Not a Catch-all

Not a Catch-all

Businesses are relying on biometrics for additional login processes

When used effectively, biometrics can contribute to safer cybersecurity practices. By moving beyond basic password-based authentication, the technology provides a much-needed, alternative layer of security that’s often more difficult for fraudsters to hack. Across the globe, businesses are relying on biometrics to bolster employee login processes, financial institutions are leveraging the technology to verify online purchases and consumer solutions such as Apple’s Touch ID are making daily smartphone usage more seamless and secure.

ABI Research estimates that the global biometrics market will reach more than $30 billion by 2021, which marks a 118 percent increase from 2015. Despite this growing enthusiasm, though, it’s a mistake for organizations to rely solely on biometrics to keep their networks and user data secure. While the technology can add an effective, additional layer of cybersecurity, it’s not a catch-all. In fact, the very nature of biometric technology can introduce additional security gaps.

Consider the following examples of key biometrics characteristics that can lead to serious cybersecurity weaknesses:

Unreliable facial recognition. While it can be used as an effective form of authentication, facial recognition is challenging to implement because it can lead to high false positive rates. For instance, if an individual is wearing sunglasses or a new pair of reading glasses their facial scan can get rejected. Also, it can be difficult for facial recognition machines to decipher between individuals who look similarly, whether it is two separate people who look alike or the same person who appears in different photos at varying ages or lighting.

Insecure fingerprints. With biometrics, fingerprints can be used in lieu of (or in addition to) passwords. Unlike with passwords, however, users aren’t trained to protect their fingerprints, and keep them a secret. As a result, they can be very easy for hackers to steal. In fact, one hacker famously beat Apple’s Touch ID technology just one day after its release by creating a copy of a fingerprint smudge left on an iPhone screen and using it to hack into the phone.

Significant user friction. Maintaining an effective balance between strong cybersecurity and frictionless usability is critical, but it’s not easy. It’s even more difficult when it comes to invasive authentication systems like biometrics, particularly if users are already happy with the level of security they get with passcode and/or two-factor authentication (2FA) systems. Biometrics require total user buy-in, and given the added layer of personal (i.e. physical) security involved, that can be difficult to maintain.

Perhaps the most worrisome aspect of biometrics, though, is that biometric-based authentication is irrevocable. A face, voice or fingerprint can’t be discarded and replaced like a password or a credit card; it’s permanently associated with a user. And just as passwords are occasionally used across multiple accounts and therefore constantly susceptible to attacks, there will always be insecure systems that can result in a leak of biometric credentials, rendering them useless for all other systems.

ABI Research estimates that the global biometrics market will reach more than $30 billion by A more effective approach to cybersecurity relies not on one technology, like biometrics, but instead on multiple technologies and forms of intelligence. By stitching together verified user data points such as location, payment details, websites visited, login credentials or typical transaction behavior to form “digital identities,” for example, organizations can better pinpoint and transact with legitimate users. ABI Research estimates that the global biometrics market will reach more than $30 billion by Because this collected user data is unique and impossible to fake, as it leverages the infinite number of connections users create when they transact online, organizations can securely deliver more seamless user experiences and thwart malicious hackers in real-time.

ABI Research estimates that the global biometrics market will reach more than $30 billion by Basic password systems, 2FA and biometrics alone are no longer enough. To compete with the increasing resources and skills of today’s determined hackers, organizations need to think bigger and implement real-time cybersecurity solutions that leverage existing user data to quickly and accurately authenticate trusted users and effectively assess risk, before it’s too late.

This article originally appeared in the May 2017 issue of Security Today.

About the Author

Alisdair Faulkner is the chief products officer at ThreatMetrix.

Featured

  • Hot AI Chatbot DeepSeek Comes Loaded With Privacy, Data Security Concerns

    In the artificial intelligence race powered by American companies like OpenAI and Google, a new Chinese rival is upending the market—even with the possible privacy and data security issues. Read Now

  • Survey: CISOs Increasing Budgets for Crisis Simulations in 2025

    Today, Cyber Performance Center, Hack The Box, released new data showcasing the perspectives of Chief Information Security Officers (CISOs) towards cyber preparedness in 2025. In the aftermath of 2024’s high-profile cybersecurity incidents, including NHS, CrowdStrike, TfL, 23andMe, and Cencora, CISOs are reassessing their organization’s readiness to manage a potential “chaos” of a full-scale cyber crisis. Read Now

  • Human Risk Management: A Silver Bullet for Effective Security Awareness Training

    You would think in a world where cybersecurity breaches are frequently in the news, that it wouldn’t require much to convince CEOs and C-suite leaders of the value and importance of security awareness training (SAT). Unfortunately, that’s not always the case. Read Now

  • Windsor Port Authority Strengthens U.S.-Canada Border Waterway Safety, Security

    Windsor Port Authority, one of just 17 national ports created by the 1999 Canada Marine Act, has enhanced waterway safety and security across its jurisdiction on the U.S.-Canada border with state-of-the-art cameras from Axis Communications. These cameras, combined with radar solutions from Accipiter Radar Technologies Inc., provide the port with the visibility needed to prevent collisions, better detect illegal activity, and save lives along the river. Read Now

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.