Related Posts
What is Op Transfer Pricing
Pro forma or proforma?
Helloo 🎏 .. need your thoughts on below 👇

Additional Posts in Tech
I need a job, please can someone assist me ?
McKinsey & Company Any advice to help prepare for data science analyst role at top consulting firms (McKinsey & Company EY Boston Consulting Group etc)? Any materials, open source platform recommended to take on freelance data science project? When should I start actively looking and applying? I am a new grad who is working in tech as a marketing analyst I’m looking to pivot to marketing& sales data science consulting next year. Would like someone with similar backgrounds offer some practical tips.
New to Fishbowl?
unlock all discussions on Fishbowl.





Rising Star
You are spot on that a biometric signature can be stolen just like a normal password. You are also correct that you can change a password but not your fingerprint.
The only real response I can give you is that biometric authentication is usually done on the local device and that hackers prefer to go after password files on servers.
So while yes a hacker can steal your password...that would be a lot of effort to get just one password. They get a better ROI by going after the servers with password files.
Good insight, thanks
Update: IRS suspends biometric authentication. https://apnews.com/article/technology-business-data-privacy-ron-wyden-f955f9f3ad074f0263018ef2ae38ea01
What are you seeing as the problem?
As far as I know, biometric validation is done locally on the device and not on the app servers, so no one should be seeing your "biometric data" anywhere outside your phone, in fact it's usually an option you can only turn on after creating an account
Rising Star
It's all about multi step verification and ease. You need to strike the right balance where security doesn't block efficiency and efficiency doesn't block security.
Public key authentication is the way
Biometrics should only be used for local logins like your phone pin imo
Chief
MFA all day
so annoying though
One specific biometrics issue that concerns me is the recently published US IRS requirement to submit biometric data to a third party for facial recognition. This will be required to log in to the IRS web site.
1. It's only a matter of time before the third party is compromised. Hopefully the biometric data is well protected. Could an attacker leverage this to cause a false positive identity validation? Probably.
2. But even if the data is well protected, will the third party be able to detect deep fake videos produced to defeat their facial recognition software?
https://www.westernjournal.com/irs-will-soon-require-biometric-data-taxpayers/