Not a Catch-all

Not a Catch-all

Businesses are relying on biometrics for additional login processes

When used effectively, biometrics can contribute to safer cybersecurity practices. By moving beyond basic password-based authentication, the technology provides a much-needed, alternative layer of security that’s often more difficult for fraudsters to hack. Across the globe, businesses are relying on biometrics to bolster employee login processes, financial institutions are leveraging the technology to verify online purchases and consumer solutions such as Apple’s Touch ID are making daily smartphone usage more seamless and secure.

ABI Research estimates that the global biometrics market will reach more than $30 billion by 2021, which marks a 118 percent increase from 2015. Despite this growing enthusiasm, though, it’s a mistake for organizations to rely solely on biometrics to keep their networks and user data secure. While the technology can add an effective, additional layer of cybersecurity, it’s not a catch-all. In fact, the very nature of biometric technology can introduce additional security gaps.

Consider the following examples of key biometrics characteristics that can lead to serious cybersecurity weaknesses:

Unreliable facial recognition. While it can be used as an effective form of authentication, facial recognition is challenging to implement because it can lead to high false positive rates. For instance, if an individual is wearing sunglasses or a new pair of reading glasses their facial scan can get rejected. Also, it can be difficult for facial recognition machines to decipher between individuals who look similarly, whether it is two separate people who look alike or the same person who appears in different photos at varying ages or lighting.

Insecure fingerprints. With biometrics, fingerprints can be used in lieu of (or in addition to) passwords. Unlike with passwords, however, users aren’t trained to protect their fingerprints, and keep them a secret. As a result, they can be very easy for hackers to steal. In fact, one hacker famously beat Apple’s Touch ID technology just one day after its release by creating a copy of a fingerprint smudge left on an iPhone screen and using it to hack into the phone.

Significant user friction. Maintaining an effective balance between strong cybersecurity and frictionless usability is critical, but it’s not easy. It’s even more difficult when it comes to invasive authentication systems like biometrics, particularly if users are already happy with the level of security they get with passcode and/or two-factor authentication (2FA) systems. Biometrics require total user buy-in, and given the added layer of personal (i.e. physical) security involved, that can be difficult to maintain.

Perhaps the most worrisome aspect of biometrics, though, is that biometric-based authentication is irrevocable. A face, voice or fingerprint can’t be discarded and replaced like a password or a credit card; it’s permanently associated with a user. And just as passwords are occasionally used across multiple accounts and therefore constantly susceptible to attacks, there will always be insecure systems that can result in a leak of biometric credentials, rendering them useless for all other systems.

ABI Research estimates that the global biometrics market will reach more than $30 billion by A more effective approach to cybersecurity relies not on one technology, like biometrics, but instead on multiple technologies and forms of intelligence. By stitching together verified user data points such as location, payment details, websites visited, login credentials or typical transaction behavior to form “digital identities,” for example, organizations can better pinpoint and transact with legitimate users. ABI Research estimates that the global biometrics market will reach more than $30 billion by Because this collected user data is unique and impossible to fake, as it leverages the infinite number of connections users create when they transact online, organizations can securely deliver more seamless user experiences and thwart malicious hackers in real-time.

ABI Research estimates that the global biometrics market will reach more than $30 billion by Basic password systems, 2FA and biometrics alone are no longer enough. To compete with the increasing resources and skills of today’s determined hackers, organizations need to think bigger and implement real-time cybersecurity solutions that leverage existing user data to quickly and accurately authenticate trusted users and effectively assess risk, before it’s too late.

This article originally appeared in the May 2017 issue of Security Today.

About the Author

Alisdair Faulkner is the chief products officer at ThreatMetrix.

Featured

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

  • Empowering and Securing a Mobile Workforce

    What happens when technology lets you work anywhere – but exposes you to security threats everywhere? This is the reality of modern work. No longer tethered to desks, work happens everywhere – in the office, from home, on the road, and in countless locations in between. Read Now

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.