pin number authorizes the payment. These are distinct differences. If you ignore authorization you get nfc payments which are very convenient but far less secure and easier to manipulate. Note: your pin can be revoked, your fingerprint can't.