Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In case od data leak - you cannot change your face, or fingerprints. You can change passwords though.


Good news that you can’t bring someone’s face to google and ask for access to their account…

Please don’t insert commentary when it’s clear you don’t know what you’re talking about


Thieves can steal a car using tech magic. That is also true about access to accounts. That contradicts your comment. Biometrics, if stolen, can be used to access any of accounts if one obtains knowledge about how to use it for hacking.

Your comment violates HN guidelines, but as guideline says I assume good faith therefore I have provided details about how you're incorrect on that one.


A passkey does not contain and is not derived from biometric data, so one cannot login to an account using biometric data alone.

If one wanted to use biometric data to access a Google Account secured with a passkey, one would:

1. Need to find a device with that passkey on it (or an account like iCloud Keychain or 1Password that contains the synced passkey). Biometric data could be used to unlock the iPhone, in theory. I'm not aware of this being done in practice.

2. Then unlock that passkey. On iOS, biometric data could be used to perform this step, just as accessing the iPhone in step 1.

If you hold the power/volume buttons or do a Find My lock, it disables biometric auth on an iPhone. I assume there are equivalent tools on Android.

So, if I lose my iPhone and someone also scanned my face, they could login to my Google account by generating a face accurate enough to fool Face ID, and only if they did it before I marked the phone as lost.


It does not have to be a thug who makes your picture.

Titanic has crashed. Microsoft has been hacked. There are no solutions that do not contain bugs. There are no drivers for sensors that cannot be hacked.

Sure hacking a device is difficult, sure. Maybe nearly impossible, but I doubt it. All software has bugs. Some even backdoors. Some data are centralized and kept on big tech cloud storage which is a honey pot for hackers. Once hacker has biometrics data on your phone captured, it could be used. Not only to obtain your passkeys, but outside of your phone.

A simple google search confirms that. There was a biometric data breach. Sure this might not be the best result, but I spend 2 seconds searching for it. Quite generic article, but I think it is sufficient.

https://www.secureworld.io/industry-news/biometric-data-brea...

Quotes

"Facial recognition and fingerprint information cannot be changed. Once they are stolen, it can't be undone."

"Putting all the data found in the leak together, criminals of all kinds could use this information for varied illegal and dangerous activities."

Keychain, iCloud, 1Password... These are just details.


Yes, I understand that biometric data can be acquired… The biometric data does not alone get you into an account with a passkey.

You still need the device/account that the passkey is stored on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: