<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>Falsehoods programmers believe about&#8230; Biometrics &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Thu, 09 Jan 2025 12:30:55 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>Falsehoods programmers believe about&#8230; Biometrics &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[Falsehoods programmers believe about... Biometrics]]></title>
		<link>https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/</link>
					<comments>https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sat, 09 Jan 2021 12:53:53 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[falsehoods]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=37661</guid>

					<description><![CDATA[(For the new reader, there is a famous essay called Falsehoods Programmers Believe About Names. It has since spawned a long list of Falsehoods Programmers Believe About....)  Everyone has fingerprints!  The BBC has a grim tale of a family with a genetic mutation which means they have no fingerprints. It details the issues they have getting official ID.  In 2010, fingerprints became mandatory for…]]></description>
										<content:encoded><![CDATA[<p>(For the new reader, there is a famous essay called <a href="https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-believe-about-names/">Falsehoods Programmers Believe About Names</a>. It has since spawned a long list of <a href="https://github.com/kdeldycke/awesome-falsehood">Falsehoods Programmers Believe About...</a>.)</p>

<h2 id="everyone-has-fingerprints"><a href="https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/#everyone-has-fingerprints">Everyone has fingerprints!</a></h2>

<p>The BBC has a grim tale of a family with a genetic mutation which means they have no fingerprints. It details the issues they have getting official ID.</p>

<blockquote><p>In 2010, fingerprints became mandatory for passports and driver's licences. After several attempts, Amal was able to obtain a passport by showing a certificate from a medical board. He has never used it though, partly because he fears the problems he may face at the airport. And though riding a motorbike is essential to his farming work, he has never obtained a driving licence. "I paid the fee, passed the exam, but they did not issue a licence because I couldn't provide fingerprint," he said.
<a href="https://www.bbc.co.uk/news/world-asia-55301200">The family with no fingerprints</a></p></blockquote>

<p>Even if this genetic issue didn't exist, it should be obvious that not everyone has fingers, or hands. Some people are born without hands, some people lose them later in life.</p>

<p>Policy is about the edge-cases. It's easy to design something which works for the majority of people - the real challenge is how we deal with the fringes.</p>

<h2 id="everyone-has-a-unique-face-unique-dna"><a href="https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/#everyone-has-a-unique-face-unique-dna">Everyone has a unique face / unique DNA</a></h2>

<p>Ever heard of twins, dumbass?</p>

<p>OK, it is a <a href="https://www.newscientist.com/article/dn27411-police-can-now-tell-identical-twins-apart-just-melt-their-dna/">little bit more complicated than that</a>.</p>

<h2 id="it-is-easy-to-revoke-a-biometric-indicator"><a href="https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/#it-is-easy-to-revoke-a-biometric-indicator">It is easy to revoke a biometric indicator</a></h2>

<p>Even if you assumed that everyone has ten fingers - that means you can only change your ID 9 times. If you're using iris recognition, that's one change you're permitted before you have to grow new eyeballs.</p>

<h2 id="biometrics-cant-be-copied"><a href="https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/#biometrics-cant-be-copied">Biometrics can't be copied</a></h2>

<p>Back in 2002, <a href="https://cryptome.org/gummy.htm">Tsutomu Matsumoto copied fingerprints using Gummy Bears</a>.</p>

<p>Researchers can consistently <a href="https://www.wired.com/2012/07/reverse-engineering-iris-scans/">fool iris scanners</a></p>

<p><a href="https://www.researchgate.net/publication/262605045_Spoofing_Face_Recognition_With_3D_Masks">3D printed facemasks can defeat facial recognition systems</a>.</p>

<p>The thing about biometrics is that they are <em>not</em> secret. You leave your fingerprints <em>everywhere</em>. If a camera can read your face, it can copy your details.</p>

<h2 id="biometrics-cant-be-changed"><a href="https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/#biometrics-cant-be-changed">Biometrics can't be changed</a></h2>

<p>Will having a "nose job" stop your iPhone from recognising you? <a href="https://web.archive.org/web/20210121213213/https://www.solomonfacialplastic.com/rhinoplasty-toronto/will-facial-plastic-surgery-alter-the-facial-recognition-of-the-iphone-x/">Probably not</a>. But there are a range of surgical procedures which can be done.</p>

<p>People who have <a href="https://www.thelondontransgenderclinic.uk/facial-feminisation-london/">Facial Feminisation Surgery</a> can be <a href="https://web.archive.org/web/20210118224315/https://2pass.clinic/en/article/belgiums-safe-travels-how-about-traveling-before-and-after-ffs">given a letter from a doctor</a> to explain to border guards why a person's face may no longer match their biometrics.</p>

<p><a href="https://web.archive.org/web/20201203160904/https://twitter.com/sonniesedge/status/1334529593110372353"><img src="https://shkspr.mobi/blog/wp-content/uploads/2021/01/ffs-fs8.png" alt="Just remembered last nights dream about trying to go back to the UK but getting refused entry as my facial biometrics no longer matched.Thanks, brain.I bet the clinic would have warned you.Oh they did. I have formal letter stating that I might not pass biometrics anymore. 😂" width="642" height="516" class="aligncenter size-full wp-image-52135"></a></p>

<h2 id="what-are-they-good-for"><a href="https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/#what-are-they-good-for">What are they good for?</a></h2>

<p>Biometrics are not passwords. Nor are they a universal 2nd factor. Biometrics are, at best, usernames.</p>

<p>For the average user, it's probably fine to use your fingerprint or face to unlock your phone. If you think an enemy state is going to devote considerable resources to steal copies of your biometrics, consider changing to a different password mechanism.</p>

<p>Or, if you have kids.</p>

<blockquote class="social-embed" id="social-embed-1044058910196477960" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/Pushkarr" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRpQAAABXRUJQVlA4IIgAAACwBgCdASowADAAPrVOoUynJCMiKrVaqOAWiWcAzNAFz2TAprR15fBzVjmLyUfCXeASb3jZe+eDBArIquj+AAD+6pbiMTVBKhiP5HYQ3YcvGE0kxdmOtMp6kYvV8idHkhHKpo4BULcfNL4ozhppgcLmcXc7aXPrpw5P7B79KJxUMUMpesw8NAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Pushkar</p>@Pushkarr</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Friend's 5-year old daughter started unlocking his phone with his fingerprint while he's asleep so that she can play games. <br><br>He now sleeps with gloves on. <a href="https://twitter.com/hashtag/lifeisblackmirror">#lifeisblackmirror</a></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/Pushkarr/status/1044058910196477960"><span aria-label="24 likes" class="social-embed-meta">❤️ 24</span><span aria-label="3 replies" class="social-embed-meta">💬 3</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2018-09-24T03:00:16.000Z" itemprop="datePublished">03:00 - Mon 24 September 2018</time></a></footer></blockquote>

<p>Or if you're cheating on your spouse.</p>

<blockquote><p>A Qatar Airways pilot was forced to make an emergency landing after a passenger found out her husband was cheating on her and had a violent reaction in midair.
The woman reportedly used her sleeping husband's finger to unlock his phone and discovered his cheating ways.
<a href="https://abc7ny.com/society/plane-forced-to-land-when-passenger-learns-of-husbands-cheating/2617560/">Eyewitness News</a></p></blockquote>

<p>In a safe-ish environment, biometrics are a good convenience mechanism. If your phone is snatched by an opportunistic thief, they're unlikely to have the means to spoof your ID.</p>

<p>But they are not a perfect security measure.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=37661&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2021/01/falsehoods-programmers-believe-about-biometrics/feed/</wfw:commentRss>
			<slash:comments>17</slash:comments>
		
		
			</item>
	</channel>
</rss>
