Reply to post: Please keep your biometric nettles away from my arse

You call it 'hacking.' I call it 'investigation'

Warm Braw

Please keep your biometric nettles away from my arse

One of the concepts that seems to be missing from "security" considerations of online systems is that of proportionality. That means, of course, that the security of access should be proportionate to the risk of unauthorised access - but conversely, that high-risk systems probably shouldn't depend entirely on online credentials because high-stakes attackers are inevitable and requiring them to post a letter or turn up in person is one of the most effective ways of thwarting brute-force or large-scale attacks.

Online access to my credit card account used to be fairly low risk, because all anyone could usefully do if they gained access was to pay my bill for me. Now any unauthorised user can change my registered email address, home address, access my credit score and do a whole bunch of other things that might threaten my financial security.

The solution to his is not to add biometric complexity so that I can continue to use the one low-risk function I've ever needed (to pay my bills) but to allow me to remove access to the higher-risk functions I don't want.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon