Skip to main content

The Problem with Biometrics


Biometrics is touted as the solution to all identity problems we have. It is like Manna from heaven that would solve all the problems associated with user IDs and passwords and tokens and make everyone so unique because of the fact that they have finger prints, retinas, face geometry, hand geometry, wrinkles on the face and whichever set of controls required to ensure that the person identifying himself is him/her.

However, this identity is under pressure from a set of technologies, that helps in recording it in such minute details that with advances in technology these could be replicated without much ado over time. Lets look at Cameras with super sensitive irises. These Cameras with high resolution sensors to the tune of 50 Mega Pixels announced recently by Canon and other Japanese Camera Leaders, makes you wonder, if your iris is protected at all. Can somebody take a shot of your iris or a shot of your fingers, make a copy of it and run away with your identity. It is a possibility and it is an area of concern to many of the developers as well as those who need to protect devices and physical protection using biometric devices.
The two pictures in this blog is to show the detail that you can expect from a simple camera, would not say who the iris belongs to for obvious reasons (Could be my Cat , Dog or my Hamster) and I also tried the same with the patterns in my fingers.These pictures are to show how much detail could be captured in a photograph.
                  
We are seeing three dimensional photographs, 3d scanners that are available in the open source domain as well
This also leads to the question about using Biometrics by the Government, Is the Government ready to protect this information, Do they need to collect this information at all, Is there not a possibility that your identity may get misused by a rogue government that have an agenda against elimination of dissent. What if they end up raking up evidence against you, the fact being that they have access to your information. This being unique, how can you take a different identity. Are we going to see a new trend of Cosmetic Surgeons, who would for a fee help you change your biometric identities. Liposuction, Tummy Tuck, Breast Augmentation and ofcourse Retina Change, Hand Geometry Swap, Finger Print Change services. We are moving into a new world of uncertainties.


It is of  major concern that you are scanned at entry into the United States, Retina Scan in some of the Gulf Countries and if the other countries start doing the same, For example any American from the USA (To be fair to Canadians and Mexicans and other countries of North America and South America) get scanned on entry into say Russia or China. Is there a guarantee that this information is secure? Would you trust a foreign Government with your only data that is indelible? Would the Chinese, Russians or Indians have trust that the data collected by the US immigration department will not be misused? You never know how this information can be misused? Every Government in this wide world may start scanning International travelers as a retaliatory measure and soon this data would become valuable.


In Information Security we say that the chain is as strong as the weakest link? Imagine a time when Biometrics are the only way to authenticate against systems. A rogue country may use this data to break into the systems of the attacked country. I will use the information I have collected to breach into the systems. It is pretty scary thinking about losing your identity. I have already lost it a few countries that already has my Iris Scans, Full hand geometry and scan of every finger in my body.

If possible under all circumstances, people should resist giving biometrics and biometrics being used as the only way to identify somebody. Would we not be implicated in crimes that we never performed because a mafia gang has a large set of stolen identities to perpetuate their crimes. Well well , Welcome to the new world!!!

Comments

Popular posts from this blog

Malware Damage - It is real and you need to be ready ...

  Malware, short for "malicious software," is any software intentionally designed to cause harm to computer systems, networks, or devices. Malware can take many forms, including viruses, trojan horses, worms, ransomware, spyware, and adware, among others. The dangers of malware are numerous, and it is crucial to protect yourself from malware to avoid serious consequences, such as: Data theft: Malware can be designed to steal personal information, such as bank account details, social security numbers, and login credentials. Once this information is stolen, it can be used for identity theft, financial fraud, and other malicious activities. System damage: Some malware can damage your computer system, causing it to crash or malfunction. This can result in lost data, system downtime, and costly repairs. Financial loss: Malware can also be used to extort money from victims. For example, ransomware can lock down a victim's computer and demand payment in exchange for the decrypti...

Is Cybersecurity for you .. A primer of Questions and probable answers!!! Are you ready!!

With the advent of AI, do you have the wherewithal to handle the new threats? As AI technology advances, so do the potential threats it poses. From deepfake videos to intelligent malware, the use of AI in cyber attacks is a growing concern. Are you equipped to handle these new threats? It's time to prepare yourself for the future of cyber security by staying up-to-date on the latest AI developments and learning how to defend against AI-powered attacks. Are you equipped to face the future of cyber security? The future of cyber security is rapidly evolving, and staying ahead of the curve is crucial to keep your data and systems secure. With advancements in technology and the increasing sophistication of cyber criminals, it's more important than ever to be equipped with the right tools, knowledge, and skills to protect yourself and your organization. Are you ready to face the challenges of the future of cyber security? Have you worked on solving issues in a cyber range? A cyber ra...

Are you a CISO in the making? What it takes to become one?

  A good CISO is a strategic leader who can articulate the business value of cybersecurity and build a strong security program that aligns with the organization's overall goals. They have a deep understanding of the latest cybersecurity threats and technologies, and they are able to translate this knowledge into actionable insights that can be used to protect the organization. A good CISO also has strong communication and interpersonal skills. They are able to build relationships with key stakeholders, including the board of directors, the CEO, and other senior executives. They are also able to communicate effectively with employees at all levels of the organization, and they are able to build a culture of security within the organization. In terms of technical skills, a good CISO should have a strong understanding of the following areas: Network security: This includes knowledge of firewalls, intrusion detection systems, and other network security technologies. Application se...