We know the damage that can happen when people steal passwords. But other stolen information can do harm, including facial templates.
Non-password authentication
I’ve been writing some use cases around the common “selfie plus ID” method.
- Usually you use facial recognition plus a government-issued ID (such as a driver’s license) to enroll in the system and verify your identity. (Although you could use other factors.)
- Usually you use only facial recognition (against the template stored from enrollment) to authenticate your identity. (Again, you could use other factors, even a password.)
If the identity mechanism is centralized, you don’t store a password, but instead store a biometric template.
The threat of theft
What happens when—not if—the central storage is hacked?
Even if the storage is decrypted (you did encrypt the data at rest, right?), all may not be lost. Biometric templates from one vendor may not be usable by another vendor’s system.
But even in the worst case scenario in which someone steals and reuses someone’s biometric template, it’s practically useless if the system guards against presentation attacks (liveness) and injection attacks. With those guards, you need more than a valid template to get into a system.
And for those who respond that decentralized identity is the perfect solution…edge devices can be hacked also.
The threat to privacy
But those are just the technical issues. You have to deal with the business issues.
Because the theft exposes personally identifiable information, which may result in legal issues.
Depending upon local law, you have to inform your users of the breach, potentially disclosing what data was breached.
What now?
Are you ready to deal with the business consequences?
Bredemarket can help you get ready.
