• neatchee@piefed.social
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    4 hours ago

    The analogy is perfectly accurate.

    An imperfect, simpler form of security vs a higher, more cumbersome form of security.

    Where is the problem with that analogy?

    Biometrics are not “bad practice for anyone concerned about security”. They are one type of security that is sufficient and effective for certain risk profiles but not others. Users should make informed decisions based on their needs and the features of the security implementations they are considering.

    Your hyperbole is, in fact, dangerous as it pushes people who do not understand security to blindly accept policies that are not good for their risk profile. We have proof that proper usage of biometrics is more consistent with end-users than proper usage of passwords. It’s not just about convenience. It’s also about adoption and proper compliance.

    Absolutist policies and positions like yours do harm. Just look at how NIST recommendations have moved away from things like frequent password change enforcement because it leads to bad behavior (writing down passwords, etc)