Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

„But biometric authentication does not fulfill the advertised security promises“

This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.



Here's some context:

    The patterns in your irises are unique to you and are
    virtually impossible to replicate, meaning iris
    authentication is one of the safest ways to keep your
    phone locked and the contents private.
Source: http://www.samsung.com/global/galaxy/galaxy-s8/security/

I think the quote is fair.

Also your pin disabled argument doesn't make a lot of sense. That's like saying 123456 is a good password because many people disable the password prompt at login.


A pin of 123456 is more secure than no pin at all.


Yes, but that doesn't say anything about the security of passwords in general. (The same way that bad iris recognition being better than no auth at all doesn't say anything about the security of iris recognition in general.)


I can obtain an image of you online, while I need to be on-site to spot you typing your pin. So if I have your phone, I can do research at home to break in.

Additionally, you cannot change your iris once it's compromised. This is an absolute no-no for secure systems! Changing your pin is easy.

This is definitely not a huge step forward. And, as already mentioned, the average user gets misguided by exaggerated marketing promises.


A random photo on the net probably doesn't have the resolution needed for Iris recognition


The CCC used an old digicam at medium distance. It is quite likely that such a photo is on FB, Instagram etc.

Side note: The CCC even recovered the fingerprint of the Germany's defense minister from a photo: https://www.theguardian.com/technology/2014/dec/30/hacker-fa...


They also used the IR mode of a digicam. That hack is not possible from existing photos only, I think.


Yeah then Samsung's "iris recognition" is more like "iris blur matching"


The trouble with statements like 'for the average xyz user' is:

1. 50% of your users won't have their needs met - that's a large proportion assuming a uniform distribution

2. We can't be sure a uniform distribution in the first place is appropriate

3. If we're going to assume an average user then why don't we assume an average phone too: If the average user gets by without something today then why bother building it as a new feature?

In the end a product should not be designed for an average user. It should be designed for a well defined audience who's needs will met well by the product. If you're going to bother with fancy biometric tech as a feature and selling point then you're clearly NOT aiming at the average user who couldn't care less...


> The trouble with statements like 'for the average xyz user' is: 1. 50% of your users won't have their needs met

Oh come on. You know what's meant: no nerds. That's 99% of users who'll have their needs met, not 50%.


These are general consumer devices and there are trade offs. The most sophisticated hacker the vast majority of users must defeat is a prying family member or friend.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: