Reply to post: Try again, no rush

HTC caught storing fingerprints AS WORLD-READABLE CLEARTEXT

Anonymous Coward
Anonymous Coward

Try again, no rush

As has been said on here many times, you cannot change your fingerprints.

Once your fingerprints are compromised what do you do, thank HTC for their broad and non-personal apology (if they issue one)?

If a load of user accounts are compromised and then everyone updates their password, the attacker's password data is useless. Not so with fingerprints... they just need another half arsed attack later to get some more unchangable data and then another minor compromise ... none of the stolen data on finger prints gets old.. its valid data until you die.

My bank give me 2 part auth with a rotating RSA key style dongle... this must be a better direction to be going right?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon