Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A fingerprint is never a secure password. It is a username at best.


No. It is a biometric identifier. That is what it is. A username is a human language convenient symbolic pointer that is meant to be public and used socially. I am still confused about why this particular incorrect meme is so persistent. "Something you know, something you have, something you are" all are simply different classes of authentication factor, and all are distinct from names, or UIDs, or any other bit of meta-information that isn't for authentication.

Just like "something you know" can have different strengths, "something you are" can too and changes in technology and threats will enable new options alongside new attacks as we go along. It's a process.


I've only heard the "something you know" and "Something you have" from my old graduate level security class. This is the first I've heard of "something you ARE" and I like this distinction. It makes sense.

Not only can "something you are" change (in some instances), it can also be something that can be difficult for technology to not recognize correctly. A username or password must be correct (unless you're Facebook and do that goofy thing where you allow both the upper and lower case versions) but a biometric is more fudgable.


Biometrics would be the something you are. A passphrase/pin would be the something you know. A fob/token would be the something you have.

Of course, the something you are necessitates a biometric system that itself can be trusted to be secure.


>I've only heard the "something you know" and "Something you have" from my old graduate level security class. This is the first I've heard of "something you ARE" and I like this distinction. It makes sense.

I'm somewhat surprised because it's definitely not new, I don't know what the exact genesis of that particular cryptographer's verse is but my vague recollection is I first heard it the late 90s, and the idea of extracting bits showing identity from physical qualities unique to a person certainly dates back a long ways. "Something you are" can cover a lot of possibilities too, and with vastly more variety and subtlety than I think a lot of people consider even in security fields. For example, there was recently a genuinely very interesting idea of measuring bottoms. As in, your actual behind/ass, via sensors in chairs. It should be unsurprising if you consider it, but of course the patterns of musculature/fat/bone structure are fairly unique to you for any part of your body if you have sensitive enough tools. It's a transparent measure for certain use cases like a workstation or the like since you're sitting down anyway, and hard to clone from afar since our butts are typically covered and subdermal is challenging without near contact. Another place if you want to look for cutting edge possibilities is advertising/surveillance. Near anything used for tracking fingerprinting could in principle be used for authentication too, and again there are potentially a lot of bits of entropy to be found there. Our gaits as we walk, our patterns of typing, our micro muscle movements, all sorts of things aren't so generic to a powerful enough system. "Biometrics" is to some extent at the stage of 80s or early 90s passwords, something to keep in mind in these discussions when people complain about them. 8-character alphanumeric passwords protected by crypt aren't exactly good these days either, but auth tech moved on even as tech benefitted attackers. In the future biometrics will undoubtedly consider far more than our current early generation systems, up to and including implants.

FWIW, I have (more rarely) seen a few other classes of factor suggested that do make sense, and are arguably distinct categories. One is spatiotemporal, ie., "somewhere/somewhen you are". This is used de facto by any sort of air gapping or "this system can only be accessed from this one place and console" or the like. It could though be taken advantage of far more thanks to more ubiquitous high resolution GPS and the like in our systems. Having certain kinds of data only become accessible in the right place/time could be very useful.

Another fuzzier category is "something you do", as-in observing the actions you take. I felt at one point that this was merely another way of measuring "something you are", but I can see the idea that it'd be distinct because it's about revealing your direct state of mind, whereas at least for the foreseeable future "something you are" tends to focus on more bulk matter aspects of your being. Technically state of mind is physical too, there is a specific vector state of axons and neurons and firing patterns that represent it, but it might make sense still to distinguish that from physical body structure or even implants. Whatever the case though it's still an interesting consideration, and makes a lot of sense in old school counterops. Sometimes the first sign of someone who "shouldn't be authenticated to use this" has been "they were 'acting funny'" after all.


"Something you are" and "something you have" are the same class, just that the thing you have is physically attached to your body. Doesn't matter if it's a fingerprint, a chip installed under your skin or a tattoo. Pretty pointless distinction. Fingerprints, faces and eyes are merely conveniences.


Nope, they are quite different exactly because "something you are" is attached to you and "something you have" is not. One can be swapped out if compromised or get lost. The other can not (intentionally or unintentionally) be replaced, but -- because it is something biological -- undergoes slow changes over time. These differences are sufficiently large that it makes sense to split it into two categories when modeling the whole system from a security -- or usability -- standpoint.


> "something you are" is attached to you

And can be compromised without theft, coercion or any other trace.

> One can be swapped out if compromised or get lost.

Which makes something you are strictly worse than something you have.

> undergoes slow changes over time

You are lacking an argument for anything attached to this point.

> ...it makes sense to split it into two categories

So you are arguing that because something is strictly worse from a security standpoint, it should be categorised as a new category? Have I summed up your position correctly?

There are usability benefits which would exist similarly by attaching something which couldn't be easily compromised to your body. For example a chip under your skin or just carrying a watch on your wrist which you could authenticate with after putting it on and which would un-authenticate automatically when it is taken off. Nobody would argue that you are your chip or your watch.

Something you know is different because there are no plausible ways aside coercion and similar for extracting such secrets in idle, and the other alternative is to get compromised on usage. It's about the threat models.


They are different classes. Something you are can be stolen or copied, but you can't easily trade it away.

Something you have can have strong copy protection like a yubikey and can be given away.


See answer above.


Because you asked, it comes from a popular blogpost that has been discussed on here a couple times. Here's the last discussion: https://news.ycombinator.com/item?id=11549536


I can read your username once and remember it. I can't do the same with a fingerprint


I'm sure you can produce a hash from fingerprint model data for your reading pleasure


OpenSSH does that thing now where it can visually display ASCII art of your key fingerprint.


Depends on the username. And you don't have your username written on your body.


That's not dispositive, you also can't dust for names.


I think you mean the worst case scenario for a fingerprint is that it's a username.


I think what he means is that you leave your fingerprint everywhere without even realizing it so it's the biometric equivalent of asking for your email; a random attacker won't know it but any one with a wee bit of motivation can get it.


What I meant is: you can not change it and you can not keep it secret so it makes a poor password replacement. Usernames do not have to kept secret (you know that my username on HN is petschge), so finger prints might be slightly more usable as usernames than they are as passwords. They are of course not great for that either. Their best use might be similar to the "card present verifier" on the back of a credit card, i.e. as a sign that the person who entered they username, they password (and possibly a physical auth token like a chip card) is actually present themselves. Or don't use fingerprints at all. They are not secure nor convenient as you think.


I agree with this, but think that faces face the same issue. If anything, we leave our faces more places than our fingerprints; fingerprints smudge over time, but faces are big enough to capture at sufficient detail using cameras that are already widely deployed. iOS is betrer about facial recognition than Android (and I'm not an Apple fanboi), but it can still be hacked with some patience and enough video frames of the given face at different angles. I would really like biometrics to work, verifiable proof-of-human would be great, but I can only buy into them as an additional requirement for authentication; a piece of privately known/held information is still our most secure authentication mechanism for competent users.


> iOS is betrer about facial recognition than Android (and I'm not an Apple fanboi), but it can still be hacked with some patience and enough video frames of the given face at different angles.

FWIW, I don’t think anyone has done this credibly yet.


It's an arms race where people keep breaking into a specific version, Apple makes it harder, and nobody can get into the new shit for a while. There was a method for the X (dunno if updates have made it harder), but not for anything more recent AFAIK. I bet we see another one drop in the next couple years. It's just an engineering problem.


> There was a method for the X

I don't recall seeing one. Do you have a link?



You are right. But note that I never said that faces where any better.


True that, I didn't mean to imply otherwise; I just thought your comment was the most coherent rebuking of fingerprints I'd seen so far while skimming, and I thought it would be a good place to expand on your sentiments with my own thoughts. I do see how my opening "but" could be confusing in this regard.


A wee bit of motivation, hah, are you James Bond or something?

Usernames can be guessed remotely, fingerprints can't really.

Please demonstrate an attack that takes "a wee bit" of effort where you can use a fingerprint you found in the wild to auth.


The CCC went after a German politician to show just how easily you could copy a fingerprint even without access to an object touched by the target[1]. A few pictures of the finger are more than enough.

[1] https://www.macrumors.com/2014/12/29/ccc-reproduce-fingerpri...


How do you actually use the picture of the fingerprint to get into a phone? It doesn’t accept pictures, only fingers.


Print with a laserjet onto overhead projector foil, spread a suitable kind of wood glue, dry, peel and apply to own finger tip. It is actually very straight forward.


From the NewScientist article Laforet linked above:

> fake fingerprints can be created by imprinting copies in rubbery gels or silicone plastic, says Marcela Espinoza of the Institute of Police Science in Lausanne, Switzerland.

Replace silicone with some other flesh-like material that's conductive.


Ok but isn't that significantly more trouble than seeing or guessing a username?

Does this take just a "wee bit of motivation"?


This video[1] is German, however as far as I can tell everything you need to get from an image to a fake print is easily available. The relevant part starts at 65 seconds. Only a few minutes to get a working fake. It is basically the process described by petschge.

[1] https://youtu.be/OPtzRQNHzl0?t=65




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: