Hitoshi Kokumai

4年前 · 3 分の読書時間 · ~100 ·

ブログ作成
>
ブログ Hitoshi
>
Quick Money from False Sense of Security – Ethically Dubious Business Practice

Quick Money from False Sense of Security – Ethically Dubious Business Practice

93

LE


Summary: The password is insufficient, but not harmful. Biometrics is harmful, and not sufficient. 


Attempting to make quick money by spreading a false sense of security is ethically dubious and practically suicidal.


- Is the password weaker than biometrics?

It is not feasible to compare a biometrics on its own, which is probabilistic, with a password on its own, which is deterministic. And, in reality, how can we select the test samples to compare from among numerous possible combinations, say, between the two extremes of ‘the securest password vs the least accurate biometrics’ and ‘the poorest password vs the most accurate biometrics’? If we hear someone speaking that biometrics is more secure than passwords, we should doubt their integrity.

Spoofing raises FA/FM rates

Counter-spoofing raises FR/FNM ratesOn the other hand, it is feasible and logically correct to compare (1) a password with (2) a biometrics with the same password as a fallback measure against false rejection/non-match of the biometrics. Logic leads us to conclude that (2) is inevitably weaker than (1) as outlined in this video - https://youtu.be/wuhB5vxKYlg


Password-Dependent Biomtrics Displaces the Password
just as Mother-Dependent Baby Displaces its Mother
Two Authenticators Deployed in "Multi-Entrance’
Have the Same Security Effect as ‘Multi-Layer’ Deployment

In Their World!As forthe perplexing security effect of liveness detection now being touted as a countermeasure against biometrics spoofing, this article might help to unravel the conundrum - "Spoofing and Liveness-Detection of Biometrics"


- Is Biometrics-only Authentication achievable?

If taken narrowly and literally, 'biometrics-only authentication' could bring such tragedies as reported in India and examined in this article - "Unnecessary Deaths Presumably Brought ByBiometrics Misunderstood"


95b1c182.pngIt also brings a 1984-like Dystopia. Democracy is dead where our identity is authenticated without having our will/volition confirmed.




If taken broadly and ambiguously as 'biometrics-only authentication that is backed up by a default/fallback password/pincode', it only brings security down to the level lower than a password/pincode-only authentication as analyzed in the above video and in this article - "Early models of smartphones were safer than newer models - How come?"

https://www.linkedin.com/pulse/early-models-smartphones-were-safer-than-newer-how-come-kokumai

- What can we gain from bringing in biometrics into multi-factor authentication?

A password and a physical token can be used on its own and also used as a second layer in 'multi-layer' deployment, whereas biometrics cannot be used on its own but must always be used with another authenticator in 'multi-entrance' deployment.

This means that biometrics cannot be a factor of the true multi-factor authentication that is supposed to be deployed in a security-enhancing 'multi-layer' method. Biometrics-involved multi-factor authentications would inevitably bring down the security that could otherwise be maintained.

6c47f96b.pngWe ought to be very careful about what security professionals tell us. Many of them are ignorant of or indifferent to the opposite security effects of two authenticators used in 'multi-layer' and 'multi-entrance' deployments – "Quantitative Examination of Multiple Authenticator Deployment"

We often hear some professionals say that we should not make a ruling on biometrics by looking at its current performance but we should take it into account that biometrics technologies is improving.

What would you say if you hear pharmaceutical companies stating "We recommend this drug for your healthier life. At present this drug is harmful to your health but we expect that it will evolve to become really effective sometime in the future. So please take this drug now"?

- Haven’t the biometrics promoters building a huge sandcastle?

Biometrics is said to be growing to be a gigantic business as reported here -

https://www.biometricupdate.com/201910/biometrics-research-notes-banking-systems-asian-retail-and-smart-tickets

It reads "Biometrics systems will generate over $65B by 2024, according to new research, with growth in different areas for different regions. Signs are also positive for the industry in banking and securities, Asian retail, and smart ticketing, with significant investments anticipated in each."

The figure of $65 billion is really mind-boggling even if it is bloated 10 times! Then, it should be extremely exciting to imagine what will happen when the myths of biometrics as examined above get debunked in front of the public and the gigantic castle of biometrics proves to have actually been a sandcastle. We might well be watching a huge vacuum generated where there was the gigantic sandcastle.

- This false sense of security has been benefiting criminals, hasn’t it?

As examined above, biometrics has continuously contributed to providing a favorable environment to criminals, not to citizens, for more than a decade and the public has been misled to believe that biometrics has provided better security for citizens. This false sense of security might well keep causing huge damages on our societal life for many more years unless we speak out articulately right now.


6f8ad7cf.png

The password is insufficient, but not harmful. Biometrics is harmful, and not sufficient. Attempting to make quick money by spreading a false sense of security is ethically dubious and practically suicidal.


< Related Articles >

Biometrics and Me

 Publication on EDPACS of Taylor & Francis


#identity #authentication #password #security #safety #biometrics  #ethic #privacy #civilrights #democracy


コメント

Debesh Choudhury

4年前 #1

Agree Hitoshi Kokumai . False sense of security is prevalent in the security community. Some group of people are utilizing the hype to promote and sell false security systems, such as biometrics, which is harmful and insufficient.

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

Today's topic is this report - “How blockchain technology can create secure digital identities” · h ...

2年前 · 2 分の読書時間

Our password headache may well be the consequence of these dual causes - · ‘Use of Impracticable Pas ...

2年前 · 2 分の読書時間

The quantum computer held in a bad guy’s hand is indeed a big threat. So is the artificial intellige ...

関連プロフェッショナル

この職種に興味がある方はこちら

  • 合同会社 アリス

    訪問介護ヘルパー

    次の場所にあります: Whatjobs JP C2 - 2日前


    合同会社 アリス Osaka, 日本

    **ハローワーク求人番号**: · **受付年月日**: · - 2024年2月20日 · **紹介期限日**: · - 2024年4月30日 · **受理安定所**: · - 大阪東公共職業安定所 · **求人区分**: · - パート · **オンライン自主応募の受付**: · - 不可 · **産業分類**: · - 老人福祉・介護事業 · **トライアル雇用併用の希望**: · - 希望しない · 求人事業所 · **事業所番号**: · **事業所名**: · - ゴウドウガイシャ アリス · - 合同会社 アリス · **所在地**: · - ...

  • MASTER key株式会社

    保安検査員

    次の場所にあります: Whatjobs JP C2 - 12時間前


    MASTER key株式会社 新宿区, 日本

    【職種名】 · 未経験OK【寮完備正社員】空港検査業務/手荷物検査スタッフ · **仕事内容**: · ~夢の空港でのお仕事~ · 20代女性活躍中 · 月3万円のホテル並みの新築独身寮付き · 空港利用客の急増により、急募いたします。 · 【アピールポイント】 · ・大手JALグループで働くチャンス空港でお仕事したい方必見 · ・面接はリモート面談で基本1回のみ(内定率驚異の80%超え) · ・コロナが回復し、事業拡大に向けて積極採用中 · ・昇給、昇格、賞与あり長期でキャリアアップを目指せる環境 · 【お仕事内容】 · ・東京国際空港、那覇空港、新千 ...

  • 株式会社タカスズ湘南

    ドライバー/配達/倉庫管理

    次の場所にあります: Whatjobs JP C2 - 4日前


    株式会社タカスズ湘南 Yokohama, 日本

    【職種】 · (正)12ドライバー・運転手、配達・配送・宅配便、倉庫管理・入出荷 · 【雇用形態】 · 正社員 · 【仕事内容】 · ペンギンマークのホシザキ製厨房機器、 · 見たことがありますか? · あのような厨房機器の搬入出と設置をお任せします · ※2tトラックの運転もお願いします。 · 最初は普通免許だけでOK · 業務用厨房機器の搬入出 · 搬入出ルートの打ち合わせ · 搬入出ルートの養成 · 厨房機 · - の搬入・設置 · ・多くても1日4つの現場 · ・1現場あたり2時間ほど · ・冷蔵庫 · ・ビールサーバー · ・食器洗浄機 · ・ ...