PaymentsJournal
SUBSCRIBE
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
No Result
View All Result

Confusion Still Persists With Biometrics And Passwords

Hitoshi Kokumai by Hitoshi Kokumai
January 22, 2018
in Industry Opinions
0
Relying on Fingerprints or Face Recognition is a Mistake, Multifactor Remains an Imperative

Hand pressing the Fingerprint scan the smart phone with technolog icon for unlock the screen over digital screen, business and technology concept

12
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

On a number of tech media still circulating so rampantly are confused reports about the password and biometrics deployed in cyberspace. We could assume that the people who circulate the befuddled perception may well have mixed up the following two views.

A: Biometrics brings some security (better than nothing).

B: Biometrics brings the security better than a password.

A is correct but B is a fallacy. Logic tells that biometrics deployed with a backup/fallback password brings down the security of password protection, offering better convenience to users and criminals alike, as shown in this short video. (https://youtu.be/wuhB5vxKYlg)

Two questions come up; (1) where, why and how those tech-reporters are mistaken and (2) who are behind the birth and growth of this confused perception.

Where, why and how are they mistaken?
  1. Unknown Nature of Biometrics

It is getting known that NIST no longer allows biometrics to be used on its own but requires it to be used ‘only as part of multi-factor authentication with a physical authenticator (something you have)’ in view of the inherent vulnerabilities of biometrics as stated in 5.2.3 ‘Use of Biometrics’ of Digital Identity Guidelines 800-63B.

Privacy issues of biometrics are relatively well known. Not a few people are aware that it will be catastrophic when biometrics data are leaked, since it is impossible to change or cancel biometrics data. (‘when’ rather than ‘if’ in view of the long lists of data breach by sophisticated attacks.)

But the security aspect of biometrics brought by the co-use with a fallback password is unknown. It is probably due to the indifference of the participants to those facts as quoted below.

–  Perfectly fake-proof biometrics would still be less secure than a password where it is co-used with a backup password; two entrances placed in parallel provide nice convenience to criminals.

This is what we witness in so many biometrics products deployed in cyberspace

–  False acceptance of 1/1,000,000 is not necessarily better than that of 1/50,000; we need to know the corresponding false rejection rates before judgment.

The lower a False Acceptance Rate is, the higher the corresponding False Rejection Rate is.  The lower a FRR, the higher the corresponding FAR.  That is, FAR and FRR are not just mutually dependent but are in a trade-off relation.

– ‘Unique’ is not ‘Secret’; biometrics data may be unique but not secret.

Identification that follows unique but non-secret data does not act for authentication that requires shared secrets.

– The same biometrics solution provides different levels of security in physical space and in cyber space; what helps the former could ruin the latter.

Biometrics could be better used for identification in physical space, not for authentication in cyberspace.

  1. Overlooked Security in Cyberspace

The security we need is for safer life of good citizens. We do not need such security measures that help criminals and tyrants.

–  A password-less Life is a Dystopia; where we can be authenticated while we are unconscious, it would be horrible for most of us.

A society where identity authentication is allowed without users’ volition would be the society where democracy is dead. The password as memorized secret is absolutely necessary.

–  Solutions that come with a password in some way or other cannot be an alternative to the password; a walking stick cannot displace a person with a walking stick.

ID federations and multi-factor authentications are the extensions, not displacement, of password authentication.

  1. Ignored Nature of Humans’ Identity

Having our identity authenticated is for social activities in human communities, in which our identity is not separated from our volition and personal memories.

–  We must discuss our identity as ‘a citizen in society’, not as ‘a chunk of bone, flesh, fat and skin’.

Democracy must require the individuals to have the rights not to get their identity authenticated without their knowingly confirming it.

–  Tech-media love to deride weak passwords; creating strong passwords is one thing.

Remembering them is another. And, recalling the relations between the accounts and the corresponding passwords is yet another. We need to be mindful of the nature of our memory and cognitive capability.

