Hacker News new | ask | show | jobs
by number6 883 days ago
Biometrics are a terrible choice for sensitive information:

* It is easier to push your thumb on a screen than to pry a password out of your head. (relevant XKCD: https://xkcd.com/538/)

* You will leave fingerprints and other biometric features everywhere.

2 comments

> Biometrics are a terrible choice for sensitive information [..] It is easier to push your thumb on a screen than to pry a password out of your head

It's way worse than that, you may only need photographs of someone's thumb:

https://arstechnica.com/information-technology/2014/12/polit...

The gummy bear method needed actual fingerprints from the victim (for instance lifted from a glass the victim had touched).

The CCC improvement worked merely from photos of the victim's thumb...

Depending on jurisdiction, there might be cases where law enforcement can force you to use your biometric to unlock your phone but they can’t force you to reveal your pin. Reality vs what’s technically legal makes this comparison hard (ie consult with a local legal expert).