Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wouldn't put too much faith in biometrics either, a real shame considering their convenience.

https://blog.kraken.com/post/11905/your-fingerprint-can-be-h...

Personally I advocate using BitWarden for commonly used logins that, if they were compromised, would not be catastrophic; perhaps in some cases because 2FA provides another, tautologically, factor, and KeePass secured with a FIDO2 device in challenge response mode, a passphrase, and possibly setting a higher key stretching work factor to further blunt any brute force attempt, in which more important data is held.



That's an absurd amount of effort to bypass fingerprint biometrics, nice.

However, it's important to note here that biometrics isn't just about fingerprints and every OS handles their available biometrics options differently. For example, I would recommend face authentication on apple devices, however I would avoid using face for windows, and instead recommend a windows hello PIN (yes, it's handled differently than the PIN in the above article).

Ultimately, you're just trying to create a balance between the layers of protection and reasonable attacks. There's only so much you can protect against, nobody can withstand someone who is cloning fingerprints, stealing devices, has access to your separate device 2FA, etc. without severely affecting their lifestyle.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: