localzuk Posted March 9, 2020 Posted March 9, 2020 What about a hash of a photo? I believe it depends on how you're processing it - it becomes biometric data when you're using it as such. Biometric data is classified as "special category data" when it is used for identification purposes. So, a photo stored on a PC of a fun event - not biometric data used for identification. A database of photos used for matching faces when they walk around the school? Biometric data for identification purposes.
mavhc Posted March 9, 2020 Posted March 9, 2020 So at that point you use the hash to reduce the risk to help justify it vs the rewards. Of course laws are written by lawyers to force you to hire lawyers, so that's annoying. Problem is given enough data anything can be used to track you, I can see that user 419 and user 194 both go to the supply closet at 4pm every Friday, and user 419 mostly uses the science and history block doors, so they're obviously Teacher X
GrumbleDook Posted March 9, 2020 Posted March 9, 2020 So at that point you use the hash to reduce the risk to help justify it vs the rewards. Of course laws are written by lawyers to force you to hire lawyers, so that's annoying. Problem is given enough data anything can be used to track you, I can see that user 419 and user 194 both go to the supply closet at 4pm every Friday, and user 419 mostly uses the science and history block doors, so they're obviously Teacher X If the hash is then used for identification purposes, it is still processing information as a result of biometric information. And these laws were written by lawyers, privacy advocates, politicians, technologist and many more. 1
mavhc Posted March 9, 2020 Posted March 9, 2020 (edited) If the hash is then used for identification purposes, it is still processing information as a result of biometric information. And these laws were written by lawyers, privacy advocates, politicians, technologist and many more. Why is that worse than processing information as a result of, say, a pin number? Biometric: Are you you? Yes. Information processed! You may now access the files/money/etc of that user Non biometric: Are you you? Maybe? Did someone steal my card, or guess my password? Information processed! You may now access the files/money/etc of whoever you're pretending to be. Edited March 9, 2020 by mavhc
localzuk Posted March 9, 2020 Posted March 9, 2020 Biometric: Are you you? Yes. Information processed! You may now access the files/money/etc of that user Non biometric: Are you you? Maybe? Did someone steal my card, or guess my password? Information processed! You may now access the files/money/etc of whoever you're pretending to be. Because you can change a PIN, you can't change your fingers.
paulkerton Posted March 9, 2020 Posted March 9, 2020 Why is that worse than processing information as a result of, say, a pin number? Really? Come on. Your PIN isn't grafted onto your body and unchangeable, for one. Your PIN isn't so unique that it can only be yours. A PIN number can't be requisitioned by the police and security services. Many, many reasons.
mavhc Posted March 9, 2020 Posted March 9, 2020 Really? Come on. Your PIN isn't grafted onto your body and unchangeable, for one. Your PIN isn't so unique that it can only be yours. A PIN number can't be requisitioned by the police and security services. Many, many reasons. But that's the point of a password, that it is only yours. That it's stuck on your body is great for getting your dinner, can't forget it. Why are the police checking who's had dinner?
paulkerton Posted March 9, 2020 Posted March 9, 2020 But that's the point of a password, that it is only yours. That it's stuck on your body is great for getting your dinner, can't forget it. Why are the police checking who's had dinner? You're being deliberately obtuse now, and know exactly the issues - so I shall withdraw from the conversation at this point.
mavhc Posted March 9, 2020 Posted March 9, 2020 Fingerprint readers are on everything, people like them, laptops, phones, they're there because they're better than passwords.
blueday Posted March 9, 2020 Posted March 9, 2020 Considering that my phone often fails to recognise my thumbprint, and when some of the Florida theme parks used to offer ride lockers only accessible by fingerprints I always had to get an attendant to help open mine, I'm glad I don't have to rely on it to get my lunch!!
chazzy2501 Posted March 9, 2020 Posted March 9, 2020 I think people still don't understand that fingerprint readers don't use pictures of your fingerprints (what you would consider a biometric identifier) but use a mathematical description of your finger which is used as part of a biometric authenticator. The (biometric authenticators) description is like comparing the description of your granny (how tall, colour hair, etc) to pick her out in a room vs a picture of your granny which could be used anywhere and for other purposes. The description (derived from a biometric source) does NOT it self qualify as a Biometric Identifier as this description can never be used outside of its environment and can't be reversed back into a fingerprint.
