Showing posts with label biometrics. Show all posts
Showing posts with label biometrics. Show all posts

Sunday, December 16, 2012

Can We Solve the Security Dilemma?

I recently wrote a blog post about the need to strike the right balance between security and convenience. In this post, I'd like to examine the ways to find that balance amid ever raising security requirements. The challenge lies in the fact that the traditional security measures such as strong passwords are becoming increasingly insufficient. The computing power available to every hacker today is simply so immense that brute-force attacks are rather easy to execute. Note: a brute-force attack is an encryption decoding technique that uses vast computing power to quickly try all possible combinations of characters - until the right key is found.

So, how do we overcome this problem?

The solution isn’t easy, particularly given the security and convenience trade-off. Strong passwords force us to use longer passwords and passphrases that have to include a combination of letters, numbers, special characters, etc. that cannot be found in the dictionary. We all know that such passwords are less convenient, particularly when entering them on a smartphone but the benefit of this trade-off is higher security. Alas, not much higher, as strong passwords can be still broken with brute-force attacks.

Multi-factor authentication takes things to the next level by combining passwords with another authentication mechanism such as one time passcodes or tokens. My bank, for example, gave me a one-time passcode generator the size of a credit card that I use for some of the more important transactions. I don’t need it to check my account balance but I do need it for money transfers. That, by the way, is a good example of the security-convenience balance in a practical use case.

The next level of security can be provided by biometrics. Today, retina scans are the way the government identifies citizens at border crossings who use the Global Crossing or Nexus service. It seems to work and for a long time I thought this would solve the authentication problem for good. However, the biometric signatures can be falsified and even stolen which not only compromises the security but also introduces a new identity theft challenge. No, I am not talking about stolen fingers and eyeballs like we see in the movies - I am talking about the series of data points that biometric scanners look for. Same is true for a DNA-based authentication, by the way. I am not aware of any practical DNA authentication use cases outside of science fiction today, but the signature files for DNA samples could be falsified or stolen just like any password.

Biometric security could be even more vulnerable as a result of genetic research. There are various initiatives underway today to build an open source library of decoded human genomes for the purposes of genetic research. That is a great cause which I fully support. However, there may be a dark side to it - as there usually is with any scientific discovery. I am not a genetic scientist but I wonder if the human genome could be used to reproduce biometric features such as fingerprints, retinas, or DNA samples. After all, a lot of the genomic research is aimed at the ability to reproduce vital human organs...

One day, we might be voluntarily or involuntarily implanting chips into the human body for the purposes of strong, fast, and secure authentication. Some of this is already happening today. We are chipping our pets to find them when they get lost. We are tagging prisoners under home confinement. We are traveling with passports containing our biometric data. A chip using some type of RFID technology could transmit our identity to various applications to identify us. The chip could do so frequently - perhaps every few seconds - to continuously validate the identity of the user. That is, until someone finds a way to falsify the chip signature...

Clearly, solving the security dilemma is not easy. Just like any high stakes game, there may never be a perfect solution. Instead, it will be a race. We will keep inventing better authentication while trying to stay a step ahead of the bad guys. Every time the good guys invent a new security measure, the crooks will find a way to beat it. Hence a new level of security has to be invented - without completely sacrificing convenience. And so it will keep going round after round.

Sunday, November 25, 2012

Security and Convenience - The Balance Matters

In our world, where information is the ultimate strategic resource, security is important. Very important. But security usually stands in the way of productivity and convenience.

Take something like strong passwords and the need to change them regularly. We could significantly increase the system security if we mandated very long, strong passwords with 256 characters and if we mandated them to be changed every day. The data would be very safe with these passwords. Of course remembering such passwords would be highly inconvenient, if not impossible, and changing them daily would be annoying. Want even higher security? How about 1024 character long passwords that have to be changed every hour?

Practical security today has to reach a compromise; a balance between security and convenience. We have to keep pushing the barriers on security without annoying users so much that they either give up or develop behavior that actually compromises the security altogether. In my password example above, people would lose productive time every day and they would likely have no choice but to write the password down every morning on a piece of paper kept right next to their monitor. All of those passwords lying around would severely compromise the security of the system which would achieve exactly the opposite from the intended result. If you are interested in learning more about password related challenges, I recommend reading the recent Wired article titled Kill the Password: Why a String of Characters Can’t Protect Us Anymore.

Clearly, there is a constant tradeoff that we have to make between security and convenience. However, not every organization is the same in terms of how strong their security needs to be  and how much inconvenience they can impose on their employees. I often meet customers who are on very different points of the spectrum, from very casual to utterly paranoid.


Of course nobody will admit that they have a casual attitude towards security. However, consider the differences between retail, manufacturing, and, yes, many technology companies which often get by with relatively simple security (I know, there are always exceptions) versus organizations such as military installations, intelligence agencies, and nuclear facilities. These operate on a completely different security level and have no choice but to impose a lot of inconvenience on their employees.

Think about all of the employees working at Internet startups in Silicon Valley and about how much security hassle you could put them through - not much! James Bond, on the other hand, never tires of opening the cafeteria doors using his palm and voice print. Apparently, high security standards come with some jobs (or companies).

What’s important is that one size doesn’t fit all when it comes to security. Different organizations face different security problems and their solutions have to be adjustable. For example, a two-factor authentication may be appropriate in some environments while a biometrics based authentication is a good fit in others.  Getting the balance right between security and convenience is important - the balance matters!

Tuesday, April 10, 2012

Mobile Security Conundrum

Typing a password on your mobile device can be a pain. The keyboard is tiny and the password gets in the way of convenience and productivity which are the reasons to use a smartphone in the first place. Chances are you only have a short password that consists of 4 or 5 characters. Your password is probably a string of easy to type numbers like “1-2-3-4” or a simple word. Strong passwords consisting of a combination of lowercase and uppercase letters, numbers, special characters and at least 8-10 characters in length are not very useful on a mobile device.

The problem is that mobile devices are easy to lose and when they fall into the wrong hands, the simple passwords are just too easy to hack. On top of that, it is quite likely that many of your important files have been copied onto your device via synchronization.

With device-to-device data synchronization via cloud based synchronization tools ranging from the consumer-oriented ones like Dropbox to the enterprise-focused OpenText Tempo, security is becoming increasingly a concern. For a minute, let’s not worry about the security of the actual repository and the private cloud vs public cloud debate. Let’s talk about the security of the data stored on the device.

The synchronization ensures that there is a current copy of your files on each mobile device which is tremendously convenient, especially if you are switching between devices throughout the day like I do - iPhone, iPad, work PC and home iMac. But the convenience comes at a price - you have to trust that each device is secure and the security starts with a good password. But good, strong passwords are just too impractical on a mobile device and most users don’t use them.

How do we solve this conundrum?

Well, there's not much you can do in the short term other than educating the users or perhaps imposing draconian password rules if the device connects to your corporate network. The draconian approach may work but it will likely result in undesired behavior - the users will find ways around your network security.

In the long term, the device manufacturers will need to step up. The devices will need to be secured via a typing-free authentication method. One such method involved biometrics. Fingerprint scanner, face recognition or retina scan could solve the problem. Some of us frequent travelers have signed up for easy border crossing services such as Nexus or GlobalEntry which use the retina scan technology. It works! In fact, these technologies are available for our smartphones today, albeit they are not quite the mainstream yet. Scanning is still relatively slow if I want to make a quick phone call but probably faster and easier than typing a strong password. And much more secure!

Voice print based passwords are another possibility. Combining the pass phrase with the color and intonation of your voice is faster and more convenient than typing on a small screen. But the ambient noise might represent a challenge. Besides, I don’t want to sit on a plane next to someone repeating his password once every five minutes...

Another possibility is the use of NFC technology (near field communication) which uses an RFID chip. This chip could be carried on the user’s body in the form of an ID card, bracelet or ring (remember Scott McNealy’s Java ring from the 1998 JavaOne conference?). Such loosely attached chips could still be lost or stolen but even with that risk, the security might be stronger than a “1-2-3-4” password. The chip could be also implanted into the person’s body which would make things much more secure and much more convenient. Imagine if your device could verify your identity several times per minute without ever interrupting your work!

OK, OK, I can hear your screams about Big Brother and the government’s invasion into your privacy. But what privacy? If you move around a city, your image is captured on hundreds of security cameras. To get a driver’s license or a passport, you’ve surrendered your picture and fingerprints. Consciously or unconsciously, you pass through multiple security checkpoints every day - from transportation security, public building entrances, hotel check-ins to in-store purchases. Oh, and your mobile phone includes a GPS chip that can be tracked by law enforcement even if the phone is switched off.

Alright, implanted RFID chips may be still a bit of a stretch. But somehow, we will need to solve the conundrum with strong security on mobile devices...