Endpoint // Authentication
03:45 PM
Sara Peters
Sara Peters
Quick Hits
Connect Directly

UK Reconsidering Biometrics

Parliament is looking for answers about biometrics' privacy, security, future uses, and whether or not legislation is ready for what comes next.

Two years after the UK government decommissioned its controversial Iris Recognition Immigration System, Parliament has launched an inquiry into both the public and private sector's current and future uses of biometrics.

From the Parliament reference document:

    Commercial organisations, however, are starting to play a greater role in both developing and using biometric data and technologies. It is anticipated that this trend will continue over the next decade, particularly as the financial costs, and computational resources required, decrease. Some commercial uses are already mainstream. Social media sites offer facial recognition software to assist users tagging uploaded photos, while accessing some mobile phones depends on fingerprint recognition rather than entering a passcode. Supporters contend that technologies relying on biometric data have transformed identity authentication. However, concerns continue to be raised about data protection, loss of privacy and identity theft.

Though the IRIS system was shut down after eight years of use, the UK still uses biometric systems for e-passports and residence permits.

The Parliament Science and Technology Committee is seeking answers to questions about research and development priorities; potential uses of biometrics; the challenges of developing, implementing, and regulating biometric technology; and the effectiveness of current legislation in governing the ownership of biometric data and who can collect, store, and use it.

The deadline to submit comments to Parliament is Sep. 26.

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Robert McDougal
Robert McDougal,
User Rank: Ninja
8/16/2014 | 10:29:10 AM
Re: Security, privacy
I agree that we need more security, but I also agree we need to find the balance with privacy.  Something along the lines of using biometrics for authentication but not keeping records for longer than 90 days.
User Rank: Apprentice
8/14/2014 | 12:59:11 PM
Re: Security, privacy
Not necessarily. Having stronger authenitcation would make it more difficult to have someone exploit your authenticator to see your information - which is only one aspect.  Using the same username (or biometric authenticator) could facilitate correlating access to two entirely different system - which may allow for unwanted leakage of private information.  If I have two completely unrelated username/password combination - the act of authenticating to two separate suites is more difficult correlate.  If one is facebook (where I have probably exposed to myuch info) and another is a health related web site which I have not talked about - being able to link the two could be a bad thing.


Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
8/14/2014 | 11:37:39 AM
Re: Security, privacy
Whoopty, wouldn't having more a secure form of authentication such as biometrics give you more privacy protection, not less? 
User Rank: Ninja
8/13/2014 | 11:17:26 AM
Security, privacy
While I really like the idea of biometrics being used for security - I have to remember too many passwords as it is - I'm wary of activity trackers and similar devices with lax privacy policies. I really don't want my insurance firm trying to find out anything about my health through a third party, or my bank checking my health to see how it would affect a mortgage. 

Some information should remain personal.
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-02
Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.

Published: 2015-10-02
Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684.

Published: 2015-10-02
Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211.

Published: 2015-10-01
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

Published: 2015-10-01
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.