Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Fingerprint scan, retina scan, faceID etc.

Not secure at all. You can be coerced physically to unlock something private/secure. Security should always be a combination of something you know and something you have (2FA).

Additionally, requiring a central authority to manage security is just _asking_ for trouble. Passwords work because of how de-centralized it is. Biometrics and physical-only tokens will fail the minute people realize they can just steal that data and use it to unlock everything centrally.

What we need are better tools to manage passwords in a more transparent way.



With physical coercion, all bets are off. The goal is to survive. You probably want a distress password perhaps.


The police can coerce you using biometrics. They can't torture you for what you know.


Ah ok, so I take it by coerced physically you mean coerced by a warrant/subpoena to physically unlock something?


Or by a bully, girlfriend, wife, etc.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: