• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

How Biometrics are Worse than Passwords

By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
May 12, 2016, 11:26 AM ET

There’s good news for consumers weary of getting their identity hacked. The password system, which is the source of so many data breaches, is getting phased out.

The bad news is that biometrics systems, which are starting to replace the password, come with some big security risks of their own.

The idea of biometric security, if you’re unfamiliar, is that people use some distinct body attribute—such as a fingerprint, iris, or heart rate—to prove one’s identity instead of a password. Such features are already common in everyday devices like Apple’s iPhone, which allows its owner to authorize a payment with a fingerprint.

The advantage of biometric security features is that they are very hard to copy, and consumers don’t have to remember them. Contrast this with passwords, which hackers can break because they are obvious (many people still use standbys like “12345”) or through the guessing power of a computer.

Get Data Sheet, Coins2Day ’s technology newsletter.

Unfortunately, biometric data can also be hacked. There have already been a number of large scale breaches, including a 2015 incident in which the fingerprints of 5.6 million workers were stolen from the Federal Government Office of Personnel Management.

Even worse, when biometric security is compromised, the damage is long-lasting. You can change your password after a data breach, but you can’t change your fingerprint.

The looming risk for consumers is that more organizations, including companies and governments, will build databases of biometric identifiers in order to conveniently identify them. Such databases are a security risk and, for companies, a legal minefield.

As a new report by PricewaterhouseCoopers points out, different countries have widely different privacy laws about the collection and transfer of biometric data. Any company who holds such data—either directly or through a third party cloud computing provider—will find themselves in a world of regulatory pain if that data is stolen or misused.

For a closer look at biometrics and passwords, watch:

The news isn’t all bad, however. There’s a growing awareness that the solution to protecting biometric data is for companies to not retain this sensitive information in the first place. Instead, advises the PwC report, the alternative is they should rely on a system where the biometric information is stored only on the user’s device rather than a centralized server.

In practice, this involves a consumer grafting one or more biometric identifiers, perhaps a thumbprint and a voice signal, onto a phone or computer. Then, when the consumer does business with a third-party like PayPal or another website, his or her device and the website swap confirmation signals (sort of like the two sets of codes used in nuclear security) in order to verify identity.

This, for example, is how the iPhone’s Apple Pay (AAPL) works. Apple does not actually transmit a copy of the user’s thumbprint to a merchant, but instead, it provides a one-time confirmation signal to authorize the payment. Such arrangements are already becoming standardized, through protocols such as one called FIDO, that include device makers and companies in the tech and financial industries.

The bottom line is that, as governments and companies embrace biometrics, they should resist the temptation to create central databases and expose consumers to even greater risks than the insecure world of passwords.

About the Author
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Coins2Day, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.