Why your fingerprint may be harder to protect than a password
Biometrics promise a world without passwords — but once your face, iris, or fingerprint becomes a digital file, it can be stolen and never changed. Here's the hidden risk, and how to build smarter passwords instead.
Table of Contents
The End of the Password?
How Biometric Authentication Works
The Hidden Downside of Biometrics
Better, Easier-to-Recall Passwords
FAQs
1 The End of the Password?
Even before the Equifax breach, we knew “password123” wasn’t enough to protect our online data. We’ve been told that constantly by websites requiring us to create a password. “This is weak,” they say. “This password can be easily guessed. Try again.”
So we try again, and come up with a complex password comprising letters, characters, and numbers that a hacker could never guess. Problem is, neither can we the next time we try to access the site. And as we acquire more electronic gadgets that are password-protected, we wish more than anything that someone would devise a simpler method.
2 How Biometric Authentication Works
Well someone has: biometric authentication. Some of these techniques have been around for years. Fingerprint and facial or iris recognition software are almost old hat by now. Newer advances use other types of human characteristics to identify a person. Primarily funded by the Defense Advanced Research Projects Agency (DARPA), researchers are working on ways to use various unique signatures of our bodies to access our devices, doing away with passwords entirely. Such identifiers as the way you walk, the way you type or click, your heartbeat, even the way you scroll down a screen are said to be unique to you, and thus a secure way to provide so-called “active authentication.”
And as reported in Britain’s The Telegraph, the Biometric Research Group says that 650 million people were already using biometrics to operate their mobile phones at the end of 2015. That number is expected to grow to two billion or more by 2020.
3 The Hidden Downside of Biometrics
Hooray! Never another password to invent and try to remember. But, is there a downside?
The information obtained from your body is—like everything else in the cyber world—converted to digital data which is then stored. If it remains on your device, that’s probably not a problem. But some devices may transmit and store the data in a remote server, using complex algorithms to verify your identity.
As a Scientific American article on the subject put it, “once your face, iris, or DNA profile becomes a digital file, that file will be difficult to protect. … Biometric identifiers could also be stolen. It’s easy to replace a swiped credit card, but good luck changing the patterns on your iris.”
“A central repository of biometric data would be a gold mine for hackers,” Salis Prabhakar, CEO of mobile security company Delta ID, told cybersecurity news site The Parallax. The site noted, “someone who has access to your raw biometric data could use it to access your accounts, steal your identity, or even implicate you in a crime.”
And as Tim Edgar, a professor in Brown University’s Executive Master in Cybersecurity program told The Parallax, no biometric measure is 100% accurate, even under ideal conditions. Inaccuracy in this area could result in someone being falsely identified—and treated—as a known felon or a suspected terrorist.
Then there’s the potential commercial value of biometric identification. Joseph Atick, who helped invent facial recognition technology 25 years ago, recently told CBS News that tracking users is so valuable to marketers that tech companies can’t be trusted to self-regulate their use of biometrics.
“You broke my password, I’m going to change it,” he said. “I can’t change my face, I can’t change my fingerprints. I need some mechanism to protect me.” That mechanism, he said, would be a guarantee that all biometric information remains on the device.
4 Better, Easier-to-Recall Passwords
So until we have better laws in place to protect our biometric data, Billshark recommends the following tips to creating better, easier-to-recall passwords.
Using a ridiculous “passphrase” is better than a single word, even with some letters of that word replaced by characters, because they are almost impossible to guess. Rubberwinewrinkles, for example, is not only difficult to say, but impossible to guess, even with a sophisticated computer algorithm.
For sites that require upper- and lower-case letters and characters, you could capitalize just a single recurring letter (rubberwInewrInkles) and add an unusual character at the beginning or end ($rubberwInewrInkles).
Because it’s crucial to have a different password for each site you use, you could add an identifier for each site to your now all-purpose passphrase. For Facebook, you could use: $rubberwInewrInklesFB, F$rubberwInewrInklesB, $rubberwInewrInklesfb ... whatever helps you remember most easily.
Alternatively, you could use a password manager program or a web storage service, which can generate secure passwords and store them online.
Or you could employ two-factor authentication (known as “2FA”), which, in addition to the password, uses a follow-up text with a code or an app which can verify your identity.
Whichever way you choose to go, investigate and evaluate the best method for you. Just don’t depend on “password123.”
Share:
Billshark · Bill Negotiation Experts Helping consumers and small businesses stop overpaying on recurring bills.
Frequently Asked Questions
What is biometric authentication?
Biometric authentication uses unique signatures of your body to identify you and access your devices, doing away with passwords. Familiar methods include fingerprint, facial, and iris recognition. Newer, DARPA-funded research explores other identifiers like the way you walk, the way you type or click, your heartbeat, and even the way you scroll down a screen to provide so-called active authentication.
Why is biometric data riskier than a password?
Once your face, iris, or DNA profile becomes a digital file, that file is difficult to protect and can be stolen. The crucial problem is permanence: it’s easy to replace a swiped credit card, but you can’t change the patterns on your iris, your face, or your fingerprints. If stolen, that raw biometric data could be used to access accounts, steal your identity, or even implicate you in a crime.
Is biometric security 100% accurate?
No. According to Tim Edgar, a professor in Brown University’s Executive Master in Cybersecurity program, no biometric measure is 100% accurate, even under ideal conditions. Inaccuracy in this area could result in someone being falsely identified and treated as a known felon or a suspected terrorist.
How can I create a strong password that’s easy to recall?
Use a ridiculous passphrase rather than a single word, since it’s almost impossible to guess. For sites needing mixed case and characters, capitalize a single recurring letter and add an unusual character at the start or end. Because each site needs a different password, append a site identifier to your all-purpose passphrase to keep it memorable.
What alternatives to memorizing passwords does Billshark suggest?
You could use a password manager program or a web storage service, which can generate secure passwords and store them online. Alternatively, you could employ two-factor authentication, known as 2FA, which in addition to the password uses a follow-up text with a code or an app to verify your identity. Whichever you choose, just don’t depend on password123.