The Macrosite for News, Analysis and Opinion about the Future of the Internet
View by
Channel
Vblogger
Top 5 Vbloggers

Kim Davis
Paul J. Fleuranges
Second Shooter
Wisdom of the Big Chair
Mitch Wagner

Vbloggers A-Z

Sam Altman
Rafat Alvi
Sandeep Amar
Jart Armin
Robert D. Atkinson
David Austin
Cyan Banister
Brian Baron
David Bartlett
Genevieve Bell
Amir Ben-Efraim
Lee H. Berke
Beau Brendler
Stephen Brobst
Brown Out
Jerry Brown
David Buckholtz
Adam Caplan
Kelli Carlson-Jagersma
Dennis Carpio
Daniel Castro
Ann Cavoukian
Staci Cenis
Aneesh Chopra
Scott Clavenna
Bram Cohen
June Cohen
Perry Correll
Phillippe Courtot
Thus Spake Mr. Cramer
Jack Danahy
Jack Dangermond
Kim Davis
Alison Diana
Gil Elbaz
John Engates
Bob Evans
Executive Takes
what.the.ferraro
TeleGraham
Jon Fisher
Paul J. Fleuranges
From the Editors
Raimund Genes
Ben Golub
Lars Härd
Not Dr. Phil
David Hayden
Swayne Hill
The Incredible Hultquist
Marianne James
Mary Jander
Chris Jones
Kevin Jones
John Kennedy
Scott Klososky
Paul Kocher
Scott Koegler
Tony Kontzer
David Koretz
Wisdom of the Big Chair
Thomas S. Kunz
Chris Laping
Eurotrash
Eugene Lee
Ginny Lee
Gideon J. Lenkey
Bill Loumpouridis
Dan MacDonald
Mary Maida
Carl Malamud
Marketing Takes
Marissa Mayer
Wayne Mekjian
Eben Moglen
Jim Morris
Bob Moul
Ken Moy
Full Nelson
Second Shooter
Bolaji Ojo
Mike Olson
Steven Peterson
Edward Pleet
Dale Potter
Reiter's Block
Jodee Rich
Mike Riegel
Treb Ryan
Simon Saba
Rob Salkowitz
Steve Saunders' Outernet
Rachel Schiff
Mary E. Shacklett
Singer at C-Level
John Soat
The Sole Man
Cirque Du Solez
Sebastian Stadil
Marc Staimer
Thomas Steding
Richard Stiennon
Sherry Swackhamer
Sweeney Blog
Chris Tolles
Bob Tricoski
David Vellante
David Vladeck
Raymond Voelker
Mitch Wagner
Cap Watkins
Jeff White
Jane Williams
Jared Wray

The Need for Biometric Encryption

Ontario's information privacy commissioner explains the unintended consequences of facial recognition technology and how biometric encryption can make it safer.
no ratings
DISCUSS     Email This
Written by Ann Cavoukian
11/10/2011 10 comments
Subscribe me to the following:
all IETV video blogs
all Ann Cavoukian video blogs
only Ann Cavoukian video blogs that match the Channels I've selected below:
 
 
  Enterprise IT   Personalization & privacy
  Security   Government
 
   close this box
Current display:       newest comments first       display in chronological order
burn0050
Rank: Cyborg
Thursday May 17, 2012 7:14:26 PM
no ratings

My biggest concern with Biometric encryption, is what happens when the source is gone?

In other words, what if my finger gets cut off? What if my face is maimed? What if I lose an eye? If there's no template, then that data is lost forever, right?

The other issue is that data stolen might be harder without a template, but biometric systems can be fooled - like facial recognition can be thwarted with a simple picture. So, it may help stop mass data theft without storing a template, but biometrics are easier to crack - on an individual basis - than a password stored in your head.

Kim Davis
Thinkernetter
Thursday March 15, 2012 3:02:34 PM
no ratings

The concern I've developed about biometric validation - and I've mentioned it before - is that if the database is breached its much harder to ask users to change their faces or fingerprints than their passwords.

q5sys
Rank: Cave Painter
Wednesday March 14, 2012 9:40:59 PM
no ratings

The problem is that if biometric encryption were devised, it would be trusted as failsafe. The problem is nothing is. Biometric Encryptions sounds wonderful, until you take into account the mess of Key exchange. The premise behind Bio-Enc is that only you can decrypt the data because only you are you. But the computer doesnt know this. All it sees is a string of binary data. A simple side channel attack with the 'correct' binary string will make the computer think that you are someone you are not.
This brings up the problem of burden of proof in legal cases. Attorney's will argue, 'He/She MUST have been there, because the file was encrypted/decrypted.' When in fact thats not the case. Anyone with the appropiate hash data could do whatever the supposed 'owner' was able to do.
Not to metion other possible legal issues. The Federal Courts have recently ruled that law enforcement cannot force you to give up your encryption passwords, because its in your head... and thus testimonial and protected under the 5th ammendment. But if your password is your face or some other biometric data, all they have to do is get you to sit down in a chair and the system will decrypt your data and possibly then give them evidence they otherwise wouldnt have had. 5th ammendment doesnt protect you from your body identifiers... Thats a bed rock of criminal law... from finger prints to DNA analysis.

Then you have the problem of what happens if you're in an accident and loose a finger/hand or are horribly injured and you're face is damaged. Are you then out of luck?
Facial Recog isnt that good, there have been locks for homes built around the concept of Facial Recog allowing entry, and anyone holding up a picture of the person was interupted as the real person.

While the whole idea of Bio-E SOUNDS great. Security wise its not.

Bruce Schneier has mentioned this several times in his blog, if you're interested in his thoughts you should go check them out.

Bio-E brings up more issues than it solves.  And saldy it brings up issues that arent an issue with other forms of encryptions.  Sure its got the Buzzword factor, and it sounds hi-tech.  But most security people would never want to use it because of all the potential issues that arise out of it.

aum007
Thinkernetter
Saturday December 31, 2011 11:16:13 AM
no ratings

Kurt,

Basically what you are saying is this-No matter how advanced and amazing the technology is today-It is'nt foolproof or 100% accurate.

Which is always the case and why any technology should be used only sparingly for critical functions till it is properly and effectively tested.

Regards

Ashish.

Kurtkeys
IQ Crew
Friday November 25, 2011 6:39:28 PM
no ratings

Ann,

having no knowledge of the inner workings of biometric facial recognition I'm not prepared to comment on that aspect of it. However recently I ran across an issue with facial recognition that completely invalidated its use for any purpose, much less legal prosecution of a person.

I recently uploaded some photographs I had taken during my Navy career to my Facebook page one particular photograph, Michelangelo's Pieta - Mary and Jesus Statue, when I loaded it Facebook's highly reputed facial recognition software tried to tag the face of Mary (mother of Jesus) as one of my personal friends who lives in rural Virginia. So for me facial recognition in the legal realm belongs in the same arena as a polygraph. Not admissible as evidence, and certainly not grounds for obtaining an arrest warrant.

~Kurt

Nicole Ferraro
IQ Crew
Thursday November 10, 2011 4:05:52 PM
no ratings

Same here, Mary. Ann Cavoukian will be our guest on IE Radio in December so we'll have the opportunity to ask her about these technologies and how she sees them being implemented going forward.

Mary Jander
Thinkernetter
Thursday November 10, 2011 3:57:35 PM
no ratings

Absolutely. And the wider the exposure to these kinds of safeguards, the likelier it will be that companies not taking action start looking like laggards.

I'm happy to see government taking a real lead in security -- at least one key aspect of it.

Nicole Ferraro
IQ Crew
Thursday November 10, 2011 3:04:32 PM
no ratings

I like that the Commissioner (between this blog and the one on Privacy by Design) poses technology solutions to technology problems. With these possibilities available, it's going to be harder for businesses and technologists to resist the idea of having privacy built right into systems.

Mary Jander
Thinkernetter
Thursday November 10, 2011 2:11:46 PM
no ratings

Great suggestions and innovation here. Biometric facial recognition isn't going away, so we may as well get used to adopting specialized security measures. Biometric encryption is a terrific example.

Bolingbroke
IQ Crew
Thursday November 10, 2011 1:02:17 PM
no ratings

Ann, if I understand correctly if the algorithm that creates the key is complex enough this mitigates against reverse engineering but theoretically reverse engineering is possible?

Ann Cavoukian
1
of
Ann Cavoukian
Privacy Is Everyone's Responsibility

11|1|11   |   4:01   |   17 comments


Ontario's privacy commissioner offers advice to businesses and users for protecting privacy online.
Ann Cavoukian
Understanding 'Privacy by Design'

10|25|11   |   1:10   |   9 comments


Ontario's information and privacy commissioner explains how technology can be used to protect privacy... not just cause its erosion.
Subscribe me to the following:
all IETV video blogs
all Ann Cavoukian video blogs
 
   close this box
5
of
Mary E. Shacklett
Law Will Define Next-Gen Privacy

4|25|12   |   1:48   |   7 comments


The plan for unmanned police drones to patrol traffic and other city conditions in Seattle has sparked a new set of legal concerns about privacy. Law traditionally lags technology, but we can expect now to see a new round of activity in the courts as legal definitions begin to emerge on what "next-gen privacy" will look like.
Ann Cavoukian
Privacy Is Everyone's Responsibility

11|1|11   |   4:01   |   17 comments


Ontario's privacy commissioner offers advice to businesses and users for protecting privacy online.
Wisdom of the Big Chair
IT Losing the Security Battle

1|7|13   |   3:15   |   No comments


ITRC found that more than 600 security breaches took place in 2012. Flaws were found in some of the nation's most respected companies: Apple, Citibank, and Wells Fargo. So, it seems the bad guys are doing better than the men in the white hats.
Mary E. Shacklett
Financial Services Policies Lag Tech Advances

12|4|12   |   2:18   |   6 comments


Regulations haven't kept up with advances in mobile devices and credit cards.
Wisdom of the Big Chair
FBI Turns Attention to Mobile Security

10|30|12   |   3:45   |   8 comments


The FBI recently issued a warning to smartphone users, highlighting two mobile malware applications: Loozfan, which steals personal information, and FinFisher, which is spyware that takes over a smartphone's functions.
Beau Brendler
Terrorism Expert Says US Gave Away Stuxnet Tech

4|4|12   |   3:29   |   9 comments


US counterterrorism expert Richard Clarke, who came to prominence with his prescient warnings before the 9/11 attacks, tells Smithsonian Magazine the US was responsible for the Stuxnet supersmart worm that attacked parts of nuclear reactors in Iran – and in the process, has given away one of the world's most sophisticated cyberweapons.
Mary E. Shacklett
Doing Social Networking Right

3|19|12   |   2:31   |   9 comments


Companies are still getting their feet wet with social networking and what employees should and shouldn't broadcast. But they don't always involve HR and PR. Here's why they should, and what they risk when they don't.
Kim Davis
Doublespeak on Internet Freedom

12|13|11   |   02:08   |   5 comments


Hillary Clinton stands accused of hypocrisy after speaking up for Internet freedom at a conference last week.
Ann Cavoukian
Understanding 'Privacy by Design'

10|25|11   |   1:10   |   9 comments


Ontario's information and privacy commissioner explains how technology can be used to protect privacy... not just cause its erosion.
an IBM information resource
sponsored content
an IBM information resource
sponsored content
big blue blog
Alison Diana
Ushering in a new era of cognitive computing systems, IBM announced today the IBM Watson Engagement Advisor, a technology breakthrough that allows brands to crunch big data in record time to transform the way they engage clients in key functions such as customer service, marketing, and sales.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
Yahoo Needs to Break Tumblr in Order to Fix It
Joe Stanganelli
As
Mitch Wagner discussed today, Yahoo is acquiring Tumblr. The big Internet debate at the moment is whether Tumblr will be good or bad for Yahoo. Regardless of their stances on the future of Yahoo itself, many claim that Yahoo will somehow ruin Tumblr.

CLICK FOR MORE