Hitoshi Kokumai

5年前 · 2 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Update: Biometrics helps for security in ‘physical space’. Not in ‘cyber space’.

Update: Biometrics helps for security in ‘physical space’. Not in ‘cyber space’.

 

Mix up “Unique” with “Secret” and we would confuse “Identification” with “Authentication”. What is feasible in physical space is not necessarily feasible in cyber space.

Biometrics follows “unique” features of individuals’ bodies and behaviors. It means that it could be well used when deployed for identification of individuals who may be conscious or unconscious, alive or dead. Due respect could be paid to biometrics in this sphere.

Being “unique” is different from being “secret”, however. It would be a misuse of biometrics if deployed for security of the identity authentication of individuals.

Confusing “Identification” with “Authentication”, we would be building a sandcastle in which people are trapped in a nefarious false sense of security. However gigantic and grandiose it may look, the sandcastle could melt away altogether when we have a heavy storm.

Tech media seem busy arguing which biometrics is better than the others. But it is all nonsense in cyber space from security’s point of view. Instead we should ask why security-lowering measures have been touted as security-enhancing solutions.

Because of its inherent characteristics, biometrics depends on a fallback means in case of false rejection. In physical security, it could be handled by personnel in charge other than the user. In cybersecurity, however, it needs to be handled by the user themselves, in most cases by way of a password that the user themselves needs to feed.


Worry about a backdoor?

So long as the biometrics is backed up by a fallback password, irrespective of which are more accurate than the others, its security is lower than that of a password-only authentication as illustrated inthis video

Then, we have to wonder why and how the biometrics has been touted as a security-enhancing tool for so long, with so many security professionals being silent about the fact.

There could be various explanations – from agnotology, neuroscience, psychology, sociology, behavioral economics and so on. This phenomenon will perhaps be found to have provided an excitingly rich material for a number of scientists and researchers in those fields.


Appendix - Quantitative Examination of Multiple Authenticator Deployment   (Added on 15/Feb/2019)

It appears that there are so many security professionals who pay no attention to the exactly opposite effects of 'multi-layer' and 'multi-entrance deployments.  ‘Multi-Layer’ is also represented by ‘In-Series’, ‘In-Addition-To’, ‘All/BothAnd’ and ‘Conjunction’ ,  while

‘Multi-Entrance’ by ‘In-Parallel’, ‘In-Stead-Of’, ‘EitherOr’ and ‘Disjunction’.   Let me offer a quantitative examination of multiple authenticators deployed in two different ways.

Vulnerability (attack surface) of an authenticator is generally presented as a figure between 0 and 1. The larger the figure is, the larger the attack surface is, i.e., the more vulnerable. Assume, for instance, as just a thought experiment, that the vulnerability of the PKI-enabled token (x) be 1/10,000 and that of the password (y) be 10 times more vulnerable, say. 1/1,000. When the two are deployed in ‘multi-layer’ method, the total vulnerability (attack surface) is the product of the two, say, (x) and (y) multiplied. The figure of 1/10,000,000 means it is 1,000 times more secure than (x) alone.

On the other hand, when the two are deployed in ‘multi-entrance’ method, the total vulnerability (attack surface) is obtained by (x) + (y) – (xy), approximately 0.0011. It is about 11 times less secure than (x) alone.

So long as the figures are below 1, whatever figures are given to (x) and (y), deployment of 2 authenticators in ‘multi-layer’ method brings higher security while ‘multi-entrance’ deployment brings lower security. As such ‘multi-layer’ and ‘multi-entrance’ must be distinctly separated when talking about security effects of multiple authenticators.

Remark: Some people may wonder why (xy) is deducted from the sum of (x)+(y).

When (x) and (y) is very small, the (xy) is very close to 0, which we can practically ignore. But we should not ignore it when the figures are considerably large.

Imagine a case that both the two authenticators are deployed in an extremely careless manner, for instance, that the attack surfaces of (x) and (y) reach 70% (0.7) and 60% (0.6) respectively. If simply added the figure would be 130% (1.3). It conflicts with the starting proposition the figures being between 0 and 1.

Imagine a white surface area. Painting 70% of it in black leaves 30% white surface. Painting 60% of the remaining 30% in black will result in 88% black and 12% white surfaces. Painting 60% first in black and then painting 70% of the remaining 40% brings the same result of 88% black and 12% white. So does “(x)+(y)­-(xy)”. The overall vulnerability (attack surface) is 0.88 (88%) in this case..


"
コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

https://aitechtrend.com/quantum-computing-and-password-authentication/ · My latest article titled ‘Q ...

2年前 · 2 分の読書時間

There is actually a valid methodology that enable us to maximize the entropy of the secret credentia ...

2年前 · 2 分の読書時間

The quantum computer held in a bad guy’s hand is indeed a big threat. So is the artificial intellige ...

この職種に興味がある方はこちら

  • Queen's Berry(クインズベリー)

    アイリスト

    次の場所にあります: beBee S2 JP - 1週間前


    Queen's Berry(クインズベリー) 摂津市, 日本 正社員 アルバイト

    更新日: · 【業務内容】アイリストとしてのサロンワーク全般 · 【雇用形態】 正社員 アルバイト · 【勤務地】阪急摂津駅より徒歩2分/JR千里丘駅より7分のヘア&アイラッシュサロン · 【給与】【正社員】※中途採用の方経験により考慮させて頂きます。 · ■アイリスト (未経験) · ・月給200,000円~230,000円 · ■アイリスト(経験) · ・月給230,000円~280,000円 · 【アルバイト・パート】 · ・時給1,064円~1,500円 · 【試用期間中給与】 1ヶ月~2ヶ月 / 給与変動なし · 【PR】 · 【休日】■月8 ...


  • 市進学院 都賀教室 千葉市若葉区, 日本 パートタイム

    雇用形態 · アルバイト · 職種・指導形態 · 集団指導(10名以上) · グループ指導(10名以下) · 小学生か中学生の集団指導を担当します。 · 1クラスの人数は10名~15名程度です。 · 給与 · 1コマ60分2,400円〜4,000円 · ◇授業1コマ(60分) 2,400円~/授業外時給 1,200円~ · *小学生・中学生指導の兼任も相談可能です。 · *希望により個別指導の追加ができます。 · *昇給あり、正社員登用制度あり。 · 社会人の場合の日給例 · ●小学部+中学部で4コマ指導:授業4コマ×2,400円+時給1,200円×1. ...

  • 公開範囲1.等を含む求人情報を公開する

    介護職員/ツクイ青森石江※土日祝限定

    次の場所にあります: Talent JP C2 - 2日前


    公開範囲1.等を含む求人情報を公開する Aomori, 日本 パート

    仕事内容 · > · ・訪問介護サービスのコーディネート業務全般 · ・ケアプランに基づく訪問介護計画の作成 雇用形態 正社員 賃金 (手当等を含む ,250円〜280,250円 就業時間 交替制(シフト制 時30分〜17時30分 時00分〜09時00分 時00分〜06時00分 休日 他 週休二日制: 毎週 年間休日数: 116日 年齢 制限あり 〜59歳以下 求人番号 公開範囲 1.事業所名等を含む求人情報を公開する 学歴不問 書類選考なし 通勤手当あり 駅近(徒歩10分以内) ...