Showing posts with label biometrics. Show all posts
Showing posts with label biometrics. Show all posts

2025-06-06

From slippers to biometrics

Image from Pixabay

Some nursing homes use facial recognition to keep elderly people with dementia inside, the Dutch tv news reported a few months ago. Because I am always on when it comes to possible topics for this blog, I made of note. And now I finally get around to explaining why that report caught my attention.

Facial recognition is a form of biometrics, just like a fingerprint scan or voice recognition. Biometrics means something like 'measuring biological characteristics'. The technology is based on the fact that every person has a number of unique characteristics. Based on these, you can identify someone. And to reassure you: biometrics doesn’t store your complete fingerprint or a photo of your face. Instead, a number of specific characteristics are recorded, such as the distance between your eyes and other proportions. When checking your access rights, a camera or scanner is used to check whether these characteristics are in its database. That is why the fingerprint scan on your phone suddenly works less well if you have been doing a lot of DIY: your finger is too rough to match.

So we use biometrics to gain access to something. Not to be denied access. But that is exactly what those nursing homes do. The front door is always open, but if the camera sees someone approaching who is not allowed outside because it is not safe for them, the door is locked. The nursing homes love it: "Otherwise we have to keep the doors closed for all residents. Now we turn that around: the doors are open."

And what if a smart resident sticks on a fake moustache, I wonder. Or puts on sunglasses. There is a good chance that he will not be recognized and will happily walk outside. Now I don't know if smart and demented can go together, but yes, I am obliged to my position to assume that things can go wrong. Edward Murphy is my role model (you know, the one with that law: everything that can go wrong, will go wrong).

What we see there is biometrics turned upside down. Why is biometrics not applied in the usual way? Everyone who is allowed to go outside is in the system. If he or she is recognized, the door swings open. If someone comes shuffling along who is not allowed to go outside and therefore is not in the system, the door stays closed. You have to be very clever to fool the system.

Before those nursing homes switched to biometrics, they used wristbands or sensors in their clients' slippers. Even then, they worked with open doors, which were locked only for some. But of course, you could easily work around that: take off your slippers and voila, you were outside. And a bit of fiddling with the wristband also turned out to work. Incidentally, the switch to biometrics has a double face: on the one hand, a band that is visible to everyone has a stigmatizing effect, on the other hand, the barely visible biometrics makes it difficult to enter an official protest – a right that also dementia patients have.

A nursing home is not a prison. Only residents who, due to their condition, are not safe to go outside alone, are kept inside – with the permission of themselves or their legal representative. Visitors are welcome and must be able to walk in and out freely. Open doors give a relaxed feeling, and thus contribute to a dignified existence. From that perspective, I understand the reverse approach, and I can imagine that there will not be that many clients who know how to hack the system. For most other applications, however, I like to stick to biometrics as they are intended.

 

And in the big bad world…

2024-11-22

Look at me

Image from Pixabay

How do you unlock your mobile, tablet or laptop? With a password, a pin code, your fingerprint or maybe even with your face? There are many possibilities and you could therefore sooner of later the question whether facial recognition is safe had to pop up. A few years ago my answer was: I wouldn't use it on business devices, privately I don't think it would be a problem - at least, if you have a somewhat normal life. But is that statement true? It’s time for some research, so that you don't have to dive into it yourself.

Facial recognition is a form of biometric identification, which compares unique features of your body to a stored pattern. Other forms of biometrics include fingerprint and palm scans, iris scans and voice recognition. These technologies work differently than the good old fingerprints you know from the police, where inked fingers are used to make a print on paper that is then compared to the prints left by the burglar on the window. Instead, the scan is translated into a biometric profile, which looks at things like the distance between your eyes, the distance between your nose and mouth, the shape of your cheekbones and the dimensions of your face. More advanced systems make a 3D scan and use infrared images, which makes the profile more accurate. It gets even better when the system is able to determine whether the camera is looking at a living person. When unlocking, the detected facial features are compared to the stored profile. So it’s not like photos from then and now are being compared with each other.

I read a bunch of articles on this topic this morning, and the answer to the question whether facial recognition is a safe way to unlock your device seems to be: it depends on the device. Apple's FaceID uses the more advanced techniques I described above from the iPhone X onwards and is therefore considered safe. Android devices are a different story, as the Dutch Consumers' Association discovered. In 2023, they repeated their research from four years earlier and had to conclude that little had changed: they were still able to fool 43% of the tested devices with a photo. This mainly concerns devices at the low end and in the middle of the price range, although a few more expensive devices also fell through the cracks. Almost all Samsung devices performed well.

Hello is available on Windows PCs . It uses infrared cameras to make a 3D scan of your face. The system can also check if it is looking at a living person, making it difficult to fool it with a photo. If your computer does not have the necessary cameras, facial recognition is not available.

Of course I put it to the test and let my private phone look at a photo on my screen. And then I quickly disabled facial recognition on that device… I will continue to use the fingerprint scanner, because it is more secure than a PIN code which can be copied. And while you can often fool facial recognition with a photo, that is much more difficult with a fingerprint. Some Android devices still have pattern recognition, where you draw a pattern with your finger on a grid of nine points. This option is almost unanimously discouraged, because someone looking over your shoulder can easily remember your pattern. Moreover, traces of grease on the screen also reveal a lot.

During the research for this blog I noticed something. I searched for “facial recognition safe” in both English and Dutch. The Dutch articles gave a good answer to my question, while the English articles mainly focused on the privacy aspect of facial recognition: for what purposes can this technology be abused? Privacy plays a role in particular when biometric data is stored in databases. And again we see that Chinese person crossing the road on a red light and receiving a fine in the mail a few days later. But criminals are also interested in technology that allows them to gather information about someone based on a (secretly taken) photo. And finally, quite a few people fear that the police can unlock their phone very easily – you can’t turn off your face (just like fingerprints, by the way). But you can refuse to give up your PIN code.

There will be no Security (b)log next week.

 

And in the big bad world…

 

 

2022-10-07

The history of keys

 

Image from Pixabay

Your bicycle, your car and your house have one thing in common: they have a lock. And all those locks come with keys. Locks have a long history – they are said to have been around for over six thousand years. Over the centuries, all those locks served the same purpose: to let in those who are allowed in, and to keep everyone else out.

There have always been people who still wanted to go somewhere they weren't allowed in. Most shrug and think “too bad,” but some are really trying to get in. We call those people burglars. They have a whole range of options for breaking down the barrier that has been raised, such as lock picking tools (which can be used to fumble with cylinder locks), the Polish key (used by bicycle thieves) and the time-honoured crowbar. It should be noted that the latter is not used to open the lock, but to work around it.

And then the computer was invented. Soon – in 1961 – it was thought that it also needed a lock. I myself have used PCs that had a physical lock, but the password is still the most common mechanism. The password itself was not new; the ancient Romans used it already, and I remember from old wild west movies that anyone who wanted to enter the fortress had to say the password at the gate.

In the good old days we had one password. You could easily remember that, if only because there were no requirements yet that it had to meet. In modern times, we all have dozens of accounts, at work and in our private life, and their passwords have to meet some of the most horrific requirements, which are different everywhere. For example, last night I found out that my bank does require a special character, but that it should not be a circumflex accent (^). And while I can think of a reason for that, I immediately wonder why using this character is fine elsewhere.

I've written it before: passwords have had their day. Not only because we are tired of it, but mainly because they lose their security value. I'd venture to say that anyone who doesn't use a password manager either writes down their passwords somewhere or uses weak passwords (which includes using the same password in several places). Writing that down doesn't have to be so bad, if you approach it a bit smartly. A notebook with the title “All My Passwords,” as seen on TV nine years ago by Ellen DeGeneres, is not a good idea.

Biometrics is a nice alternative for some applications. You can unlock your phone smoothly with your fingerprint or with facial recognition. Even firearms are equipped with it (although such a smart gun has never been sold, Wikipedia says). There are also more robust – and therefore more expensive – biometric systems that scan your iris, for example, or your palm. The latter technology scans, in addition to the shape of your hand, the pattern of the veins in the hand. Biometrics can literally go deep.

An alternative to logging in to websites is the FIDO standard (Fast Identity Online). When using FIDO, you register once at a website. You can then log in using your mobile device or your computer, possibly using a FIDO USB key, which you only need to touch to log in. But despite roaring texts on the FIDO Alliance website (“FIDO is widespread and growing fast!”), I've never seen it on a website. Major players such as Google, Facebook and Dropbox are connected, but apparently not for Dutch users.

Change is difficult, as it turns out. But one day there will be people who will no longer know what a password is, just as there are already millions of people walking around who have not experienced the time without computers and smartphones, or people who do not know what a floppy disk is. Until then: use a password manager. And wherever possible, activate two/multi-factor authentication (2FA/MFA, also known as two-step verification).

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

Getting hosed

Photo: author Summer is my favourite time of year to gather stories for this blog. You travel to other countries and get a taste of other cu...