Post: Use of Biometrics
Use of Biometrics →
Posted Tuesday 27th November 2007 14:00 GMT
In Biometrics won't fix data loss problems
I think there is a general misunderstanding of how they propose to use biometrics to link individuals to an electronic identity/identity card. As far as I understand it the proposal is to use a biometric to unlock a digital certificate stored on a smartcard which may have other identifiers on it also, such as photo, name, mag stripe, 3D barcode etc. The biometric replaces the PIN normally used to release such information from a card (such as a credit card etc). I don't think anyone is proposing to have a single biometric identifier system since that would be pretty unworkable (the computing power needs to identify 'who am I' rather than 'am I who I say I am').
The biometric is just used to create a very large number when hashed through an algorothim; you can't steal it since it is just a number, and most secure systems will reject exact matches anyway, while encrypting and timestamping traffic between reader and card.
It does all work, but very expensive, and you need to be very sure who people are at registration. Only took 3 months to do paper ID cards though last time
