Not a Catch-all

Not a Catch-all

Businesses are relying on biometrics for additional login processes

When used effectively, biometrics can contribute to safer cybersecurity practices. By moving beyond basic password-based authentication, the technology provides a much-needed, alternative layer of security that’s often more difficult for fraudsters to hack. Across the globe, businesses are relying on biometrics to bolster employee login processes, financial institutions are leveraging the technology to verify online purchases and consumer solutions such as Apple’s Touch ID are making daily smartphone usage more seamless and secure.

ABI Research estimates that the global biometrics market will reach more than $30 billion by 2021, which marks a 118 percent increase from 2015. Despite this growing enthusiasm, though, it’s a mistake for organizations to rely solely on biometrics to keep their networks and user data secure. While the technology can add an effective, additional layer of cybersecurity, it’s not a catch-all. In fact, the very nature of biometric technology can introduce additional security gaps.

Consider the following examples of key biometrics characteristics that can lead to serious cybersecurity weaknesses:

Unreliable facial recognition. While it can be used as an effective form of authentication, facial recognition is challenging to implement because it can lead to high false positive rates. For instance, if an individual is wearing sunglasses or a new pair of reading glasses their facial scan can get rejected. Also, it can be difficult for facial recognition machines to decipher between individuals who look similarly, whether it is two separate people who look alike or the same person who appears in different photos at varying ages or lighting.

Insecure fingerprints. With biometrics, fingerprints can be used in lieu of (or in addition to) passwords. Unlike with passwords, however, users aren’t trained to protect their fingerprints, and keep them a secret. As a result, they can be very easy for hackers to steal. In fact, one hacker famously beat Apple’s Touch ID technology just one day after its release by creating a copy of a fingerprint smudge left on an iPhone screen and using it to hack into the phone.

Significant user friction. Maintaining an effective balance between strong cybersecurity and frictionless usability is critical, but it’s not easy. It’s even more difficult when it comes to invasive authentication systems like biometrics, particularly if users are already happy with the level of security they get with passcode and/or two-factor authentication (2FA) systems. Biometrics require total user buy-in, and given the added layer of personal (i.e. physical) security involved, that can be difficult to maintain.

Perhaps the most worrisome aspect of biometrics, though, is that biometric-based authentication is irrevocable. A face, voice or fingerprint can’t be discarded and replaced like a password or a credit card; it’s permanently associated with a user. And just as passwords are occasionally used across multiple accounts and therefore constantly susceptible to attacks, there will always be insecure systems that can result in a leak of biometric credentials, rendering them useless for all other systems.

ABI Research estimates that the global biometrics market will reach more than $30 billion by A more effective approach to cybersecurity relies not on one technology, like biometrics, but instead on multiple technologies and forms of intelligence. By stitching together verified user data points such as location, payment details, websites visited, login credentials or typical transaction behavior to form “digital identities,” for example, organizations can better pinpoint and transact with legitimate users. ABI Research estimates that the global biometrics market will reach more than $30 billion by Because this collected user data is unique and impossible to fake, as it leverages the infinite number of connections users create when they transact online, organizations can securely deliver more seamless user experiences and thwart malicious hackers in real-time.

ABI Research estimates that the global biometrics market will reach more than $30 billion by Basic password systems, 2FA and biometrics alone are no longer enough. To compete with the increasing resources and skills of today’s determined hackers, organizations need to think bigger and implement real-time cybersecurity solutions that leverage existing user data to quickly and accurately authenticate trusted users and effectively assess risk, before it’s too late.

This article originally appeared in the May 2017 issue of Security Today.

About the Author

Alisdair Faulkner is the chief products officer at ThreatMetrix.

Featured

  • Survey: 54% of Organizations Cite Technical Debt as Top Hurdle to Identity System Modernization

    Modernizing identity systems is proving difficult for organizations due to two key challenges: decades of accumulated Identity and Access Management (IAM) technical debt and the complexity of managing access across multiple identity providers (IDPs). These findings come from the new Strata Identity-commissioned report, State of Multi-Cloud Identity: Insights and Trends for 2025. The report, based on survey data from the Cloud Security Alliance (CSA), highlights trends and challenges in securing cloud environments. The CSA is the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment. Read Now

  • Study: Only 35 Percent of Companies Include Cybersecurity Teams When Implementing AI

    Only 35 percent of cybersecurity professionals or teams are involved in the development of policy governing the use of AI technology in their enterprise, and nearly half (45 percent) report no involvement in the development, onboarding, or implementation of AI solutions, according to the recently released 2024 State of Cybersecurity survey report from ISACA, a global professional association advancing trust in technology. Read Now

  • New Report Series Highlights E-Commerce Threats, Fraud Against Retailers

    Trustwave, a cybersecurity and managed security services provider, recently released a series of reports detailing the threats facing the retail sector, marking the second year of its ongoing research into these critical security issues. Read Now

  • Stay Secure in 2024: Updated Cybersecurity Tips for the Office and at Home

    Cyber criminals get more inventive every year. Cybersecurity threats continue to evolve and are a moving target for business owners in 2024. Companies large and small need to employ cybersecurity best practices throughout their organization. That includes security integrators, manufacturers, and end users. Read Now

Featured Cybersecurity

Webinars

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3