localzuk Posted March 9, 2020 Posted March 9, 2020 I think people still don't understand that fingerprint readers don't use pictures of your fingerprints (what you would consider a biometric identifier) but use a mathematical description of your finger which is used as part of a biometric authenticator. The (biometric authenticators) description is like comparing the description of your granny (how tall, colour hair, etc) to pick her out in a room vs a picture of your granny which could be used anywhere and for other purposes. The description (derived from a biometric source) does NOT it self qualify as a Biometric Identifier as this description can never be used outside of its environment and can't be reversed back into a fingerprint. The law disagrees, as the original article shows. Poland's data protection rules are based on GDPR, as are the UK's so it is likely applicable here too. And that is what matters in this discussion, as we work in professional environments where we have to abide by the law. This isn't just about fingerprints either. A Swedish school was fined for using facial recognition - even though the school got permission from the parents, the school were still fined as the Swedish equivalent of the ICO didn't consider this to be adequate for the reason they were using the data, and that there were less intrusive ways of achieving their goal. 2
GrumbleDook Posted March 9, 2020 Posted March 9, 2020 Why is that worse than processing information as a result of, say, a pin number? Biometric: Are you you? Yes. Information processed! You may now access the files/money/etc of that user Non-biometric: Are you you? Maybe? Did someone steal my card, or guess my password? Information processed! You may now access the files/money/etc of whoever you're pretending to be. Biometric for identification for banking services: We want to provide the tightest possible security as this is something that needs protecting and we will only use it for identification of this service alone, because security around money is what we do! Biometric ... just because: Hey, here is a cool tech that saves some time ... and we will force you to use it, even though we have taken pretty much no safeguards on how we do things. Non-biometric used by careful users: I will retain this complex, unique password in a password management system that relies on MFA to start it up each time I start my computer/browser ... or ... I have an RFID ID card that I keep in a card holder, attached to a lanyard and make sure it does not leave my person ... every ... and also need a pin to go with it. Non-biometric used by ... well ... you know the sort of people: Hey, I'll write this password on a post-it note and stick it on the screen ... and I'll make sure all my password
GrumbleDook Posted March 9, 2020 Posted March 9, 2020 I think people still don't understand that fingerprint readers don't use pictures of your fingerprints (what you would consider a biometric identifier) but use a mathematical description of your finger which is used as part of a biometric authenticator. The (biometric authenticators) description is like comparing the description of your granny (how tall, colour hair, etc) to pick her out in a room vs a picture of your granny which could be used anywhere and for other purposes. The description (derived from a biometric source) does NOT it self qualify as a Biometric Identifier as this description can never be used outside of its environment and can't be reversed back into a fingerprint. The data held can be used and checked against biometric data to validate it ... it still counts as biometric data. If I get your fingerprint and create a fake one, I could fool certain fingerprint readers. 1
synaesthesia Posted March 9, 2020 Posted March 9, 2020 As has been said, you can't forget, lose or easily damage a fingerprint - it's a matter of convenience over anything else. For a typical UK school the basis of asking for fingerprint for cashless catering as an example is convenience and cost. With less cards to replace in the case of RFID, it costs less financially and in time reprogramming. In the case of PIN codes, it costs less in time for resetting/reminding. Time and money are both valuable in schools now more than ever with less staff to run all of this, whether that's IT/reception staff resetting or handing out these details or canteen staff having to put several hundred children through a system in half an hour. We make it clear we prefer the use of fingerprints for this reason - sometimes some people's fingers don't register so we express a preference to try their thumb instead, but there is the option for a PIN if all else fails, or they don't have permission or have other reasons against doing so. We won't discriminate against it's use, and wouldn't dream of telling those with pins to the back of the queue - that's just immoral. Facial recognition though - yes realistically it's little more invasive than fingerprint but does seem particularly over the top! TLDR: We generally have a good basis for processing biometric data in this fashion, and would be a large, countrywide upheaval if someone says OI! SCHOOLS! NOOOOO! . Simply, don't take the mick
Zammo Posted March 9, 2020 Posted March 9, 2020 Fingerprint readers are on everything, people like them, laptops, phones, they're there because they're better than passwords. I have yet to come across a laptop that runs slower if you dont use a fingerprint or a phone that has reduced battery life if you choose not to enable biometrics In the case linked the school were deliberately putting non-biometric users at a disadvantage Similarly I have not come across either where the use of biometrics is *mandated* and then stored on a device that you have no control over Apples and massive oranges To round it off you are not even right when you say people prefer them on laptops https://laptopstudy.com/best-laptop-fingerprint-reader/ Very few laptops I see have built in readers, and I dont know of anyone who uses one at home Phones are a different beast as they are accessed dozens or hundreds of times a day.
mikeprice Posted March 9, 2020 Posted March 9, 2020 Where I have seen fingerprint readers used it was always simply the preferred option One of the reasons for it being preferred was bullying - there was a problem of kids being threatened (apparently) to hand over their card so the bully could get dinner for free you can;t so easily force someone to hand over their fingerprint That was the main reason they were introduced - cards were always an option but one that the kids didn;t really like as it meant having to remember the thing as an aside - when they were installed I was amazed to find that the readers and money machines communicated to their server via serial lines - using RS-422 standard - I hadn;t seen that used for over 10 years when it was already ancient tech!!! I assume that they use IP nowadays
mavhc Posted March 9, 2020 Posted March 9, 2020 Unlikely, hardware people can't do software. And they doubly can't do secure software. Serial is sometimes better though, do you want a whole IP stack to exploit, or just a character interface? All the laptops we've bought (cheap because they were old versions) in the past 3 years have had fingerprint readers. Interestingly the G4 HP Probooks have the swipe ones, whereas the G6 ones have the press, I assume because of phones making those cheaper now
paulkerton Posted March 10, 2020 Posted March 10, 2020 As has been said, you can't forget, lose or easily damage a fingerprint I'll give you forget, but you can lose and easily damage them. Ask the people who made the chainmail for Lord of the Rings!
paulkerton Posted March 10, 2020 Posted March 10, 2020 If I get your fingerprint and create a fake one, I could fool certain fingerprint readers. Working in schools, it's not like fumigation cupboards and superglue are hard to get a hold of either! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now