News
3/18/2013
12:00 AM
Dave Kearns
Dave Kearns
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

With Biometrics, Can Fingers Do Password Management's Work?

Biometrics are one way end users can, literally, "give the finger," to cumbersome password management systems. But it won't be cheap.

Why haven't companies replaced clunky password management with fingerprint biometrics for mobile device authentication? Three words: fear, uncertainty, and doubt (FUD).

The vendor Sileo once claimed in a blog post:

In a worst-case-scenario, someone inside of the biometric database company could attach their fingerprint to your record — and suddenly they are you. The reverse is also true, where they put your fingerprint in their profile so that if they are convicted of a crime, the proof of criminality is attached to your finger.

Sileo was either purposely lying or extremely naïve. The fingerprint stored in the database has no possible use to law enforcement, because it isn't an image of your finger. The reader and the accompanying client software take multiple measurements (the best take many, many measurements) of the ridges and valleys on the tip of your finger. They then compute a number according to a proprietary algorithm and hash that number. That becomes the token for your fingerprint.

Because the token is salted and hashed, it's irreversible. Even if you have all the computing power in the world, you simply cannot recreate that fingerprint to implicate someone in a crime.

Another point that's frequently made is that you can easily (and frequently) replace a password, but you can't replace your finger or change your fingerprint. But you've got eight fingers and two thumbs. They have different patterns -- perhaps even more different than your last 10 passwords. How often has your password been hacked? More than nine times? And even though you should probably change the finger you use periodically, reusing a finger after a year or so really shouldn't cause a problem.

Then there are the stories that keep resurfacing about how easy it is to fool a biometric reader with a photograph. And it's true that cheap readers can be fooled. It's the equivalent of having a system that limits passwords to four lowercase letters. Just as you need to consider the strength of your password requirements, you need to consider the sophistication of your biometric readers.

This brings us to the only reason that could stop you from using biometrics: the cost. Passwords can be implemented for no cost. Even password-based single sign-on solutions can be had for less than $10 per user. But even a cheap, easily fooled biometric system will set you back $25-$50 per user. A decent system will more than likely cost more than $100 per user (unless you have tens of thousands of users, but you still likely would pay a half million for one of those systems). What happens when you go to the bean counters and say you want to spend $100 for each employee, partner, client, etc. who needs to authenticate to your system? I don't have to tell you what the answer will be.

It's not the technology that's the problem, really. It's the fear, uncertainty, doubt, and cost. Still, once you've been hacked and the crown jewels have been stolen or leaked, it'll probably be easier to convince the powers that be that a better system is needed. Just hope they don't make you the scapegoat.

This article originally appeared in The Transformed Datacenter on 5/27/2013.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?