a thoughtful web.
Good ideas and conversation. No ads, no tracking.   Login or Take a Tour!
comment by goobster
goobster  ·  460 days ago  ·  link  ·    ·  parent  ·  post: Authenticating without a password is something we should talk about

Biometric data is just another identifier, like a SSN, driver's license, name, whatever. Because it is harder to gather right now does not make it any different than any other identification method. All the same security concerns apply.

Regardless of whether the imposter has my social security number or the digital hash of my blood's fingerprint, it's just data. And that data can be validated or invalidated through more stringent testing methods; like running another blood test and validating I am who I say I am. No scammer has access to my blood, so I'll always be able to prove I am me.





kleinbl00  ·  460 days ago  ·  link  ·  

I'ma go get a new driver's license. You go get new fingerprints. We'll circle back and compare our tasks, deal?

"Aha!" you're tempted to say. "But I can always prove who I am because I have the original fingerprints!" Sure. But you're going to verify your fingerprints by going "look this is my birth certificate I'm really me and THESE are my fingerprints" and so is the guy who is stealing your fingerprints and because he's aware he's doing it and you're still catching up, lo and behold, you are no longer you.

In a normal situation when you've been subjected to identity fraud, you erase the defrauded shit and start over. In a situation where the fraud involves biometrics, there will forever be an asterisk next to your data. You're going to take longer to get on a plane, you're going to be held up by medical insurance, your bank loans are going to be subject to additional scrutiny, all of it. It'll be the same as the credit bureaus do to you NOW except they'll say "we use biometrics we're perfect" and it'll be ten years of brown people bitching about how that is very much not the case before a single white person gives a shit.