Ready or Not, Biometrics Finally in Stores
cancer4xmas writes: "It's very exciting to see USA Today's Technology front page saying, "Will that be cash, fingerprint or cellphone?" They're running a story on emerging biometric devices being the most fundamental change in personal finance since 1950, when the credit card was introduced. The concept is now being tested in some stores. Check out the full story." Now couple that tidbit with this morsel from wherley: "In a letter [scroll down a bit] to Bruce Schneier's Cryptogram newsletter, Ton van der Putte tells of a recent invitation from the BBC to comment on the addition of fingerprint biometrics to the British ID card. Using a digital camera and UV lamp he was able to make dummy fingerprints that fooled the readers - and in less time and less cost than similar experiments 10 years ago. He says: '...now the average do-it-yourselfer is able to achieve perfect results and requires only limited means and skills.'"
Its kind of scary that a fingerprint is so easy to forge. It would be so simple to wipe out someone's life savings.
I would have expected banks to adopt this technology only after it has been widely proven to be secure. Instead they are the guinea pigs risking your money. Something's wrong with this picture.
I'm glad I didn't have an account there. Would your money be federally insured if it were stolen by a forged fingerprint? How could you prove it was a forgery (assuming the forger hid his face from the camera above the ATM)?
Actually, severed fingers won't read on a capacitance sensor, but then again the would-be thief wouldn't know that until after he "borrowed" your finger. Thankfully, if nothing else this means they'll leave it behind so the doctors can re-attach it.
I was with a group that evaluated biometric authentication as a primary systems. The primary flaw that was pointed out that no one seems to really talk about is, what if someone compromises the key server? In a traditional authentication system, you simply change your keys. Since in a biometric system the keys are based off of the human body, not only has this compromised system been comletely destroyed, but potentially ALL biometric systems used by the same individuals is now compromised until the day they die.
That was a pretty big problem.
We decided on using biometrics as a 3rd or 4th level of authentication (to verify that someone using all of the other levels of authentication are who they say they are to a reasonable level of accuracy).
[RIAA] says its concern is artists. That's true, in just the sense that a cattle rancher is concerned about its cattle.
I don't know why all of these so-called "security experts" keep on advocating biometrics with little or no understanding of their real properties, much less how they should be properly used. Biometrics can be used as unique identifiers, but biometrics are not secrets. They can provide a unique identifier in an already trusted environment, but alone they cannot be used for authentication, which is what so many of these "experts" are ready to do. If I steal your fingerprint using any of the simple yet effective techniques (none of which require me to cut off your finger) described by Ton van der Putte, it can't be un-stolen, and nobody will be able to give you a "replacement" fingerprint.
A quote that iluustrates this naivete from the USA Today article: "Biometrics is one way to really identify the customer you're dealing with," he [Steve Vallance] says. What a foolish, naive statement. Alone, biometrics cannot really identify anybody.
I really can't do any better than point people out to an article in yet another issue of Crypto-Gram, which first came out five years ago: Biometrics: Truths and Fictions.
Qu'on me donne six lignes écrites de la main du plus honnête homme, j'y trouverai de quoi le faire pendre.
As someone who worked in the biometrics field for a number of years I can say that fingerprint biometrics are stupid.
Too easily compromised (kinda hard to change your fingerprint) and very unreliable.
Fingerprints just are not unique enought and only work in small sample sets. For example, when a criminal investigation is being done the search is limited. When trying to do something like credit cards, you're talking about millions of people. It just won't work. Not solely using fingerprints. Not ever.
This is far easier than pretending a severed thumb is your own, and with the use of acetone based prints (from the gelatine master) it is virtually impossible for a layperson to determine that you have an overlayed print on your thumb.
Just your $0.02... :)
Q.
Insert Signature Here
http://www.schneier.com/crypto-gram-9808.html#biom etrics
Biometrics are seductive: you are your key. Your voiceprint unlocks the door of your house. Your retinal scan lets you in the corporate offices. Your thumbprint logs you on to your computer. Unfortunately, the reality of biometrics isn't that simple.
Biometrics are the oldest form of identification. Dogs have distinctive barks. Cats spray. Humans recognise each other's faces. On the telephone, your voice identifies you as the person on the line. On a paper contract, your signature identifies you as the person who signed it. Your photograph identifies you as the person who owns a particular passport.
What makes biometrics useful for many of these applications is that they can be stored in a database. Alice's voice only works as a biometric identification on the telephone if you already know who she is; if she is a stranger, it doesn't help. It's the same with Alice's handwriting; you can recognize it only if you already know it. To solve this problem, banks keep signature cards on file. Alice signs her name on a card, and it is stored in the bank (the bank needs to maintain its secure perimeter in order for this to work right). When Alice signs a check, the bank verifies Alice's signature against the stored signature to ensure that the check is valid.
There are a bunch of different biometrics. I've mentioned handwriting, voiceprints, and face recognition. There are also hand geometry, fingerprints, retinal scans, DNA, typing patterns, signature geometry (not just the look of the signature, but the pen pressure, signature speed, etc.), and others. The technologies behind some of them are more reliable than others, and they'll all improve.
"Improve" means two different things. First, it means that the system will not incorrectly identify an impostor as Alice. The whole point of the biometric is to prove that Alice is Alice, so if an impostor can successfully fool the system it isn't working very well. This is called a false positive. Second, "improve" means that the system will not incorrectly identify Alice as an impostor. Again, the point of the biometric is to prove that Alice is Alice, and if Alice can't convince the system that she is her then it's not working very well, either. This is called a false negative. In general, you can tune a biometric system to err on the side of a false positive or a false negative.
Biometrics are great because they are really hard to forge: it's hard to put a false fingerprint on your finger, or make your retina look like someone else's. Some people can mimic others' voices, and Hollywood can make people's faces look like someone else, but these are specialized or expensive skills. When you see someone sign his name, you generally know it is him and not someone else.
Biometrics are lousy because they are so easy to forge: it's easy to steal a biometric after the measurement is taken. In all of the applications discussed above, the verifier needs to verify not only that the biometric is accurate but that it has been input correctly. Imagine a remote system that uses face recognition as a biometric. "In order to gain authorization, take a Polaroid picture of yourself and mail it in. We'll compare the picture with the one we have in file." What are the attacks here?
Easy. To masquerade as Alice, take a Polaroid picture of her when she's not looking. Then, at some later date, use it to fool the system. This attack works because while it is hard to make your face look like Alice's, it's easy to get a picture of Alice's face. And since the system does not verify that the picture is of your face, only that it matches the picture of Alice's face on file, we can fool it.
Similarly, we can fool a signature biometric using a photocopier or a fax machine. It's hard to forge the vice-president's signature on a letter giving you a promotion, but it's easy to cut his signature out of another letter, paste it on the letter giving you a promotion, and then p
Why stop with the steady stream of articles that point out the real shortcomings of biometrics? So you can keep your job? Sorry, but that's a pretty selfish reason that only works for you, your boss, and a handful of investors.
As Bruce Schneier pointed out years ago, biometrics are a double edged sword. Biometrics are hard to forge (I am deliberately ignoring the $0.50 gelatin trick that fools fingerprint readers since I assume someone will repair that particular shortcoming,) and look to the implementations of the systems for the weaknesses instead. Yes, they are hard to forge. But once the data is turned into bits, it's pathetically easy to copy. And you can't put the genie back in the bottle it once it's gone!
It comes down to "who do you trust?" Do you really trust the department store or the bank to not keep a copy of your biometric identification? What's to keep an unscrupulous merchant from intercepting a copy of your raw biometric data, and saving a copy?
I see signature capture pads all over the place these days. I categorically refuse to use them because I have no confidence that my signature won't be captured and replayed by the wrong person. You can't tell me that a "secure" system will prevent this, because I can't tell a secure system by looking at one. The promise of Open Source is no guarantee, either. Even if it had a picture of a penguin on the outside, a spiffy GNU-y logo, and OSF and SourceForge brand stickers on it, how do I know it's really "IdentifyMe_2.0" and not some hacked-up demo being run by Vinnie the Chiseler? People believe that when they walk into a Home Despot that Home Despot doesn't keep a permanent record of their signature. Of course they keep it; it's actually required by law to retain the audit copy for 36 months (42 in Illinois.)
There are also plenty of known cases of fraudulent ATM machines that read your card, accept your PIN, spit out "TEMPORARILY UNABLE TO DISPENSE CASH", and report both your card and PIN to the machine's owner. How is a user supposed to be able to authenticate the biometric device is genuine; that it's not a sham, running a copy for a thief?
How will this change with fingerprinting, hand geometry, retinal scans, or whatever the biometric system of the week may be? It won't; it can't. And since the systems can never be trusted to not "steal" or retain copies of identification for future playback, the systems should never be used in the first place. Using them even one time will put your irreplaceable data in a system it may never escape from.
Biometrics are a technology that should not ever be mainstreamed. They might work fine for a secure military facility, but once they're out in the general populous for any length of time, the protections they represent are gone.
John
Last night in the checkout I was behind a very nervous man who got what he claimed was -HIS- ATM PIN wrong 14 times! It was quite obvious that he was using somebody else's card, he eventually got it but I watched him try several permutations of someone's birthday. After he left I asked the clerk what she thought and she was totally clueless, she said she deals with people who forget their PIN numbers all day long. I asked if the store had a policy to check their state ID against the card they were trying to use if it's obviously fraudulent, and she said she's only interested in keeping the line moving.
Now you know one reason identity theft is so easy, store clerks are letting people try PIN numbers willy-nilly until they get the right one. There should be a 'five times' law, after which they cut your card up.
"Sometimes, I think Trent just needs a cup of hot chocolate and a blankie." -Tori Amos on Nine Inch Nails
That sounds like a handy system. However, I have first hand experience that that does not always occur. My fiance's ex-husband, the typical try-to-get-tons-of-money-without-working-for-it type (he actually sent money in a Nigerian scam more than once) has quite a few credit cards in his dead (over 10 years now) father's name. In a fit of spite, she called the credit card companies, who said that if she could not provide a death certificate, they weren't willing to do anything about it.
Systems only work when those that use them actually use them.
Saying Android is a family of phones is akin to saying Linux is a family of PCs.
CO doesn't want fingerprints. I just got my (first/new) driver's license here in CO 1 year ago. No (thumb|finger)print taken or asked for.
I had to give a thumbprint.
Where I live, bank branches are asking for thumbprints from non-account holders wanting to cash checks.
This, despite:
- The check was written on that bank.
- The person can produce a driver's license to verify that they are the payee.
Yes, it's true that it cuts down costs of fraudulent checks that banks must bear. But it also increases risks to check cashers that their special identifier may be misused. What guarantee does the bank provide that the thumbprint won't be used for the single purpose of preventing fraud on that transaction and that it will be destroyed to prevent any possibility of further misuse?Heavy-handed tactics like this have really driven people to want to use cash more and more.
The fun side of money tracing is wheresgeorge.com
But imagine if ATM machines used OCR to record the serial numbers of bills dispensed to people and if banks were required to inventory serial numbers of incoming currency, too.
Credit card and debit card transactions have already reduced the proportion of anonymous financial transactions. The technology exists to reduce financial anonymity a lot further.
"Provided by the management for your protection."