Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>aren't PINs weaker security-wise than biometric logins?

Depends on how you look at it. I'll focus on fingerprint here.

Sure, there are far more possible fingerprint features that can be identified for accept/decline decision "Does this match a registered fingerprint", than 1,0000 PIN combinations (4 digits).

But if the fingerprint reader is too lax in matching, it's possibly worse.

If you can crash the fingerprint reader system, which then accepts all future patterns, that's worse.

If you can trick the system into revealing all the biometric data it's collected, and then replay it directly without using the sensor using their debugging interface, that's worse.

That's not to say defaulting to PINs is or isn't the "least bad" option. Just that it's more complicated than the question makes it look.

There are other issues around your question in general that aren't particularly relevant in context:

You can't reasonably change or revoke your PIN.

Your device is likely covered in your fingerprints.



> You can't reasonably change or revoke your PIN.

i can, have, and will

> Your device is likely covered in your fingerprints.

true, fingerprints are not (a) secret


Sorry, that was a typing error, you obviously can do that with a PIN. Which was the point I was trying to make.

I meant you can't reasonably change or revoke your fingerprints!

Changing your actual fingerprints, while possible, is usually painful and done accidentally.

(The best you can do is change from which fingers the prints will accepted. And at best, you only have a couple of handfuls of options there.)


Thanks for the explanation. I really didn't understand it but figured there is something I was missing here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: