MSE News: Keep forgetting your PIN? Fingerprint recognition cards on the way

Options
'Shoppers will be able to use fingerprint authenticated bank cards to pay for shopping from next year
Read the full story:

Keep forgetting your PIN? Fingerprint recognition cards on the way

OfficialStamp.gif


Click reply below to discuss. If you haven’t already, join the forum to reply. If you aren’t sure how it all works, read our New to Forum? Intro Guide.
«1

Comments

  • Pincher
    Pincher Posts: 6,552 Forumite
    Combo Breaker First Post
    Options
    After all those movies with villains gouging out eyeballs and cutting off fingers for access? Count me out!
  • Biggles
    Biggles Posts: 8,209 Forumite
    Combo Breaker First Post
    Options
    The name of the Norwegian bank involved, Sparebanken, doesn't fill be with confidence.
  • ZTD
    ZTD Posts: 24,327 Forumite
    Options
    It's that old chestnut...

    Similar technology broken - http://www.besttechie.com/2013/09/23/iphone-5s-fingerprint-scanner-cracked/

    I like the quote: "It is plain stupid to use something that you can´t change and that you leave everywhere every day as a security token."
    "Follow the money!" - Deepthroat (AKA William Mark Felt Sr - Associate Director of the FBI)
    "We were born and raised in a summer haze." Adele 'Someone like you.'
    "Blowing your mind, 'cause you know what you'll find, when you're looking for things in the sky."
    OMD 'Julia's Song'
  • Paul_Herring
    Paul_Herring Posts: 7,481 Forumite
    Name Dropper Photogenic First Post First Anniversary
    Options
    What a terrible idea. Fingerprints should be used like usernames, not passwords!

    http://blog.dustinkirkland.com/2013/10/fingerprints-are-user-names-not.html
    The prevailing opinion from security professionals is that fingerprints are perhaps a good replacement for usernames. However, they're really not a good replacement for passwords. Consider your laptop... How many fingerprints of yours are there on your laptop right now? As such, it's about as secret as your username. You don't leave your password on your spacebar, or on your beer bottle :-)
    Conjugating the verb 'to be":
    -o I am humble -o You are attention seeking -o She is Nadine Dorries
  • Mirno
    Mirno Posts: 219 Forumite
    Options
    Two factor authentication is based on the idea that you're proven to be there, and proven to actively consent to the payment.
    Having the card proves you're there, and the PIN proves you're giving consent.
    Changing from a PIN to a finger print changes things so you prove you're there, and then the second factor proves you're there again.

    It seems like they've missed the point with this idea.
  • InsideInsurance
    Options
    Mirno wrote: »
    Two factor authentication is based on the idea that you're proven to be there, and proven to actively consent to the payment.
    Having the card proves you're there, and the PIN proves you're giving consent.
    Changing from a PIN to a finger print changes things so you prove you're there, and then the second factor proves you're there again.

    It seems like they've missed the point with this idea.

    How does it not prove you are consenting? Its presumably still a two step process as the Apple Pay finger print payment is? Present your card first and secondly present your thumb.

    Ok, there is a slightly higher chance of you presenting your card and subsequently "randomly" resting your thumb on the reader and it being read but thats a bit of a stretch.

    Obviously you could be coerced into putting your thumb on the reader but then you can coerced into entering your pin too.

    There are different technologies of how "finger print" reading can work from the norm of just looking at the print itself to actually reading the blood vessels under the skin. Without knowing exactly what is being used its hard to predict its security. With the Apple Pay it uses the existing TouchID technology which has already shown to be able to be bypassed with fake prints - though those that did bypass it did say in real life situations it would be fairly difficult to get a good enough clean print from the phone itself as its normally covered in them thus damaged.
  • Mandelbrot
    Mandelbrot Posts: 9,139 Forumite
    Rampant Recycler
    Options
    Why bother with the card?
    Just implant a chip into everyone's finger.
  • Paul_Herring
    Paul_Herring Posts: 7,481 Forumite
    Name Dropper Photogenic First Post First Anniversary
    Options
    Mandelbrot wrote: »
    Just implant a chip into everyone's finger.

    I do hope you're joking there, but on the off-chance you're not:

    No thank you. It's bad enough that the current government is proposing even more mass medicalistion of the general public, without corporations requiring/encouraging invasive procedures to implant RFID chips which can't be turned off, cloned easily, hijacked for governmental purposes etc.
    Conjugating the verb 'to be":
    -o I am humble -o You are attention seeking -o She is Nadine Dorries
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 343.5K Banking & Borrowing
  • 250.2K Reduce Debt & Boost Income
  • 449.9K Spending & Discounts
  • 235.7K Work, Benefits & Business
  • 608.7K Mortgages, Homes & Bills
  • 173.3K Life & Family
  • 248.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards