Hacker News new | ask | show | jobs
by floatingatoll 2358 days ago
Can we calculate reproducible cryptographic private keys from fingerprints?

If you solve that, you'll unlock an entire business model centered around "anonymous entities that can be regenerated at any time using a biometrics booth at the mall and a secret passphrase known only to you".

2 comments

That's even worse. Impossible to change fingerprints if a malicious party has your biometrics.
Secure enclave like with Ios is an option. You never give your biometrics away.
Sure, I'm all for a key based solution. My opposition is against using biometrics for anything beyond convenience features.
Biometrics are relatively convenient and very safe when they're used in place (not remotely) with a human agent overseeing. No cops have ever let a suspect pop out to buy a 3D printer and some custom moulds before taking their prints. The airbase's gate guard isn't going to let you substitute a custom-made adversarial JPEG image for your face after asking you to roll down the window even though her normal job is statistical analysis and she has never fired that weapon she's carrying in anger.

They're not great without supervision and they're completely hopeless remotely.

> Biometrics are relatively convenient and very safe when they're used in place (not remotely) with a human agent overseeing.

In your estimate, how large a percentage of biometric security implementations follow your description?

Yea but you'd literally be leaving your private key everywhere you are.
If you seared your passphrase into your fingertips, sure. There's a reason it's not just 'fingerprints only' or 'passphrase only'.