December 8, 2017 By Douglas Bonderud 2 min read

Has the death of the password finally arrived? Biometric authentication seems poised to supplant the ever-insecure username/password combination.

According to Help Net Security, 68 percent of European citizens surveyed by security firm Unisys said their trust level would increase if organizations leveraged biometric tools for multifactor authentication. But is trust the best measure of long-term security, or are biometric solutions just security breaches waiting to happen?

Benefits of Biometric Authentication

The Unisys survey found that consumers comfortable with technology were ready to ditch passwords in favor of biometrics, Help Net Security noted. Many respondents pointed to the benefit of no longer needing to remember, protect and regularly change passwords.

Sixty-three percent of those asked said they believe biometrics are more secure than current password and personal identification number (PIN) solutions. Meanwhile, 61 percent reported that they were most happy with fingerprint scans as a potential replacement and 41 percent said they prefer iris scanning.

Consumer expectations also play a role in the rise of biometrics, since users are prepared to wait just over 25 seconds for sign-in processes to complete. Fingerprint- and iris-based metrics should speed the authentication process, reducing user frustration.

Customer confidence varies by industry, with 51 percent believing banks would manage biometric data securely and 45 percent confident that the government would do the same. However, just 12 percent think social media companies would be so trustworthy.

As noted by TechTarget, biometric scanning may also offer a way to shore up trust in emerging Internet of Things (IoT) markets. By replacing stock permissions and poorly crafted passwords with reliable biometric scans, enterprises can tap the growing wave of public trust for persistent security measures tied to people, not passwords.

Downstream Concerns

But it’s not all smooth sailing for biometrics. Consider a recent Harvard Business Review article, which discussed the evolving role of Social Security numbers (SSNs) in the process of identification. While SSNs were originally designed to identify Social Security beneficiaries, they’re now used to verify identity and intent across multiple industries.

The same is undoubtedly true for biometrics. What begins as a way to access banking or government services will eventually be leveraged for different purposes, such as marketing. As HBR noted, facial scans, combined with behavioral analysis, can help predict consumers’ personality traits, habits and socioeconomic status.

This naturally leads to target-based marketing, but could also extend to more sinister activities, such as using biometric data to take over a one’s identity. Given the permanent nature of many biometric markers, the results of such a theft could be disastrous.

How Will Biometrics Impact the Future of Security?

Consumers are ready to trust biometrics and willing to hand over fingerprints or iris scans if they can ditch passwords. But technology constantly evolves, and the original intent seldom matches the eventual purpose. Ideally, the shift to biometic authentication comes with a commensurate commitment to regulations and the implementation of standards that clearly lay out how this data may be collected, used and, ultimately, destroyed.

The bottom line is that biometrics are coming. The question is where will it take consumer security?

More from

Unpacking the NIST cybersecurity framework 2.0

4 min read - The NIST cybersecurity framework (CSF) helps organizations improve risk management using common language that focuses on business drivers to enhance cybersecurity.NIST CSF 1.0 was released in February 2014, and version 1.1 in April 2018. In February 2024, NIST released its newest CSF iteration: 2.0. The journey to CSF 2.0 began with a request for information (RFI) in February 2022. Over the next two years, NIST engaged the cybersecurity community through analysis, workshops, comments and draft revision to refine existing standards…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Obtaining security clearance: Hurdles and requirements

3 min read - As security moves closer to the top of the operational priority list for private and public organizations, needing to obtain a security clearance for jobs is more commonplace. Security clearance is a prerequisite for a wide range of roles, especially those related to national security and defense.Obtaining that clearance, however, is far from simple. The process often involves scrutinizing one’s background, financial history and even personal character. Let’s briefly explore some of the hurdles, expectations and requirements of obtaining a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today