Chinese citizens will have to submit to a face scan in order to get a new phone number

This is really hard to do with biometrics. A password is a string of characters which is always exactly the same every time you type it, but biometrics are messy, and there will always be noise in the measurements. You need a special kind of hash function which is tolerant of that noise and still lets you correctly compare a new measurement to the stored hash.

Even if you have that, I’m not sure that hashing really gains you anything here. If I were only allowed one password and it was tattooed on my face, then it wouldn’t matter how good of a hash algorithm was used - anyone with the hash and a security camera pointed at my face could easily tell that I’m a match for the hash, because the password is right there on my face.

I think the only secure and privacy-preserving biometric system is a two factor system which relies on biometrics to unlock a key stored in a physical token I carry. Apple Pay is a real world example of that kind of system: my biometric data is only stored in my phone, and is only used to decrypt keys which are also stored on my phone, which then authenticate me for credit card payments.

1 Like