Hacker News new | ask | show | jobs
by dfox 653 days ago
The main issue there is that the mantra something you know, something you own, something you are is completely wrong in the authentication context. The issue there is that the biometric “something you are” cannot be revoked and also depends on the relying system having some kind of secure path to whatever sensor measured it. So in the end as an authentication it is only useful as convenience feature (eg. how TouchID/FaceID works on Apple platforms). Identification is another thing and obviously biometrics are useful there, but well, there are not that many ethical uses for system that does identification without authentication.