Who are behind the confused perception?

The confused perception does not come up from nowhere. There are people behind it.

We could think of three groups of people – who generate the fallacy, who pour fuel on it and who disperse it.

– Those who generate the fallacy; presumably researchers, developers and vendors of biometrics sensors

– Those who pour fuel on the fallacy; Perhaps not a few security professionals who wrongly endorsed the fallacy and are now turning a blind eye to what has now grown to be an anti-social phenomenon.

– Those who disperse this misinformation; probably corporate users, financiers and the tech reporters who are misguided by those who generate and pour fuel

To err is human. We know that NIST admitted that they had long been mistaken in their old password guidelines.  We should not blindly trust all that professionals, experts and gurus tell us, but should rely on our own logical reasoning.

The above people may have been trapped unwittingly in the wrong belief that the biometrics that could help physical security should also help cyber security. Many of them may now be aware specifically that their biometrics products are actually bringing down the security in cyberspace and looking forward to the opportunity to admit the fact, desirably without affecting their reputation.

Making this clear, we could then move to the true question; what will eventually succeed the hard-to-manage password?

Reference

Biometrics & Password – FA, FR & Threshold

https://www.slideshare.net/HitoshiKokumai/biometrics-password-fa-fr-threshold

– Fallacies and illogics generated and dispersed by professionals, big businesses and tech-media

http://expandedpassword.blogspot.jp

– Identity & Episodic Memory

https://www.slideshare.net/HitoshiKokumai/identity-episodic-memory

About Author

– Hitoshi Kokuman is the inventor of Expanded Password System that enables people to make use of episodic image memories for intuitive and secure identity authentication.  He has kept raising the issue of wrong usage of biometrics with passwords and the false sense of security it brings for 16 years.

– Mnemonic Security Inc. was founded in 2001 by Hitoshi Kokumai for promoting Expanded Password System. “Mnemonic” and “Mneme” used in the company name and logo imply that our identity must be protected with our own memory and volition.  Following the pilotscale operations in Japan, it is currently searching for the location to set up the global headquarters.

Related Article by this Author

– Mitigation of Password Predicament

https://www.paymentsjournal.com/Mitigation-of-Password-Predicament/

Tags: BiometricsSecurity
12
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Analyst Coverage, Payments Data, and News Delivered Daily

    Sign up for the PaymentsJournal Newsletter to get exclusive insight and data from Mercator Advisory Group analysts and industry professionals.

    Must Reads

    cross-border payments

    Cross-Border Payments: Fighting
    E-Commerce Fraud Using Data

    March 20, 2023
    fraud, ChatGPT-4

    How to Fight Fraud While Still Enabling a Great Online Customer Experience

    March 17, 2023
    RTP

    Financial Institutions Without an RTP Strategy Risk Being Left Behind

    March 16, 2023
    visa chargeback

    New Visa Chargeback Guidelines Will Be a Game Changer

    March 15, 2023
    liquidity management

    Liquidity Management Takes on Increasing Importance in Uncertain Economic Times

    March 14, 2023
    payments

    Key Challenges from Growing Payment Methods and Volume

    March 13, 2023
    Data Governance is a Journey, financial data

    How FIs Can Power Their Operations with a Modern Data Architecture

    March 10, 2023
    ISO 20022

    How Banks Can Realize Business Benefits and Reduce Payments Fraud With ISO 20022

    March 9, 2023

    Linkedin-in Twitter

    Advertise With Us | About Us | Terms of Use | Privacy Policy | Subscribe
    ©2023 PaymentsJournal.com

    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Videos
    Menu
    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Videos
    • Industry Opinions
    • Recent News
    • Resources
    Menu
    • Industry Opinions
    • Recent News
    • Resources
    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Industry Opinions
    • Faster Payments
    • News
    • Jobs
    • Events
    No Result
    View All Result

      Register to download the Autorek complimentary report: Payments Industry Outlook 2023: