News
3/18/2013
12:00 AM
Dave Kearns
Dave Kearns
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

With Biometrics, Can Fingers Do Password Management's Work?

Biometrics are one way end users can, literally, "give the finger," to cumbersome password management systems. But it won't be cheap.

Why haven't companies replaced clunky password management with fingerprint biometrics for mobile device authentication? Three words: fear, uncertainty, and doubt (FUD).

The vendor Sileo once claimed in a blog post:

In a worst-case-scenario, someone inside of the biometric database company could attach their fingerprint to your record — and suddenly they are you. The reverse is also true, where they put your fingerprint in their profile so that if they are convicted of a crime, the proof of criminality is attached to your finger.

Sileo was either purposely lying or extremely naïve. The fingerprint stored in the database has no possible use to law enforcement, because it isn't an image of your finger. The reader and the accompanying client software take multiple measurements (the best take many, many measurements) of the ridges and valleys on the tip of your finger. They then compute a number according to a proprietary algorithm and hash that number. That becomes the token for your fingerprint.

Because the token is salted and hashed, it's irreversible. Even if you have all the computing power in the world, you simply cannot recreate that fingerprint to implicate someone in a crime.

Another point that's frequently made is that you can easily (and frequently) replace a password, but you can't replace your finger or change your fingerprint. But you've got eight fingers and two thumbs. They have different patterns -- perhaps even more different than your last 10 passwords. How often has your password been hacked? More than nine times? And even though you should probably change the finger you use periodically, reusing a finger after a year or so really shouldn't cause a problem.

Then there are the stories that keep resurfacing about how easy it is to fool a biometric reader with a photograph. And it's true that cheap readers can be fooled. It's the equivalent of having a system that limits passwords to four lowercase letters. Just as you need to consider the strength of your password requirements, you need to consider the sophistication of your biometric readers.

This brings us to the only reason that could stop you from using biometrics: the cost. Passwords can be implemented for no cost. Even password-based single sign-on solutions can be had for less than $10 per user. But even a cheap, easily fooled biometric system will set you back $25-$50 per user. A decent system will more than likely cost more than $100 per user (unless you have tens of thousands of users, but you still likely would pay a half million for one of those systems). What happens when you go to the bean counters and say you want to spend $100 for each employee, partner, client, etc. who needs to authenticate to your system? I don't have to tell you what the answer will be.

It's not the technology that's the problem, really. It's the fear, uncertainty, doubt, and cost. Still, once you've been hacked and the crown jewels have been stolen or leaked, it'll probably be easier to convince the powers that be that a better system is needed. Just hope they don't make you the scapegoat.

This article originally appeared in The Transformed Datacenter on 5/27/2013.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5426
Published: 2014-11-27
MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows remote attackers to cause a denial of service (unhandled exception and DNP3 process crash) via a crafted message.

CVE-2014-2037
Published: 2014-11-26
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vulnerability exists because of an incomplete fix for CVE 2013-6466.

CVE-2014-6609
Published: 2014-11-26
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

CVE-2014-6610
Published: 2014-11-26
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dia...

CVE-2014-7141
Published: 2014-11-26
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?