496
submitted 9 months ago by misk@sopuli.xyz to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] Luci@lemmy.ca 36 points 9 months ago* (last edited 9 months ago)

Stop using biometrics for authentication!!!!!

Edit: lots of opinions below. Biometrics are a username, a thing you are. Finger printed can be taken from your laptop with a little powder and masking tape.

Use an authentacator app or security key kids!!

[-] 0xD@infosec.pub 6 points 9 months ago* (last edited 9 months ago)

A username is not something "you are", it's something "you know". Biometrics are not nearly the same as usernames.

[-] Luci@lemmy.ca 1 points 9 months ago

A username is something you are. It's you! You are 0xD.
A password is something you know. A security key is something you have.

When we interview security analysts you don't get past the first round if you disagree.

[-] feddylemmy@lemmy.world 8 points 9 months ago

If your interview involves telling me a username is "something you are" rather than "something you know", I'm running away from that job as fast as I can.

[-] Luci@lemmy.ca -1 points 9 months ago

Other people know your username.

How hard is this?

[-] Blueteamsecguy@infosec.pub 2 points 9 months ago

I guarantee you I know thousands of people's passwords as well, I just don't know the username associated.

[-] sirfancy@lemmy.world 0 points 9 months ago

By this same logic, other people could know your fingerprint since it's "something you are". No, other people cannot know your fingerprint. It's a complex mathematical equation to a computer. This is such a terrible take.

Source: CASP+ certified.

load more comments (3 replies)
load more comments (3 replies)
load more comments (35 replies)
this post was submitted on 22 Nov 2023
496 points (98.6% liked)

Technology

57944 readers
3101 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS