Slashdot Mirror


Fingerprint Requirement For a Work-Study Job?

BonesSB writes "I'm a student at a university in Massachusetts, where I have a federal work-study position. Yesterday, I got an email from the office that is responsible for student run organizations (one of which I work for) saying that I need to go to their office and have my fingerprints taken for the purposes of clocking in and out of work. This raises huge privacy concerns for me, as it should for everybody else. I am in the process of contacting the local newspaper, getting the word out to students everywhere, and talking directly to the office regarding this. I got an email back with two very contradictory sentences: 'There will be no image of your fingerprints anywhere. No one will have access to your fingerprints. The machine is storing your prints as a means of identifying who you are when you touch it.' Does anybody else attend a school that requires something similar? This is an obvious slippery slope, and something I am not taking lightly. What else should I do?"

81 of 578 comments (clear)

  1. Non-issue? by Fastolfe · · Score: 5, Interesting

    I've used biometric scanners like this in the past. Whatever it stores to recognize your fingerprint never leaves the machine. I don't know if that's what's going on here, but it seems perfectly reasonable.

    1. Re:Non-issue? by martin-boundary · · Score: 5, Insightful

      Not sure what `safe` has to do with anything, unless you think you're likely to catch swine flu from touching a fingerprint reader or something.

      Safety means you won't get your finger chopped off by someone who wants to impersonate you to enter the building.

      Safety (for people) is higher when there's no biometric system in place, becaus the bad guys don't have an incentive to chop their fingers off or gouge out their eyes.

    2. Re:Non-issue? by Macfox · · Score: 4, Informative

      Ask if the unit is FIPS 201 certified. If it is then you can be certain that no reproducible image leaves the unit. There's no more identifying data than a password or PIN that leaves the unit.

      There are cheaper units on the market that centrally process the finger print image to speed up matching, which is open to abuse.

      Disclaimer: I previously worked for a fingerprint / time-clock manufacture that produced FIPS compliant devices.

      --
      Area51 - We are watching...
    3. Re:Non-issue? by tophermeyer · · Score: 2, Insightful

      We use a lot of students where I work. I can speak from experience that students, especially part-timers who like to squeeze in hours whenever they can, are without their badges and ID cards a lot. Either lost or left in the dorm room when they left for the day. As someone who is responsible for getting a temporary day-badge for my co-op whenever he forgets his, my first reaction was something like "cool! How can I get me one of those?".

      I suppose I don't know exactly how this system works, and thus what kind of privacy implications might exist. But I can imagine the privacy implications here are no different than all the other personal information employers routinely collect about their new hires.

  2. What else should I do? by NfoCipher · · Score: 5, Insightful

    Start looking for another job..

    --
    I'm sorry, I can't hear you over the sound of how awesome I am.
    1. Re:What else should I do? by johnlcallaway · · Score: 5, Interesting

      I agree .. if you don't like it .. don't do it. No one is forcing you to. Others may not have the same concerns and would be more than happy to do that job, so I'm sure it won't bother them too much.

      I used to work at a job that required using an id card to clock in and out. If you left it at home it was a huge hassle to get a temporary id card. Forget it too many times and they started to take disciplinary action. I'd rather use my fingerprint to 'clock in' than try and remember to bring my id card every day when the only function of that card was to clock in and out.

      --
      I rarely read replies, it's my opinion and if you thought about your opinion a little more, I'm OK with that.
    2. Re:What else should I do? by causality · · Score: 4, Insightful

      I agree .. if you don't like it .. don't do it. No one is forcing you to. Others may not have the same concerns and would be more than happy to do that job, so I'm sure it won't bother them too much.

      Those others and their indifference is part of the problem. If this university is doing this, you can bet that others have considered it. If this is successful and does not receive much opposition, others will follow suit. The result is that the people who do care about privacy are going to have fewer ways to protect it. So no one is forcing you to support this right now but when every such institution adopts these requirements, that will change. Of course by that time there'll be little or no hope of doing anything about it because it will be entrenched.

      It's similar in some ways to the relative uniformity of cellphone service plans in the USA despite the multiple competing companies that offer it. A few such companies established pricing and service plans and were successful, so others adopted similar business practices. The result is that there's little actual innovation in the industry. None of the cellphone companies has any incentive to rethink their pricing, so I as a customer cannot vote with my wallet if I want, for example, text messaging prices that realistically reflect the actual cost of delivering SMS.

      I'm sure there is a whole litany of reasons why an institution wants biometric identification. I'm sure that some of those justifications are reasonable enough. I just don't care, to be honest with you. I don't want to live in a surveillance society. If that means a few more unauthorized users gain access, or if that means a few more criminals avoid detection, I'm fine with that and more than willing to take my chances. Only cowardice would make me feel differently. It is obvious to me that a surveillance society is like a totalitarian state; it is created by means of baby steps. Each baby step down that path looks harmless enough at the time and plenty of useful idiots will sing the mantra of "I've got nothing to hide, so I'll surrender my privacy to anyone who asks." Stop this early when it seems minor and benevolent and you avoid the tremendous problems that become inevitable otherwise.

      I used to work at a job that required using an id card to clock in and out. If you left it at home it was a huge hassle to get a temporary id card. Forget it too many times and they started to take disciplinary action. I'd rather use my fingerprint to 'clock in' than try and remember to bring my id card every day when the only function of that card was to clock in and out.

      I'm sorry but I believe in fixing problems at their source. This is simple forgetfulness that a little self-discipline can easily solve. The privacy of every member of society that is never coming back once lost is far more important than the very minor inconvenience to you of learning to bring your ID card to work. To say otherwise is supreme selfishness and amounts to forcing your beliefs about privacy on everyone else. Those who like privacy appreciate that about as much as you'd appreciate being forced to practice a religion you don't believe in. I don't think you really are this selfish; I just think you're not considering the full implications of your position.

      Privacy is a good default; anyone who doesn't want it can always become an exhibitionist with their personal information if that's what they want to do. I won't try to find ways to stop them since it's their choice and, unlike this slippery slope, doesn't affect me in any way either real or potential. Anyone who thinks that this won't grow and expand if it isn't stopped, who believes that the companies producing biometric machines won't seek new markets and new customers, who really thinks that no one would ever want to retain and datamine such detailed information about your habits and whereabouts, is frankly rather naive.

      --
      It is a miracle that curiosity survives formal education. - Einstein
    3. Re:What else should I do? by bunbuntheminilop · · Score: 2, Interesting

      They should tell them what it is and how it works. Clearly. In a little brochure. Does no one care about employee relations anymore?

    4. Re:What else should I do? by pnewhook · · Score: 2, Insightful

      Your rights to what exactly?

      --
      Tesla was a genius. Edison however was a overrated hack who liked to torture puppies.
    5. Re:What else should I do? by darkmeridian · · Score: 3, Insightful

      To say otherwise is supreme selfishness and amounts to forcing your beliefs about privacy on everyone else.

      That seems like what you're doing. The problem is that others are willing to trade off some privacy to get some convenience. Look at Facebook.

      --
      A NYC lawyer blogs. http://www.chuangblog.com/
    6. Re:What else should I do? by TheRaven64 · · Score: 3, Insightful

      It it my inalienable right to only leave my fingerprint on everything that I touch, not in some database.

      --
      I am TheRaven on Soylent News
    7. Re:What else should I do? by skade88 · · Score: 2, Informative

      I have been using a finger print scanner to clock in and out of my jobs for the past 10 years. As the IT guy at some of these jobs, I know that its not actually storing the full image of my finger print. It stores a few critical points to make sure it has it and not the full image. But if someone really wanted your finger print, it would be easy for them to lift it off the door knob when you enter your office, or from a coke can you throw into the trash or from your keyboard when you get up to goto the bathroom or anything else you touch in a given day. It would be much easier than hacking the time clock or a server to get your finger print.

  3. You're dumb by ArchieBunker · · Score: 4, Insightful

    Its a time clock. Many jobs have them along with your address, phone number, date of birth, and social security number. Welcome to the working world. I could just as easily steal your fingerprints from your car door handle or the can you threw in the trash. After this fiasco don't expect the job offers to roll in.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
    1. Re:You're dumb by Midnight+Thunder · · Score: 4, Informative

      Solutions like this are often used to prevent someone clocking-in for you. I used this type of solution at a sports club which used to go to, where you would enter your member number followed by you finger print. Chances are this is another closed system, so it the finger prints probably won't get much further than the database.

      --
      Jumpstart the tartan drive.
  4. As long as you are assured that your privacy by ragethehotey · · Score: 4, Insightful

    As long as you are assured that your privacy is protected...this is a huge non-issue. Fingerprint scanners are the best (In terms of ease of implementation) way to prevent people from clocking in and out for each other, even though they are obviously easily defeated by anyone sufficiently motivated.

    1. Re:As long as you are assured that your privacy by ragethehotey · · Score: 2, Insightful

      sufficiently motivated.

      to press their finger against a piece of sellotape.

      And with an inkjet printer and blank check paper, you can commit bank fraud. How is the fact that you CAN cheat relevant?

      At literally every hourly job I have ever held in my life, people "clocking in" to cover for friends has been a huge problem.
      Its outright theft from the employer, yet people that would never steal physical property, will cheat a time clock without thinking twice.

  5. No contradiction. by Anonymous Coward · · Score: 5, Interesting

    I checked into these before. The scanner records a description of your fingerprint, not the image. The description is used to match. It's a form of message digestion.

    Most scanners of this type do not even record enough detail to qualify as evidence. Those that do must have their data shared with law enforcement, making them a hard sell as a biometric time card.

    1. Re:No contradiction. by ThinkingInBinary · · Score: 3, Interesting

      Most scanners of this type do not even record enough detail to qualify as evidence. Those that do must have their data shared with law enforcement,

      Do they have to just volunteer all the data automatically, or only if law enforcement asks? (If the former, [citation needed].)

    2. Re:No contradiction. by Protocol16 · · Score: 2, Informative

      Yup, exactly correct. Scanners will store a "hashed" version of your fingerprint based off of an algorithm. It just stores the "fingerprint" as a random string of data. The more secure versions store the hash on a Smart Card, which you have to authenticate against. The DoD uses this type of system on their ID cards for Contractors, Civilians and Military personnel. If you're worried about how bad this situation is, you need to watch a specific myth busters episode: http://www.youtube.com/watch?v=LA4Xx5Noxyo Nothing to worry about, no privacy being broken, etc.

      --
      Don't click here...
  6. Welcome to the new world by ColdWetDog · · Score: 3, Insightful

    Same as the old one... My wife's workplace has this system. Works terribly but somehow it got past some CxO. Not sure if the privacy issue is a big deal however. You train the system in the system (if it's the same one). The print doesn't go out to the big Gov.

    Not saying that they couldn't do that, but you do realize (being an aluminum foil shielded card carrying Slasdotter) that 'they' can get your fingerprints, DNA and bog knows what else without much of a problem these days.

    Hell, at least it's pretty unlikely to show up on Facebook.

    --
    Faster! Faster! Faster would be better!
  7. Disney World by crow · · Score: 2, Interesting

    At Disney World, they require finger prints when you enter the park if you want to be able to re-enter or switch to another park (if you have a ticket that allows that). At least the government doesn't directly get them, but who knows what they're doing with them or how long they keep them. (This was several years ago; I don't know if it's changed.)

    1. Re:Disney World by MadCow42 · · Score: 2, Insightful

      Yes, and I was equally concerned with them using these at Disney World! Thankfully they don't collect fingerprints from kids - maybe they're also concerned with the potential legal issues?

      Hint - at least at Disney World you can decline. You simply have to show picture ID. Don't be a sheep - at least ask what your options are, how your privacy will be protected, and what THEIR liability is if there is a breach in that privacy.

      MadCow.

      --
      I used to have a sig, but I set it free and it never came back.
  8. For the fossils by stokessd · · Score: 4, Funny

    And friends, somewhere in Washington enshrined in some little folder, is a
    study in black and white of my fingerprints. And the only reason I'm
    singing you this song now is cause you may know somebody in a similar
    situation, or you may be in a similar situation, and if your in a
    situation like that there's only one thing you can do and that's walk into
    the shrink wherever you are ,just walk in say "Shrink, You can get
    anything you want, at Alice's restaurant.".

    1. Re:For the fossils by catherder_finleyd · · Score: 2, Interesting

      And now for the rest of the story:

      http://www.youtube.com/watch?v=5_7C0QGkiVo

  9. Acid by EightBits · · Score: 3, Funny

    Use acid on your finger tips to remove the prints and use that for ID. The only problem is that you are now linked to hundreds of crimes where no traces of fingerprints were found. But at least they wont be able to identify YOU when they find your actual fingerprints somewhere.

  10. Modern Fingerprint Scanners dont keep prints by Tepshen · · Score: 4, Informative

    The way that most modern fingerprint scanners work is by using matching algorithms. They scan your fingerprint and translate that into a numeric value and then store that. Not a copy of your fingerprint itself. This numeric value cannot be used to recreate your fingerprint but it can however be used to match the output that only your fingerprint will produce when scanned. To be perfectly candid its far easier to steal your fingerprints by stealing something you own than it is to take them from a fingerprint security/tracking system.

    1. Re:Modern Fingerprint Scanners dont keep prints by tsm_sf · · Score: 4, Insightful

      All they have to do is get your fingerprint from something

      like your finger? Look, if "they" want your fingerprint, they're going to come get it from you. If you're a suspect you will be fingerprinted. This time clock is not connected to a federal black-helicopter database, no matter how exciting that might be.

      making a stink about something trivial like this makes legitimate privacy concerns look bad

      --
      Literalism isn't a form of humor, it's you being irritating.
    2. Re:Modern Fingerprint Scanners dont keep prints by timmarhy · · Score: 2, Insightful
      they lift your print off something, why the fuck would they need anything out of this dinky database? all it's going to tell them is when you clocked into work.

      big fucking deal.

      --
      If you mod me down, I will become more powerful than you can imagine....
  11. Get Back To Us by longacre · · Score: 2, Funny

    ...when your boss starts asking to personally take samples of your reproductive DNA. Until then, there's nothing to be upset about.

    1. Re:Get Back To Us by Tablizer · · Score: 2, Funny

      when your boss starts asking to personally take samples of your reproductive DNA...

      Then just hand him/her your keyboard.
           

  12. It's like storing a hash. by HiggsBison · · Score: 5, Insightful

    Apparently what it is storing is a statistical summary of the biometric information (if that's not redundant). It doesn't store the fingerprints themselves anymore than an operating system will store your password. With the password, whatever you type in has to have a hash which matches the hash associated with your account. With the scanner, the summary generated each time you plop your hand on the scanner has to match (to a significant degree) the summary on file.

    But, yes, if someone finds your fingerprints somewhere else, and they have access to this data, they can be reasonably certain it is you.

    --
    My other car is a 1984 Nark Avenger.
    1. Re:It's like storing a hash. by davester666 · · Score: 2, Funny

      If you're really opposed to this, but also really want the job, bribe one of the medical students to cut off a finger and give it to you. Then you can use that finger to clock in/out instead...

      --
      Sleep your way to a whiter smile...date a dentist!
  13. It's all stupid, and for stupid reasons by gerf · · Score: 5, Informative

    Apparently if you visit Brazil, Europeans and Brazilians go through one line. Americans, we can all step over here to get fingerprinted, retina scanned, etc.

    Why? We do it to them, so they do it back. F.

    1. Re:It's all stupid, and for stupid reasons by ivoras · · Score: 2, Insightful

      An it is only fair - I wish other countries will do the same. There should be no reason not to reciprocate any such nonsense requirement.

      --
      -- Sig down
    2. Re:It's all stupid, and for stupid reasons by aylons · · Score: 5, Informative

      Yes, that is right. This is due to Brazilian Constitution, which says that all diplomacy must be reciprocal. E.g., for every country which demands a visa from Brazilian people, Brazil demands a visa for their people to get in Brazil. If the government, the Federal Police or the airport authority decides to do any different, they will get sued.

      --
      This comment may contain speech figures. Reader discretion is advised.
    3. Re:It's all stupid, and for stupid reasons by dunkelfalke · · Score: 3, Insightful

      Nope, because the non-voters agree with everything that comes up by default.

      --
      "It's such a fine line between stupid and clever" -- David St. Hubbins, Spinal Tap
    4. Re:It's all stupid, and for stupid reasons by gerf · · Score: 2, Insightful

      My point being that we (US) treat others like crap for NO reason, we get shafted back. I'm currently getting my 4th work visa in my 3rd country, and I really do think it ends up being a detriment to come from the US.

  14. Not working there is not a solution. by EightBits · · Score: 3, Insightful

    Not many posts yet but I already see a LOT of posts pushing the idea of not working for this employer. This is not a solution. If we don't fight it and win, it will be adopted by more and more employers until it snowballs into something too big to fight. If we think this is a bad idea, it needs to be fought now while it's still in its infancy.

  15. I recommend... by pak9rabid · · Score: 4, Insightful
    ...that you stop being such a whiney bitch. So they want your fingerprints to ID you...so what? What is it that you're worried about that they're going to do with them, other than use them internally for authentication purposes?

    I am in the process of contacting the local newspaper...

    Are you for real? Other than than the fact that they likely won't give a rats ass about this, you are treading on very thin ice. I'm not sure what it is you're planning on doing after graduation, but being labeled a well-known whistle-blower isn't going to do you much justice when you're out looking for a job.

    1. Re:I recommend... by Blakey+Rat · · Score: 5, Interesting

      Humor me:

      How much information about you is encoded in your fingerprint, exactly?

      If someone gained access to your fingerprint could they, for example, empty your bank account? Take out a loan in your name? Give me an example here.

    2. Re:I recommend... by potat0man · · Score: 2, Insightful

      being labeled a well-known whistle-blower isn't going to do you much justice when you're out looking for a job.

      We need a +1 coward moderation.

      There are plenty of arguments about why this guy shouldn't be concerned about using his finger print to clock in and out, but being worried about being labeled as a honest man who fights for his principles isn't one of them.

    3. Re:I recommend... by Joe+Jay+Bee · · Score: 2

      By using an image of a fingerprint? In fact, not even an image, a statistical summary of one?

      Nah.

  16. Those things don't work by tomhudson · · Score: 2, Funny

    We had one, after the first couple of weeks people started punching it instead of "punching in". They're supposed to also have a keypad so you can manually enter an access code, since the reader is known to be undependable.

    If you want to mess it up, each time you stick your finger on it while it's "registering you" (it needs more than 1 scan), put your finger in a different position, different angle, or even use a different finger (people generally don't notice). After 5 failed attempts, they'll give up. Or, if they "insist" o "helping you" place your finger, tell them that as far as you're concerned, their broken machine is their problem, and that touching you is common assault and you'll file charges.

    1. Re:Those things don't work by tomhudson · · Score: 2, Interesting

      After the first two weeks, it kept saying (in a REALLY annoying voice) "Please try again ..." "Please try again ..." "Please try again ..." "Please try again ..."

      It was tempting to just hack into the PC it was running on and just update the stupid database manually, but that would have been too much work to maintain, running after everyone and asking them what hours they wanted to show on the timesheet.

      And if you did more than 12 hours, it got confused.

      And if you forgot to punch out the night before, it would SAY you were punching out the next morning when you punched in, but in reality it was punching you in, since you had exceeded the 12-hour limit. So people would quickly "correct" it by punching in, and it would SAY that they were now punched in, but in reality they just punched out. And 8 hours later, when the went to punch out ... it would say they just punched in.

      And it didn't update when the time changed between DST and EDT, and vice versa.

      After a few weeks of that, it's understandable that people began beating on it.

      It also must have had a math aversion - it couldn't add up time properly. I would take the numbers on the print-out, add them up manually, and get an hour LESS than I was being credited for. It can't add. Not if one day had 10 or more hours worked, but less than 12 - it would throw in an extra hour, giving 11 hours worked. for example, a 4-day week, 4 x 10 hours, is not 44 hours.

  17. Pick your battles. Settle for knowing... by dpbsmith · · Score: 3, Interesting

    ...that the next time a pompous administrator says in public "nobody has complained about that," you know that he is lying. Settle for not just knucking under without saying anything at all. Settle for knowing, if you do know, that your complaint has reached someone who sets policy and that you're not just making things hard on a bunch of other ordinary workers whose job is to keep things running.

    This is not nothing at all, but it's a small thing.

    You can't change the world through indignation. You really have only three choices. First, be docile and do nothing at all. That's often a good option by the way. Second, make sure your concerns have been heard, even if they are dismissed. Or, third, be prepared to devote at least a year or two of your life to the cause of fighting this thing.

    If you feel that spending a year or two toward the goal of getting the university to stop using fingerprinting gadgets for access to work-study jobs is worth it, and is what you want to do with that chunk of your life, you can probably achieve your goal. I dunno how. Work through the union if there is one? Start a union if there isn't one? Make appointments and personally talk to one administrator after another, calmly, until you figure out how to get the policy changed? Personally work out an actual proposal, including costs and benefits, for alternative security, so you're presenting them with something positive and their work all done for them, instead of just saying "don't do what you're doing?" Find a faculty committee that's interested in the question that you can swing to your side? I dunno.

  18. GENTETIC Testing by hackus · · Score: 2, Interesting

    Wait till they start genetically testing everyone with DNA requests for security purposes.

    Thats when the fun will begin.

    Expect to be denied loans based on life span and proclivities to all sorts of diseases they find you will contract.

    Effectively they can prevent your student loans/grants to save money as they certainly do not want to invest in anyone who won't be around long enough to pay back that 100K.

    All sorts of monkey business is planned. If you have a kid right now, the blood of every baby born in US hospitals MUST be saved by the department of homeland security for a genetic test for identification.

    -Hack

    PS: NO, they DO NOT tell you about that last part.

    --
    Got Geometrodynamics? Awe, too hard to figure out? Too bad.
  19. biometric time clocks by linuxbert · · Score: 4, Insightful

    I installed these at a client.
    The issue was the employees would take an afternoon off to go to an appointment, and get buddy to clock them out at the end of the day - The emplyoee would then get paid for an afternoon they didnt work.

    The time clocks have a fingerprint scanner. You place your thumb on the device as you punch out. Now buddy cant swipe out for you, and you cant defraud your employeer.

    They also had biometric locks instead of prox cards on the doors. Much more convieient then having to remember a card the few days when i was on site.

    1. Re:biometric time clocks by Anonymous Coward · · Score: 2, Insightful

      For the love of god people, If your employees are doing this, don't install biometric scanners - just fire them.

    2. Re:biometric time clocks by lordholm · · Score: 2, Insightful

      Put in a rotating gate that only let one person pass at a time, then it will be more or less impossible to swipe two badges at the same time.

      --
      "Civis Europaeus sum!"
  20. They don't store your actual fingerprint by Colin+Smith · · Score: 4, Informative

    Not the image anyway. They store the relative positions of specific details of your print. 2 minutes on Google would have told you this.

    The question remains though whether you want them to hold a representation (of any kind) of any part of your body on file.
     

    --
    Deleted
    1. Re:They don't store your actual fingerprint by goaliemn · · Score: 3, Informative

      I've installed systems that work like this. They store afew statistical points of your fingerprint. If someone actually got those points that they stored, they still couldn't make a complete fingerprint.

      This type of system is usually implemented due to former employees punching in for each other. This is a way that makes that more difficult.

    2. Re:They don't store your actual fingerprint by AlamedaStone · · Score: 2, Insightful

      I have nothing to hide

      I suppose some people will accept a lot of money to surrender their freedoms. It must be nice to live in a little world where the only thing that matters is the size of a paycheck.

      Everything costs something, I guess.

      My compliance opened-up new opportunities and is certainly better than living off Welfare or doing the Walmart shuffle.

      Yes... those are the only two options available. Surrender your privacy or go on welfare. Service guarantees citizenship!

      --
      "All these years believing you're the signified monkey, only to find out you're just a big hunk of nobody cares."
    3. Re:They don't store your actual fingerprint by Zerth · · Score: 2, Interesting

      This type of system is usually implemented due to former employees punching in for each other. This is a way that makes that more difficult.

      Only if you work for a security conscious facility who is willing to deal with the hassles of running such a system. Both places I've been at that used it for just timeclock purposes either turned the discrimination down so far that at least one other person could fake for them, or gave up on the high false negative rate and switched to "type in something you wouldn't want your coworkers to know, like your SSN".

      I left the latter place real quick.

    4. Re:They don't store your actual fingerprint by Anrego · · Score: 4, Insightful

      I totally agree with commodore64_love

      I don't want the government tapping into my phone, spying on my Internet traffic, or searching through my house without just cause.. but we're talking finger prints here.

      And while I do agree.. saying the only alternative is welfare was a little extreme.. you are definitely limiting yourself by refusing to allow any intrusions into your precious privacy.

      I suppose some people will accept a lot of money to surrender their freedoms.

      This is completely true.. and I think in a lot of cases.. people are better off for it. Everything is a balancing act.. certain jobs (especially government) require a fair degree of background checking.. this is of course an invasion into your privacy.. but you are compensated for it (both financially and in terms of getting to work on some really cool stuff).

      It's not about completely selling out your privacy.. but it's not about living the life of a paranoid delusional who thinks the world is out to get them either. It's about finding a balance you're comfortable with.

      As someone who has "given up" a lot of privacy in exchange for a very enjoyable career.. I've felt no ill effects from it. What exactly do the tin foil types of the world think the government / Illuminati / whatever .. are doing with this information.. and specifically.. how do they think it's going to realistically effect their lives in an actual concrete way (vice some paranoid "when the commies come back" throb).

    5. Re:They don't store your actual fingerprint by MikeV · · Score: 2, Insightful

      And... just what "freedoms" are being surrendered? The contents of our lives are sequestered already in many dozens of places. Our complete physiology in doctor's files. Tell me the government is hands-off with those? Pictures on our driver's license - how is that different from a "picture" of your fingerprint? Nowadays even that is digital and contains a lot more information about you than your fingerprint. Surely you have a driver's license, doncha? So, what freedoms have you surrendered? You get to do what? Drive. Anywhere. Sounds pretty free to me. You guys are freaking out over nothing when other governments in history have done a lot worse with far less already. There is no such thing as true freedom in any society. No such thing as a utopia when people have to live with each other. Life is about compromise and meeting each other half way. And do you think people on welfare have more privacy than those who are not? What planet did you arrive here from? The only way is to completely drop out of society altogether and go squat in some forest or out in the jungle and live as a hermit. If that is what you want, well - that's freedom for you. Freedom for me is being able to live a lifestyle that allows me to explore my potential and raise my family. Guess what? Even people in China do that. There is always something to gripe about no matter what society you find yourself in. But while you are focusing on the worst, you are missing the best. Live your life to the most that it can be lived - it's far too short to spend it imagining all the bad things - like that nitwit who flew an aircraft into the IRS building, as if that would change a single thing and did nothing more than murder a 9-5'er, leave his wife and kid homeless (and no doubt in debt for a burned home they can't collect insurance from) and he's a hero to no one - only one big loser. That's the road you walk on when you spend all your time whining about how the government wants to take away all your freedoms and live your life as a victim. Guess what - the government is going to do stuff you disagree with no matter how much you cry about it. Deal with it and move on. There's life to be lived - live it. Vote where you can, try to make your part of the world a better place where you can, and live your life.

    6. Re:They don't store your actual fingerprint by benchbri · · Score: 3, Insightful

      I agree. I just pulled out my Pennsylvania drivers license, and it has on there my eye color, height, and *sex*.

      That's a privacy concern.

      OH MY GOD THERE'S A PICTURE OF ME ON HERE TOO

    7. Re:They don't store your actual fingerprint by Jackie_Chan_Fan · · Score: 2, Insightful

      I think we've let enough intrusions in our "precious privacy"

      Too much.

    8. Re:They don't store your actual fingerprint by RivieraKid · · Score: 3, Insightful

      So first you bash people's legitimate desire for privacy, than you claim to have a legitimate reason for anonymity? You *do* realise, don't you, that anonymity is just another aspect of privacy?

      So, either you're for privacy, or you're not, but stop pretending you have a legitimate reason for abolishing it while taking full advantage of it.

      Required reading for those 'I've got nothing to hide' people.

      Also, perhaps you can explain how somebody chooses not to be born in a particular country?

      Not posting anonymously because I'm not scared of what people have to say.

      --
      "Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves
  21. Re:Oh no! by physicsphairy · · Score: 2, Insightful

    If they want to check his presence, logging him in and out, there are other methods to do that. They don't need his fingerprints. It worked perfectly well with badges and/or company ID cards.

    How exactly does an ID card verify his presence, rather than simply that someone possessing the card happened to run it through the machine?

    And, yes, his fingerprints are all over the doorprint. Together with a gazillion of other fingerprints. And withoug registration that makes him one of the anonymous crowd.

    As long as no one goes to the extraordinary effort of pre-emptively wiping the handle clean.

    It's easy to ridicule people as paranoid. Instead, however, you should be thinking "why the heck are they requiring my fingerprints".

    What I am comparing this to is, for example, using a social security number for identification, which seems to generate a large current of opposition here on slashdot precisely because it such a non-physical, easily reproducible security feature. I want anonymity as much as the next guy, but the one place I don't want it is in verifying my identity. (I would think most people could see the inherent contradiction in wanting both at the same time.) Ideally only one person will be able to gain access to things under my identity, that being me.

    Fyi, pretty much any job working for the government or with children is much more invasive--you will actually have your prints submitted to a database for a background check, rather than simply having checksummed on the given machine. The latter doesn't seem that controversial to me.

  22. cut off finger? gummy bear can beat the system and by Joe+The+Dragon · · Score: 2, Interesting

    cut off finger? gummy bears can beat the system and the myth busters where even able to beat high tech lock with a copy on paper.

  23. Concerns = big waste of time by rcolbert · · Score: 2, Insightful

    Of all the things in the world to worry about, a fingerprint reading timeclock is very close to the bottom of the list. Your fingerprints are not stored, nor are they uploaded to some evil master government database. You fingerprints are not DNA. They can't be used to predict if you'll get colon cancer by age 50. Quite frankly, they're not even private. You leave them all over the place every single day. I don't think this rises to the level of concern of someone taking a picture of you and putting it on an ID card. And we all know about how much evil has been done with misappropriated badge ID photos.

  24. They could go even further... by pentalive · · Score: 4, Interesting
    They could do even better than that, they could take relative position information you described and then hash it. Hashes are one way, no one can recover the respresentation once it is hashed.

    To login BonesSB would present a finger, the same information points would be measured, then hashed then the two hashes compared.

    I am not saying that they did go to that extent, but they could have.

    1. Re:They could go even further... by netsharc · · Score: 2, Insightful

      Ehm, wouldn't that still enable identification via fingerprint? Get the prints off a drinking glass, measure the points, input the data, and see if the hash matches one stored in the database?

      --
      What time is it/will be over there? Check with my iPhone app!
    2. Re:They could go even further... by digitalunity · · Score: 4, Insightful

      Wouldn't work, for technical reasons.

      Both major algorithms need to be able to compare the data from an authoritative database against the test sample.

      The reason for this is no two scanners, in fact even the same scanner will not produce identical results for the same fingerprints. There will always be "fuzziness" to the data that the algorithm must interpret.

      --
      You can't legislate goodness. Let each to his own destiny, by will of his freely made choices.
    3. Re:They could go even further... by bratgitarre · · Score: 2, Insightful

      They could do even better than that, they could take relative position information you described and then hash it. Hashes are one way, no one can recover the respresentation once it is hashed.

      even with a "secure" hash, if the recorded data has low entropy, you can still guess it in an offline dictionary attack. If you believe otherwise, please post your /etc/shadow for us, thanks!

      But seriously, it's besides the point whether they store hashes or high-res pictures of your fingers. Whoever gets their hand on the database can still identify the prints you leave everywhere. High-res pictures just make it easier for them to impersonate you to other fingerprint scanners.

    4. Re:They could go even further... by Anonymous Coward · · Score: 5, Insightful

      This leads to the principle flaw of biometrics: If someone manages to reproduce the key (synthetic fingerprint for example), there is no way to issue a different key to the owner of the original. Anywhere you authenticate with a fingerprint, the people who control the system can gather all information which is needed to create a fake fingerprint, plus there are countless other ways to get a person's fingerprint, and you still only have that one set of fingerprints that you can't change. What are you going to do then?

    5. Re:They could go even further... by Herby+Sagues · · Score: 3, Insightful

      Hashing would work if the scanners were taking absolute, binary measurements without error. But they are not, not a single biometrics unit has or can have that sort of precision. If you capture your fingerprint parameters with the same device, with the same process, two or three times in a row, you'll see significant changes in the parameters from one time to the next. While the detection algorithms are designed to cope with such scanning errors, hashing would make relative comparisons fail 100% of the time. And there lies the problem with biometrics: once you use them once (or even before you do), your "parameters" are no longer a secret under your control. If you give your fingerpring parameters to your bank, your school and your employer, each of them can in theory authenticate as you to the others. That's why I always say: biometrics are technically useless as an authentication mechanism. They can be used for identification (replacing your username) but not for validation (your password) because they are NOT a secret, they CAN'T be revoked, you don't have the option to use different ones for different organizations and they are easy to fake. Of these issues, only the last one can be improved with better technology, the rest are intrinsic to the concept.

    6. Re:They could go even further... by timeOday · · Score: 2, Interesting

      Then taking pictures of people's faces to identify them will never catch on.

    7. Re:They could go even further... by tburkhol · · Score: 2, Informative

      If "the system," being time-clock or Federal database, uses a specific, formulaic derivation of your fingerprint to establish identity, then storing that formula result is, from a privacy perspective, equivalent to storing your fingerprint. It's a means of identifying you, personally, by extracting your hash from a database of all hashes based on the hash of an unknown fingerprint. That the algorithm is one-way (ie: you can create the hash from the fingerprint, but not the fingerprint from the hash) is irrelevant. Maybe if the has space is small enough that many fingerprints give the same hash value - ie, the has provides sufficient uniqueness for a population of 50 or 100 employees, but not is not unique over a population of 1,000 or 10,0000 - although that seems to compromise its value as an employee identifier.

    8. Re:They could go even further... by Simmeh · · Score: 4, Insightful

      This is why fingerprints should be usernames, not passwords.

    9. Re:They could go even further... by profplump · · Score: 4, Insightful

      This isn't a flaw of biometrics so much as it's a flaw of any dongle-based, single-layer security system.

      For example, you have the same problem with a door with the same key issued to 1000 people -- yes it technically can be changed, but it's quite expensive, so in practice it's never done. That leads to people who should no longer have access still having access, and the ability to easily copy the key and use the copy without detection.

      The solution is trivial. If you combined a password with a fingerprint there would be a secret bit of information that's easy to change AND a physical bit of security apparatus that's harder to reproduce/copy than a password. This same solution also solves the key problem above. And it's the same solution already used in all sorts of applications where security is actually important.

      It's not in use for this timeclock system because the problem they're trying to solve is not a high-security application. They're going from the honor system for clocking in to a single-layer physical-dongle security system, likely in an attempt to raise the barriers for clocking in a co-worker. If they were relying on this system to allow you to make changes to your direct deposit account it would be a problem, but for the stated application I don't see why it's a concern.

      Now, you could be concerned about them having your fingerprints on file -- I understand the desire to keep people from collecting information about you. But honestly, unless you wear gloves all day long, they could already have your fingerprints if they wanted them; fingerprints are not secret information in the first place.

    10. Re:They could go even further... by stewbacca · · Score: 2, Interesting

      This is why fingerprints should be usernames, not passwords.

      That's why they are on our (government) systems.

  25. Re:find another job. by Eskarel · · Score: 2, Insightful

    Let's get something clear here.

    They are NOT finger printing him. They are having him clock on with a biometric finger print scan. There are certainly concerns with this sort of thing, but it's not the same.

    Certainly there are issues with biometric scanning in regards to the quality of the scanners and what you do if your biometrics get compromised(which is possible), but biometric scanning is not the same as being fingerprinted. They'll only ever take one finger, and generally speaking the resulting hash probably won't even be useful outside the proprietary hardware it's running on.

    As for looking for a new job, after making a huge fuss about this and accusing them of acting like a police state in the papers, they're more than likely to sack his ass anyway.

  26. No substitute for good management by goodmanj · · Score: 4, Insightful

    The purpose of this device is to keep people from cheating on their hours. You can get all Big Brothery all you like, but there is one and only one technology that can reliably ensure that people come to work and do the jobs they're paid to do.

    It's called "management". The way it works is, you know your employees' names, you stop by their workstations, both to help them with problems they're having and to check to see that they're doing their jobs. You build up a culture of trust, so that when they need to leave work they *tell* you, and you arrange for them to make up the time.

    Or you can treat them like condemned criminals, and let them be monitored by machines while you sit in your throne of an office eating donuts and browsing bmw.com. It's really up to you.

  27. Re:Contradictory by digitalunity · · Score: 3, Informative

    I am on federal work study right now and I have not had to submit my fingerprints for anything. You have a few options.

    Accept that this is the way they track work study hours.

    If you can afford it and the privacy concerns are too compelling, decline the work and let them know why in a formal letter. It may go directly to the waste bin but at least you made your reasons known.

    Lastly, you can try to change the policy. Contact your student senate for some backing as they're the most likely to listen, although not the most likely to have power to change it. A couple of suggestions: Switch from bio-informatics scanning methods to plain old bar code badges, RFID chips or paper timecards.

    My school does work study timecards on paper. It's probably the most likely to be abused, but it is convenient for everyone. I'd be more than happy to use an RFID token or bar code badge for clocking in and out. Wouldn't work very well for my specific job, considering I work from home, but in theory I would accept either.

    Your ability to change the policy by force is pretty limited. Employment rights(especially regarding privacy) vary by state when it comes to work study. You could try to contact your local department of labor but it's unlikely they will give you anything other than a headache.

    --
    You can't legislate goodness. Let each to his own destiny, by will of his freely made choices.
  28. It would be illegal in many EU coutries by L-One-L-One · · Score: 4, Interesting

    I know this will surprise many slashdot readers but using your fingerprint as described by the poster for the purpose of clocking you in and out of work would be illegal in many countries accross Europe (with the possible exception of the UK). In France, for example, you can actually get fined by the data protection authority for doing so.

    It's true that most of these devices don't store an image of your fingerprint but rather a "template" : a description of some special features of your fingerprint. But that doesn't change the problem.

    Indeed, many data proctection authorities accross the EU consider that biometrics pose sevreall security and data protection issues and must therefore be used with caution. Fingerprint biometrics are of special concern, in particular when the biometric data (templates) are stored in a central database. The big problem with fingerprints is that we leave them everywhere, on all objects we touch. Someone can pick up your fingerprint and test it against the templates inside the database. (Sounds crazy or technically impossible ? It's much easier than you think : i've tested it myself, that's part of my job). There are other issues whith fingerprint biometrics that I won't detail here.

    In the end data protection authorities in the EU consider that the use of a central fingerprint database is excessive if your only objective is only clocking people in and out. Instead, they encourage the use of a smartcard to store the biometric data : you show your finger to the biometric reader and it gets compared with the data stored in the smartcard. This solution offers the same benefits in terms of security but you keep control of your biometric data.

  29. Re:find another job. by turbidostato · · Score: 2, Insightful

    "This type of Orwellian"

    Oh, holy shit! I'm as much concerned about privacy as any other next guy and then probably more, but this is crystal clear:
    1) Do you think there's a need for authorization (you can go in, you can't go in)?
    2) If yes, then you need authentication. As in you *need* authentication or else no one will be sure the authorized guy is the one meant to be authorized.
    3) If you need authentication, then biometrics is quite a good candidate (while not absolutly great: once it gets tampered there's no easy replacement)

    Privacy is not about nobody tracking your steps; it's about nobody tracking your steps except for really valid reasons and only for as long as those valid reasons stand valid.

  30. Why even ask about privacy? by Jane+Q.+Public · · Score: 2, Interesting

    Privacy doesn't seem to be the real issue here, unless they're selling your prints to the Feds. What I would like to know is: given the fact that these things don't work worth a damn, why would they be using a system like this in the first place?

    I mean, if I had to use a fingerprint scanner for identification, I'm the kind of person who would fool with it just for fun. The only way they have been able to make them "reliable" -- that is, reliably accept your fingerprint and not lock you out -- was to loosen up the match criteria enough that they are much too prone to false positives, which in turn makes them easy to fool.

    I would do things like clock in Susan for four hours when she is really on vacation in Hawaii, for example, just to see what happens. Or clock in Sam at 3 a.m. so that when he comes around at noon and scans, he's really clocking out. And so on. Consider it like friendly hacking... you are showing the owners that their system just doesn't work. It's a useful technique when they simply won't listen to reason.

  31. Get over it. by Domini · · Score: 2, Informative

    Sheesh... this is the same as having public and private encryption keys. The private one is for you, the public one is... you guessed it, public, and cannot be used to reproduce or fake the private one. They only store enough data to verify your fingerprint again. VERIFICATION and IDENTIFICATION are two very different things. No privacy issue.

    Move along, nothing to see here...

  32. Has more to do with hygene than privacy by GrantRobertson · · Score: 2, Interesting

    GEEZ! The Slashdoters sure can pitch a fit about nothing!

    These devices only store a few numbers that were derived from the patterns of your prints. They don't store anything near the actual image. When you re-scan your finger to clock in it creates a new set of numbers and looks for a set that is statistically close to something it has in it's database. Usually you have to enter a PIN as well because these things do such a crappy job that without knowing where to start, it would have a terrible time figuring out which of the stored sets of numbers match up to the one you just scanned in. I'm not saying that some systems can't do a great job. I'm just saying that the kinds of systems they sell for time-clocks are usually pretty lame. Especially after they get beat around for a while. So all these time-clock units really do is determine if the clock-in scan is statistically close enough to the original scan to be more likely to be you than some other employee. The actual data stored is less personally identifiable than your name. Are you gonna complain if they ask you to give your name when you clock in?

    I also seriously doubt that these things produce any form of standardized data that could be transferred to any other system. Heck, sometimes the scans won't match up just because you bought a slightly different model from the same manufacturer to replace a broken unit. Ever try to troubleshoot one of these systems? It is a nightmare.

    So, you have nothing to worry about. "They" are more likely to track you by mere facial recognition via security cameras than by your fingerprints.

  33. Been there, done that by Mathinker · · Score: 2, Informative

    OK, I've actually never faked a fingerprint myself. But I've read about research on it in Bruce Schneier's blog:

          http://www.schneier.com/crypto-gram-0205.html#5

    Care to guess what the batting average of most fingerprint readers was against someone trying to fool them?

    (Answer: the eleven commercial fingerprint ID systems, together, wouldn't defeat my son's blindfolded Little League team.)