FuckyWucky,

contactless cards are already a thing. why why why

TiredSpider,
@TiredSpider@slrpnk.net avatar

All this trouble and they didn’t even make the scanner shaped like a hand so you can high five it. Waste of potential.

Kolanaki,
@Kolanaki@yiffit.net avatar

It won’t be long now until we have the eye scanner things from Minority Report and the only way to protect your privacy is to become blind

ricecake,

don’t you want some WLD???

Eyeuhnluuung,

Saw this at Whole Foods the other day for the first time and commented to the cashier that it was kind of creepy and her response was “I know right”.

ArmokGoB,

These types of things never work for me because my skin changes so much 💀

01189998819991197253,
@01189998819991197253@infosec.pub avatar

It measures your blood flow and veins using thermal and maybe infrared (?), so your exterior skin doesn’t come into play.

Stabbywithsocks1,

Body parts aren’t secure. They’re removable.

Obi,
@Obi@sopuli.xyz avatar

And probably imitable, if not, soon enough.

Kolanaki,
@Kolanaki@yiffit.net avatar

Stop telling people their body is insecure. Everyone is beautiful!

user224,

Except me.

Lucidlethargy,

I don’t understand what this solves… We can use a card faster than this (a mere tap), and if we forget our card, it’s programmed into our phones and even our watches as a backup.

float,

Its meant to save you a step. Before at whole foods you had to get out your phone, open the amazon app, scan your prime QR code, then get a card and pay. This just does all that with an enrolled palm.

I still don’t trust it. I laughed at it when I saw it and even the clerk admitted it was dumb.

JoeBidet,
@JoeBidet@lemmy.ml avatar

Oh no! I trashed my faithful Palm Pilot ™ years ago :/

01189998819991197253,
@01189998819991197253@infosec.pub avatar

I trashed the Pilot. But I still have the Pre and Pixi haha

Well, one of them has Android now…

EffortlessEffluvium,

Drop the Pilot. Try my balloon.

Rollio,

Whelp, it was only a matter time.

01189998819991197253,
@01189998819991197253@infosec.pub avatar

And bad legislation.

Mojojojo1993,

I don’t get the issue with it ? Why wouldn’t fingerprint be the best way to pay for stuff ?

Kaped,

Make this tech viable, let the companies store your finger prints for 6 gorillion years. Companies get hacked.

Yeah bro go ahead

Mojojojo1993,

So nothing is safe. Therefore???!!

nimbus5000,
01189998819991197253,
@01189998819991197253@infosec.pub avatar

For the same reason this isn’t a good idea. Privacy aside, when your biometrics get leaked (and they will), you’ll have no recourse, because biometrics are literally a part of your body and you can’t change them.

Mojojojo1993,

How do biometrics get leaked ? Can they 3d print my finger ? What difference does it make to all my dsta getting sold on the daily ? I don’t see how it changes things

01189998819991197253,
@01189998819991197253@infosec.pub avatar

They don’t need to 3D print anything, only to “side load” the hash (it’s more complex than that, but that’s the gist). If your ID is tied to your finances, and it gets leaked, you can’t change your ID. Your finger/palmprint is always your finger/palmprint.

Mojojojo1993,

Right. But can’t they do that anyway? Your ID is linked to your finances. You get people stealing IDs all day everyday.

Family Guy did an episode on it.

If I’ve got your records you I’d birth certificate your job numbers your state details. Address phone emails passport passwords. I’m you. Except I have my biometrics.

Biometrics cannot be forcibly taken. I can’t rock up to the bank manager with a severed finger. Yet I can take out a loan in your name without the fingerprint.

For fuck sake our security relies on signature. A badly written name.

raubarno,

Smash it!

01189998819991197253,
@01189998819991197253@infosec.pub avatar

I’d rather not go to prison. If I were a billionaire, I could probably avoid prison with a good/sleazy lawyer, but, as it stands, I cannot.

Jmr,

LG did this on a phone. It didn’t really work, at all

01189998819991197253,
@01189998819991197253@infosec.pub avatar

Theirs was camera. This one is camera and thermal. Creepypasta for sure!

Stoneykins,

I still think the idea of tech implants are cool but I’ve also reached the point where I wouldn’t get one unless I learned to build it myself and was in charge of every single aspect of it.

Considering I lack degrees in medicine and computer science, I don’t think I’ll have them done anytime soon lol

MonkderZweite,

You don’t need degrees to hack stuff.

sin_free_for_00_days,

I’d want to get some type of learning before I started to cut myself open.

MonkderZweite,

There’s really a body hacking community!

frustbox,

One scar away from losing access to your ability to pay …

Biometrics can not really be changed. Except maybe through time or trauma (i.e. age or injury). They can be used to uniquely(?) identify a person - except maybe twins - at the expense of anonymity, which has it’s own set of problems.

But because they can not easily be changed they’re a terrible security feature. Once they leak, they’re unusable and you’re hosed. You can’t issue a new palm print for your bank account like you could a new chip card and password.

Also, just because you waved your hand over a scanner does not mean that you approve and consent of the transaction. With tap to pay there were ideas of mobile point of sales devices just tapping on peoples backpacks in a crowded area. You don’t even keep your biometrics markers in your pocket, they’re just out in the open for anyone with a camera. This may be bordering on paranoia, but a few years back (2014) German hackers from Chaos Computer Club took iris scans from Angela Merkel (then Chancellor of Germany) and finger prints of Ursula von der Leyen (then Minister of defense) using nothing but press fotos. Cameras have only gotten better.

TL;DR: Biometrics can be used for identification but should never be used for authorisation.

Blackmist,

Biometrics also aren’t great and uniqueness. At least where computers are concerned.

Recently we had one of our customers install fingerprint readers on their points of sale, the idea being any staff member can log in just by touching the pad. Even with only a few hundred staff registered, you get people logging in as each other.

AWistfulNihilist,

I worked with Kronos, had their top tier biometrics in a 1,000+ employee company.

  1. The data is only as good as the person loading the data.
  2. Some people don’t have good fingerprints.

It was bad enough that of you had a person with a bad fingerprint, Kronos would just take ANY input. It would even tell you if a persons fingerprint wasn’t good enough. It happened fucking constantly.

So either it’s so good you can’t escape it, it is so bad you can’t use it to identify anyone uniquely. It’s literally either a threat or an inconvenience.

TWeaK,

Paying with your phone works on the presumption that your phone is locked and you accept responsibility for ensuring your phone wasn’t breached. It uses contactless technology, but it’s still effectively chip and pin as far as your bank is concerned.

Meanwhile, paying with a contactless card is processed as “cardholder not present” where the seller assumes de facto liability and must prove otherwise. Contactless payments were never a new type of card processing, it was a new method but is categorised the same as when mail/phone ordering from a catalogue. The same with online purchases. They were always a step below card & signature or chip & pin. Paying with your phone is the same as chip & pin though, where the onus is on you to ensure the transaction is secure.

Paying with your hand has all sorts of issues making it impractical. You would definitely need an additional confirmation eg PIN, but claiming that your hand is as secure as a traditional card doesn’t lend well to pinning the liability on you. So banks are unlikely to use it.

phase,
@phase@lemmy.8th.world avatar

Someone took the novel “The Java Script Café” from “Stealing the network: How to own an identity” (page 141) and made a business model for it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacy@lemmy.ml
  • ngwrru68w68
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • kavyap
  • cubers
  • JUstTest
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • megavids
  • lostlight
  • All magazines