Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We know multiple ways to reliably identify someone using biological markers with near-perfect accuracy. Yes, that lack of perfection leaves open the possibility of subversion, but so what? You'll grow old and die waiting for the perfect solution.


Human biometrics are subject to spoofing, replay, and birthday attacks. You can't extract enough entropy from any extant biometrics to be useful, secure, and free of collisions (without having an intolerably high false negative rate).


And those are not subject to replay attacks?


This seems to me like the whole misadventure of putting finger print readers in door locks and phones: Someone noticed that fingerprints work quite well for identifying people in customs and law enforcement and simplified that thought to "fingerprints can identify people" - ignoring the circumstances of how fingerprints are taken when they work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: