Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News

3/18/2013
12:00 AM
Dave Kearns
Dave Kearns
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

With Biometrics, Can Fingers Do Password Management's Work?

Biometrics are one way end users can, literally, "give the finger," to cumbersome password management systems. But it won't be cheap.

Why haven't companies replaced clunky password management with fingerprint biometrics for mobile device authentication? Three words: fear, uncertainty, and doubt (FUD).

The vendor Sileo once claimed in a blog post:

In a worst-case-scenario, someone inside of the biometric database company could attach their fingerprint to your record — and suddenly they are you. The reverse is also true, where they put your fingerprint in their profile so that if they are convicted of a crime, the proof of criminality is attached to your finger.

Sileo was either purposely lying or extremely naïve. The fingerprint stored in the database has no possible use to law enforcement, because it isn't an image of your finger. The reader and the accompanying client software take multiple measurements (the best take many, many measurements) of the ridges and valleys on the tip of your finger. They then compute a number according to a proprietary algorithm and hash that number. That becomes the token for your fingerprint.

Because the token is salted and hashed, it's irreversible. Even if you have all the computing power in the world, you simply cannot recreate that fingerprint to implicate someone in a crime.

Another point that's frequently made is that you can easily (and frequently) replace a password, but you can't replace your finger or change your fingerprint. But you've got eight fingers and two thumbs. They have different patterns -- perhaps even more different than your last 10 passwords. How often has your password been hacked? More than nine times? And even though you should probably change the finger you use periodically, reusing a finger after a year or so really shouldn't cause a problem.

Then there are the stories that keep resurfacing about how easy it is to fool a biometric reader with a photograph. And it's true that cheap readers can be fooled. It's the equivalent of having a system that limits passwords to four lowercase letters. Just as you need to consider the strength of your password requirements, you need to consider the sophistication of your biometric readers.

This brings us to the only reason that could stop you from using biometrics: the cost. Passwords can be implemented for no cost. Even password-based single sign-on solutions can be had for less than $10 per user. But even a cheap, easily fooled biometric system will set you back $25-$50 per user. A decent system will more than likely cost more than $100 per user (unless you have tens of thousands of users, but you still likely would pay a half million for one of those systems). What happens when you go to the bean counters and say you want to spend $100 for each employee, partner, client, etc. who needs to authenticate to your system? I don't have to tell you what the answer will be.

It's not the technology that's the problem, really. It's the fear, uncertainty, doubt, and cost. Still, once you've been hacked and the crown jewels have been stolen or leaked, it'll probably be easier to convince the powers that be that a better system is needed. Just hope they don't make you the scapegoat.

This article originally appeared in The Transformed Datacenter on 5/27/2013.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: "Network congestion ahead."
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27342
PUBLISHED: 2021-05-17
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack
CVE-2021-31727
PUBLISHED: 2021-05-17
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x8000201...
CVE-2021-31728
PUBLISHED: 2021-05-17
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook wit...
CVE-2021-32402
PUBLISHED: 2021-05-17
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules.
CVE-2021-32403
PUBLISHED: 2021-05-17
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.