The Register® — Biting the hand that feeds IT

Feeds

Post: Use of Biometrics

MGJ

Use of Biometrics 

In Biometrics won't fix data loss problems

Thumb Up

I think there is a general misunderstanding of how they propose to use biometrics to link individuals to an electronic identity/identity card. As far as I understand it the proposal is to use a biometric to unlock a digital certificate stored on a smartcard which may have other identifiers on it also, such as photo, name, mag stripe, 3D barcode etc. The biometric replaces the PIN normally used to release such information from a card (such as a credit card etc). I don't think anyone is proposing to have a single biometric identifier system since that would be pretty unworkable (the computing power needs to identify 'who am I' rather than 'am I who I say I am').

The biometric is just used to create a very large number when hashed through an algorothim; you can't steal it since it is just a number, and most secure systems will reject exact matches anyway, while encrypting and timestamping traffic between reader and card.

It does all work, but very expensive, and you need to be very sure who people are at registration. Only took 3 months to do paper ID cards though last time

Forums

Password reminder