Microsoft Got Your Fingerprint

  • user warning: Table 'nolan.comments' doesn't exist query: SELECT COUNT(*) FROM comments WHERE nid = 102 AND status = 0 in /home/sneakin/web/nolan.eakins.net/includes/database.mysql.inc on line 120.
  • user warning: Table 'nolan.comments' doesn't exist query: SELECT c.cid as cid, c.pid, c.nid, c.subject, c.comment, c.format, c.timestamp, c.name, c.mail, c.homepage, u.uid, u.name AS registered_name, u.picture, u.data, c.score, c.users, c.thread, c.status FROM comments c INNER JOIN users u ON c.uid = u.uid WHERE c.nid = 102 AND c.status = 0 GROUP BY c.cid, c.pid, c.nid, c.subject, c.comment, c.format, c.timestamp, c.name, c.mail, u.picture, c.homepage, u.uid, u.name, u.picture, u.data, c.score, c.users, c.thread, c.status ORDER BY c.thread DESC LIMIT 0, 50 in /home/sneakin/web/nolan.eakins.net/includes/database.mysql.inc on line 120.

I just loaded up Microsoft.com, and right there on the front page is an image that says "Tired of remembering passwords? Replace them with your fingerprint". Arg, must Microsoft be told about the evils of using your fingerprint for authentication too, or will they just have to wait until a customer calls and says, "A worm just sniffed my fingerprint and credit card number and sent them off. Now my credit is out of whack, and I can't change my fingerprint!"

Even Microsoft warns against the use of it for financial activity, "The Fingerprint Reader should not be used for protecting sensitive data such as financial information or for accessing corporate networks. We continue to recommend that you use a strong password for these types of activities."

Lets reiterate: the only secure way to use a fingerprint is to place the reader on a smart card or USB key that does public-key encryption. That leaves no possibility of a man in the middle to sniff your fingerprint, and they can't even get at your public key. So why does Microsoft even try to sell a fingerprint scanner as a cure all to the password problem?

Ad's by Google