Biometrics
Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > What precautions should be taken if biometric data is compromised?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What precautions should be taken if biometric data is compromised?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 November 2007
What happens if a biometrics database gets compromised? How do you recover from this event? What do you say to your customers?

>
EXPERT RESPONSE
The compromise of biometric data is like the theft of any other authentication credential. It allows unauthorized access to systems.

But, on the other hand, also like other authentication credentials, it's not really considered sensitive employee or customer information, whose loss might have to be reported under some state and federal legislation.

Either way, that doesn't lessen the impact of its compromise, and biometric data needs to be protected and secured. Though it's much harder to steal, replay and use than more traditional authentication credentials, such as user IDs and passwords, biometric data is still digital data than can be sniffed off the wire if not properly encrypted.

Biometric credentials, which start out as analog data in the form of fingerprints, voice recordings and images ranging from faces to retinas, must ultimately be converted into the same ones and zeros as any other data to be read and used by computer systems.

The other problem with compromised biometric data is that it's hard to replace. Unlike user IDs and passwords which can be reset, or tokens and smart cards which can be replaced, lost biometric data, such as fingerprints, is more difficult to replace. This is a fundamental problem with biometrics.

One solution is to have the biometric device only use a portion of the data. For example, rather than storing a whole fingerprint, the device would only use a random piece of the fingerprint. This way, if the biometric data on file is compromised, another part of the fingerprint can be used as a replacement.

Other things to consider when shopping around for biometric products is whether the device securely captures the data, encrypts it in transit to the authentication server and then stores it securely. Recent releases of Active Directory and LDAP mesh with biometrics products and have mechanisms for securely transporting and storing biometrics data.

What should you tell customers? Besides best practices and common sense, this is a legal issue. An attorney should be contacted for regulatory requirements on notification of breaches for authentication credentials, including biometrics.

For more information:

  • Joel Dubin discusses the positive and negative aspects of using keystroke dynamic-based authentication systems.
  • Learn how the combination of biometrics and electrophysiological signals can be used for authentication.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Identity Management and Access Control
    CardSpace vs. user IDs and passwords
    Biometrics vs. biostatistics
    What are the dangers of using radio frequency identification (RFID) tags?
    What are the risks of connecting a Web service to an external system via SSL?
    What should an internal support model for identity management look like?
    How to prevent hack attacks against smart card systems.
    For a small office, what are the best, least expensive office servers with secure access?
    What are the pros and cons of using stand-alone authentication that is not Active Directory-based?
    Should users set up password expiries in Active Directory?
    How to conduct an efficient and thorough employee access review.

    Biometrics
    Keystroke recognition aids online authentication at credit union
    Biometrics vs. biostatistics
    How to choose the right biometric security product
    Using fingerprint door locks in a network environment
    Where did the biometric device come from?
    How can the combination of biometrics and electrophysiological signals be used for authentication?
    What are the pros and cons of using keystroke dynamic-based authentication systems?
    What risks are associated with biometric data, and how can they be avoided?
    Is there any policy or regulation to help protect biometric data?
    Review: DigitalPersona offers solid biometric authentication
    Biometrics Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    biometric payment  (SearchSecurity.com)
    electro-optical fingerprint recognition  (SearchSecurity.com)
    false acceptance  (SearchSecurity.com)
    finger vein ID  (SearchSecurity.com)
    fingernail storage  (SearchSecurity.com)
    keystroke dynamics  (SearchSecurity.com)
    live capture  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    password hardening  (SearchSecurity.com)
    ridge  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts