Hacker News new | ask | show | jobs
by lolsal 3205 days ago
Why? I am not terribly upset if someone has my username, but I would be very concerned if they had reproducible biometrics of mine (fingerprints, facial, etc).
2 comments

Usernames are fixed values and are generally public. Biometrics are also fixed values and are generally only slightly less public. They're both identifiers.

Passwords can be changed and are secrets. They're authenticators.

The difference between them is exactly the difference between identifiers and authenticators. Misunderstanding this difference causes tons of issues, in a wide variety of situations. The most notable one recently is probably Social Security Numbers being used as both, which leads to identity theft.

Because biometrics are usually relatively publicly accessible information. Passwords aren't. You're arguing reproducibility. Well, your face can be replicated by a picture you put on Facebook, fingerprints are left everywhere you go.