Hitoshi Kokumai

3年前 · 2 分の読書時間 · 0 ·

ブログ作成
>
ブログ Hitoshi
>
Biometrics for Increasing and Decreasing Security

Biometrics for Increasing and Decreasing Security


"Air Force and DISA working to secure off-the-shelf phones with specialized cases" https://www.fedscoop.com/phone-cases-security-air-force-disa/

It could be a correct use of biometrics for increasing security if biometrics is used for continuously monitoring the user's voice and behaviors to detect when a bad guy has grabbed the logged-in device from the user.

Demand the user's password afresh, and the bad guy could be turned away as discussed here - "Anything used correctly is usefuland so are UV, disinfectant and biometrics."

It could be a wrong use of biometrics for decreasing security if biometrics is used as a second authenticator along with a default password as examined here - "Early models of smartphones were safer thannewer models - How come?"

Windows Hello for payment authentication would be fine if the objective is to increase convenience, not security – “Google Chromesupports “Windows Hello” face unlock and fingerprint for payment authentication”


-----------------------------------------------------------------------------

"Early models of smartphones were safer thannewer models - How come?"


ecc079ec.png

Early iPhones only with PINCODE were safer than the newer iPhones with TouchID and FaceID added. The same observation applies to the newer models of all the smartphones, PCs and tablets that come with biometrics.

 The point is that even a perfectly hacking-proof biometrics could only provide the level of security lower than a PINCODE-only authentication when the biometrics is deployed in 'multi-entrance' method with a PINCODE as a default fallback measure against false rejection (false non-match).

 This is what a logical reasoning inevitably leads us to, as illustrated in the picture above and in this brief video.

 Biometrics might help security in physical space where there are competent managers who are ready to take care of falsely rejected people. But, in cyber space, the fallback measure against falsely rejection (an extra entrance) has to be provided by the falsely rejected people themselves.

The security effect of ‘multi-entrance’ deployment of 2 authenticators as against ‘multi-layer’ deployment is quantitatively examined in this article "Quantitative Examination of Multiple Authenticator Deployment"

 A huge amount of resources have been spent for a huge volume of biometrics products. We could say that the resources were well spent if all the users and consumers had knowingly adopted the biometrics solutions as a convenience-improving tool, not a security- enhancing solution. We doubt it is the case.

 Sharing our observation may well be enormously embarrassing and inconvenient for the people who had advocated, promoted, recommended and marketed the biometrics products as a security enhancing tool.

Opting to stay silent could be taken as opting to be complicit. We could be somewhat sympathetic in view of the collective pressure of the environment, but their children and grandchildren may be just unsympathetic. We would like to recommend them to come out and speak up sooner than later.



コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

I take up this report today - “Facebook's metaverse plans labelled as 'dystopian' and 'a bad idea'” ...

2年前 · 2 分の読書時間

Our password headache may well be the consequence of these dual causes - · ‘Use of Impracticable Pas ...

2年前 · 2 分の読書時間

Bad guys, who have a quantum computer at hand, would still have to break the part of user authentica ...

この職種に興味がある方はこちら

  • 城南コベッツ 茅ヶ崎教室

    塾講師 アルバイト 個別指導

    次の場所にあります: beBee S2 JP - 3日前


    城南コベッツ 茅ヶ崎教室 茅ヶ崎市, 日本 パートタイム

    雇用形態 · アルバイト · 職種・指導形態 · 個別指導 · 基本は「講師1人に生徒2人まで」の個別指導です。 · 演習形式の複数名授業、勉強会等において集団授業スタイルも実施することがあります。 · 給与 · 1コマ90分1,670円〜2,250円 · ■1コマ1,670円〜2,250円(授業80分+付随業務10分) · 時給[1,113円~1,500円] · ※試用期間(指導開始月~3ヶ月)は[時給:1,113円]となります。 · ※授業以外の事務業務にも給与のお支払いをしています。詳細は面接時にご確認下さい。(規定あり) · ■給与見直しあり(最 ...


  • 株式会社アンビス Utsunomiya, 日本 正社員

    採用情報 勤務時間 8:30~17:30 · 16:30~翌9:30 · ※夜勤明けの次の日は基本お休み 想定給与 年収:599.9万円 · 月給:43.68万円 · ※夜勤5回/月手当込み、拠点により回数は異なる · ※地域限定をご希望の場合、要相談 休日・休暇 週休2日(シフト制) · 年間休日:115日(夏季冬季休暇含む) · 有給休暇:4月or10月付与 必須スキル・経験 看護師免許必須(准看護師不可) · 臨床経験3年以上 歓迎スキル・経験 看護師としての一般的な病態生理や症状・治療の知識や観察力、洞察力がある方 待遇 住宅手当あり(当社指定単 ...

  • ハーバータウンクリニック

    准看護師

    次の場所にあります: Whatjobs JP C2 - 3日前


    ハーバータウンクリニック Osaka, 日本

    **タイトル**: · 准看護師 · **このお仕事の特徴**: · 残業なし 賞与あり 産休・育休取得実績あり 急募 即日勤務OK · **勤務先名**: · ハーバータウンクリニック · **職種**: · 准看護師 · **仕事内容**: · - 各線難波駅から徒歩スグ好立地なうえ、雨にも濡れません · - 経験が浅い方もしっかりとした研修でサポートしますので安心して勤務できる環境です人間関係良好ですよ · - 年間休日も120日以上お休みが多いので、メリハリをつけて働くことができます。忙しい主婦の方や子育て中の方も歓迎です · ※透析経験必須 · ...