Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts

Monday, June 5, 2023

Authorized Pets Only

found on Reddit

Having seen how difficult face recognition can be in humans, I don't have a lot of faith in this application either. Among all the other problems, have fun enrolling your pets when they're soaking wet, because that's what they're going to look like when they want in in a hurry.

Thursday, June 1, 2023

Cutting edge security

@normalmemess #phone #joke #funnyvideos ♬ Originalton - Normal Memes
Something no one really wants to talk about is the fact that most biometric authentication is just one knife accident away from being token-based authentication.

Tuesday, May 23, 2023

Brute Force: Now with less brutality

from here and here

My fingers are resting just a little bit easier knowing that there are now attacks against fingerprint authentication that involve a dictionary of digitized fingerprints. I'd just as soon the vulnerabilities involved not get fixed as that would force attackers back to using less civilized means. 

I suppose it might be more accurate to call it a dictionary attack rather than a brute force attack, but what do I know?

Monday, May 22, 2023

Maybe it's just the work you had done

found on Dump A Day

I can't imagine facial recognition is going to handle facial modification all that well. If you get cosmetic surgery, be prepared to re-enroll.

Monday, May 1, 2023

How much verification is too much?

from here

This is the precise problem I've been having with GMail. I enter the correct password and then GMail decides that's not good enough. Then they say they needs to verify me so they sends a code to my recovery email, and when I present the code back to them they decide that's not good enough either. Why attempt verification that way if you aren't going to accept the results? Anyway, now they want a cell phone number to send a code to, but I don't have a cell phone and even if I did I have little faith left that the result of that would be any different than the email verification.

Unfortunately I made the mistake of tweeting about the problem and as a result scammers have been sending me messages for days promising to help me get back into my account if I just contact them through Instagram or Whatsapp. I can recognize them for the scams they are, but not everyone would, so essentially Google's attempts to curb account take-overs are actually creating opportunities for account take-overs. 

Wednesday, April 26, 2023

Freaky Friday Jailbird Edition

from here and here

Well here's a new twist on "You've got the wrong guy". I wouldn't want to be the guy left behind, but even worse, I wouldn't want to be the guard who not only failed to see through the impersonation but also failed to recognize it might be a possibility. Authentication by the honour system is not something you should try with criminals.

Friday, March 10, 2023

Biometric racism

found on Reddit

How can technology be racist? Well this is a perfect example. The people who made this biometric authentication technology had a racial bias in favour of certain facial features and failed to account for or consider any races that didn't meet their criteria - thus this error message telling someone to open their eyes wider than they naturally would open. It means they can't use the technology as easily (or at all) which means they don't get access to the same level of security that someone from a different race would. 

Thursday, March 2, 2023

Who's The Login


Watch on YouTube

Abbott and Costello for the information security age.

Monday, February 20, 2023

First World Security Problems

from here and here

This is probably going to be an unpopular opinion in certain circles, but Twitter erecting a barrier in front of the laziest form of 2 factor authentication isn't that big a deal. Not only because there are more secure options that are still free for the people who really need 2FA, but also because the vast majority of people don't really need it. In fact, the vast majority of people aren't even using 2FA right now. 

While it would be good if everyone was using 2FA for things like their bank or their email account, it is a foolish consistency to think we need it for everything.

Friday, December 2, 2022

It's more "secure"

from here and here

There are some scenarios where I can see fingerprint biometrics providing a lot of additional security, but phones and laptops aren't among them. It's like a combination lock with the combination written on it. They do provide convenience, and maybe that's what we should be caring about, but we shouldn't try to pretend it's for security

Wednesday, July 27, 2022

Good thing you didn't forget which finger to use

found on Acid Cow

There are a variety of reasons why unlocking a phone with just a fingerprint might not be a good idea (such as the fact that it can be entered without your consent by an intimate contact or compelled from you by the authorities) but if those kinds of adversaries aren't part of your threat model then forgetfulness is certainly an argument in favour of fingerprint unlock.

Friday, April 8, 2022

Turn the other cheek

from here and here (image source)

I sometimes question whether fingerprints are actually more secure than passwords, but I'm not sure if buttprints have the same caveats 

Thursday, January 6, 2022

Computerphile: Fingerprint Recognition


Watch on YouTube

There are of course additional steps one can add to the process to make sure you're dealing with a live genuine finger rather than some sort of facsimile, but it still boils down to comparing minutae points.

Wednesday, December 29, 2021

Biometrics are easy, they said

found on Reddit

There are a lot of assumptions inherent in any authentication mechanism, but ones that are relatively new deserve to have things spelled out a little more clearly than just 3 words. It's not like they don't have room for more words, there's plenty of room.

Friday, December 17, 2021

The Biometric Bandit

from here and here

This bad ex-boyfriend in China is yet another reminder that biometrics enable authentication without consent.

Tuesday, December 7, 2021

A Key Is A Metal Password sticker

Product Page

While it's not strictly true (a key is more of a token than a password), they are both authenticators, and there's actually not that much difference between them. After all, if you write down your password on a slip of paper and then forget it, it becomes something you have rather than something you know. Likewise, if you memorize the bitting on a key, then with the right tools you could push the pins in a lock up the right amount from memory.

Wednesday, November 17, 2021

Not sure about that beard, though

found on Reddit

A little bit of weight gain isn't going to change the contours of your face much, but growing a beard is certainly going to obscure what was there before. 

Thursday, November 4, 2021

Go Go Gadget Fingernails

from here and here (image source)

In terms of authentication, keys have traditionally represented tokens or "something you know", while body parts are usually consider to fall under the heading of "something you are" such as biometrics, but what happens when you combine the two? If it's attached to you is it really still just something you have? And biometrics aren't strictly about your biological components. If you have a prosthetic nose, do you think face recognition isn't going to use it? Of course it will. 

Wednesday, October 20, 2021

No access for Sweaty McClammyHands

found on Funny Junk

Generally this would be an annoyance, but if the reason your fingers were sweaty was because the cops were interrogating you then maybe this works out in your favour.

Friday, September 24, 2021

When you forget about the bad guys

found on Funny Junk

Sometimes we use security controls more out of habit than anything else. We forget why they're there and why we need them and so we sort of go through the motions and don't get any benefits as a result.