Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
The Hidden Dangers Of 'Bring Your Own Body'
Newest First  |  Oldest First  |  Threaded View
JulietteRizkallah
50%
50%
JulietteRizkallah,
User Rank: Ninja
8/31/2016 | 2:39:10 PM
Think about the OPM breach is far more worse for individuals
I agree, we have only one body but can have many passwords.  I reminds me of the OPM breach in which sensistive data about former gov't employees and their family was stolen, information that you cannot erase and replace, information that can identity an individual solely.  But yet still information, not a finger, a pupil, a heart...i am staying away for biometrics until we have a better answer on how to keep that data safe...i am sure it will be a while.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
8/30/2016 | 9:43:53 PM
Re: what will happen after a breach?
@Whoopty: The methodology might be the trick to it, but these types of biometrics -- fingerprints, heart rhythms, etc. -- are pretty replicable.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
8/30/2016 | 9:40:24 PM
Re: what will happen after a breach?
"The aftermath of that data breach cost me an arm and a leg!"
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
8/30/2016 | 9:39:40 PM
Re: Security
Multiple InfoSec experts I know put it this way: You have ten fingers and ten toes -- and that's it.  But the number of possible passwords you can have is nearly infinite.

Besides: biometrics aren't generally protected under the 4th Amendment, whereas passwords (sometimes) are.
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
8/30/2016 | 7:28:23 AM
Re: what will happen after a breach?
Try a heart transplant! Biometric data can use internal metrics like your own unique heart rhythm, so I don't think plastic surgery would cut it. 
hykerfred
50%
50%
hykerfred,
User Rank: Apprentice
8/29/2016 | 10:13:16 AM
what will happen after a breach?
What will happen when your biometrical data has been breached? Will you be fired or forced to take a long vacation since you are the vulnerability? Or will the company just provide you with some plastic surgery? :)
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
8/29/2016 | 6:58:53 AM
Security
I definitely want real safeguards in place before I hand over any biometric data to any companies. As you point out, while biometric data is more unique than passwords and other forms of security, it's still only as useful as the security in place protecting that data.

I'm also concerned that the NSA and other intelligence agencies would love to get their hands on that sort of data. I'd want guarantees that it would only be sent over in the case of a warranted, criminal investigation, not just scooped up randomly when I use it for a login.


News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31414
PUBLISHED: 2021-04-16
The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted workspace configuration.
CVE-2021-26073
PUBLISHED: 2021-04-16
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or ...
CVE-2021-26074
PUBLISHED: 2021-04-16
Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs with a se...
CVE-2018-19942
PUBLISHED: 2021-04-16
A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 build 20210202 (and later) QT...
CVE-2021-27691
PUBLISHED: 2021-04-16
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request...