Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. When your password leaks:→ Change your password→ Problem solved

When your password leaks:→ Change your password→ Problem solved

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
biometricsprivacydiscord
68 Indlæg 51 Posters 49 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • capitainesam@mastodon.socialC capitainesam@mastodon.social

    When your password leaks:
    → Change your password
    → Problem solved

    When your biometric data leaks:
    → You can't change your face
    → You can't change your fingerprints
    → The compromise is permanent
    → Your biometric data is in breach databases forever

    This is why facial recognition for age verification is dangerous.

    #Biometrics #Privacy #Discord

    paco@infosec.exchangeP This user is from outside of this forum
    paco@infosec.exchangeP This user is from outside of this forum
    paco@infosec.exchange
    wrote sidst redigeret af
    #31

    @capitainesam It’s not all bad: when my security questions got compromised, I got a puppy! (I didn’t want to change my dog’s name)

    1 Reply Last reply
    0
    • capitainesam@mastodon.socialC capitainesam@mastodon.social

      When your password leaks:
      → Change your password
      → Problem solved

      When your biometric data leaks:
      → You can't change your face
      → You can't change your fingerprints
      → The compromise is permanent
      → Your biometric data is in breach databases forever

      This is why facial recognition for age verification is dangerous.

      #Biometrics #Privacy #Discord

      joat@mastodon.scotJ This user is from outside of this forum
      joat@mastodon.scotJ This user is from outside of this forum
      joat@mastodon.scot
      wrote sidst redigeret af
      #32

      @capitainesam market opportunity: add face management to password managers. Generate different fake faces for each service. Automatically overlay fake faces and fake text details over passport scans.

      1 Reply Last reply
      0
      • dancingtreefrog@mastodon.socialD dancingtreefrog@mastodon.social

        @capitainesam So maybe you combine biometrics with password/passkey?

        One of the foundational stories of cyberpunk illustrated a defense against biometrics fraud. The hackers targeted a victim that used fingerprint login. They managed to get a copy of the victim's fingerprint and used it.

        Then the victim's security system kicked in - because the victim always deliberately *failed* the first finger login and used their *second* finger login...

        mercutio@troet.cafeM This user is from outside of this forum
        mercutio@troet.cafeM This user is from outside of this forum
        mercutio@troet.cafe
        wrote sidst redigeret af
        #33

        @dancingtreefrog
        Why copy? Just get the finger. With or without the human hanging on it.

        @capitainesam

        marco_m_aus_f@freiburg.socialM yura@udongein.xyzY chloeraccoon@mastodonapp.ukC 3 Replies Last reply
        0
        • capitainesam@mastodon.socialC capitainesam@mastodon.social

          When your password leaks:
          → Change your password
          → Problem solved

          When your biometric data leaks:
          → You can't change your face
          → You can't change your fingerprints
          → The compromise is permanent
          → Your biometric data is in breach databases forever

          This is why facial recognition for age verification is dangerous.

          #Biometrics #Privacy #Discord

          muzicofiel@mastodon.nlM This user is from outside of this forum
          muzicofiel@mastodon.nlM This user is from outside of this forum
          muzicofiel@mastodon.nl
          wrote sidst redigeret af
          #34

          @capitainesam @EUCommission @HennaVirkkunen Stop biometric identification. It Will turn in a disaster for money (young) people. Caught for life.

          1 Reply Last reply
          0
          • capitainesam@mastodon.socialC capitainesam@mastodon.social

            When your password leaks:
            → Change your password
            → Problem solved

            When your biometric data leaks:
            → You can't change your face
            → You can't change your fingerprints
            → The compromise is permanent
            → Your biometric data is in breach databases forever

            This is why facial recognition for age verification is dangerous.

            #Biometrics #Privacy #Discord

            capitainesam@mastodon.socialC This user is from outside of this forum
            capitainesam@mastodon.socialC This user is from outside of this forum
            capitainesam@mastodon.social
            wrote sidst redigeret af
            #35

            🧵 So what can you do about it?

            Discord isn't the only platform pushing biometric surveillance.

            More platforms will follow. "Age verification" is just the beginning.

            Here's what I'm doing about it:

            capitainesam@mastodon.socialC 1 Reply Last reply
            0
            • capitainesam@mastodon.socialC capitainesam@mastodon.social

              🧵 So what can you do about it?

              Discord isn't the only platform pushing biometric surveillance.

              More platforms will follow. "Age verification" is just the beginning.

              Here's what I'm doing about it:

              capitainesam@mastodon.socialC This user is from outside of this forum
              capitainesam@mastodon.socialC This user is from outside of this forum
              capitainesam@mastodon.social
              wrote sidst redigeret af
              #36

              I'm building @Snugg - social media that will NEVER require:
              ❌ Facial recognition
              ❌ Fingerprint scans
              ❌ Biometric data of any kind

              Why? Because we chose a business model that doesn't need surveillance.

              capitainesam@mastodon.socialC emilyenco@todon.nlE 2 Replies Last reply
              0
              • capitainesam@mastodon.socialC capitainesam@mastodon.social

                I'm building @Snugg - social media that will NEVER require:
                ❌ Facial recognition
                ❌ Fingerprint scans
                ❌ Biometric data of any kind

                Why? Because we chose a business model that doesn't need surveillance.

                capitainesam@mastodon.socialC This user is from outside of this forum
                capitainesam@mastodon.socialC This user is from outside of this forum
                capitainesam@mastodon.social
                wrote sidst redigeret af
                #37

                Subscription model = we serve users, not advertisers.

                No ads = no need for behavioral tracking
                No tracking = no biometric data to "verify" you
                No biometric data = nothing permanent to breach

                Simple.

                capitainesam@mastodon.socialC charlesdelavalleepoussin@mastodon.socialC 2 Replies Last reply
                0
                • capitainesam@mastodon.socialC capitainesam@mastodon.social

                  Subscription model = we serve users, not advertisers.

                  No ads = no need for behavioral tracking
                  No tracking = no biometric data to "verify" you
                  No biometric data = nothing permanent to breach

                  Simple.

                  capitainesam@mastodon.socialC This user is from outside of this forum
                  capitainesam@mastodon.socialC This user is from outside of this forum
                  capitainesam@mastodon.social
                  wrote sidst redigeret af
                  #38

                  We're launching March 2026.

                  Features:
                  ✅ End-to-end encryption (messages + metadata)
                  ✅ Chronological feed (no algorithm)
                  ✅ Open source (auditable code)
                  ✅ Fediverse compatible (ActivityPub)
                  ✅ €5/month (founding members get lifetime discount)

                  capitainesam@mastodon.socialC 1 Reply Last reply
                  0
                  • capitainesam@mastodon.socialC capitainesam@mastodon.social

                    We're launching March 2026.

                    Features:
                    ✅ End-to-end encryption (messages + metadata)
                    ✅ Chronological feed (no algorithm)
                    ✅ Open source (auditable code)
                    ✅ Fediverse compatible (ActivityPub)
                    ✅ €5/month (founding members get lifetime discount)

                    capitainesam@mastodon.socialC This user is from outside of this forum
                    capitainesam@mastodon.socialC This user is from outside of this forum
                    capitainesam@mastodon.social
                    wrote sidst redigeret af
                    #39

                    If 700+ of you care enough to boost the problem,

                    Maybe some of you want to be part of the solution?

                    Founding member waitlist (first 500 get lifetime 40% discount):
                    👉 https://snugg.social

                    No biometric data. Not now. Not ever.

                    1 Reply Last reply
                    0
                    • jacobgorm@sigmoid.socialJ jacobgorm@sigmoid.social

                      @capitainesam unless your profile photo is fake your face data leaked already. I am not sure I understand the concern about face biometrics in a world where we all expose this readily on social media.

                      lp0_on_fire@social.linux.pizzaL This user is from outside of this forum
                      lp0_on_fire@social.linux.pizzaL This user is from outside of this forum
                      lp0_on_fire@social.linux.pizza
                      wrote sidst redigeret af
                      #40

                      @jacobgorm @capitainesam, quite some assumptions there…

                      “Profile photo”

                      “We all”

                      1 Reply Last reply
                      0
                      • dancingtreefrog@mastodon.socialD dancingtreefrog@mastodon.social

                        @capitainesam Don't use biometrics to unlock phones. Police and criminals can grab your hand or aim the phone at your face to unlock your phone regardless of your wishes. They have to ask you for password/PIN; they don't have to ask to simply stick your finger on the phone screen or point the phone at your face.

                        dzwiedziu@mastodon.socialD This user is from outside of this forum
                        dzwiedziu@mastodon.socialD This user is from outside of this forum
                        dzwiedziu@mastodon.social
                        wrote sidst redigeret af
                        #41

                        @dancingtreefrog
                        This might help, it's shake and lock feature to be exact:
                        https://f-droid.org/packages/com.paranoid.privacylock

                        Android advanced security also has this feature, but it adds blocking non-Play app installs and updates.

                        @capitainesam

                        1 Reply Last reply
                        0
                        • capitainesam@mastodon.socialC capitainesam@mastodon.social

                          I'm building @Snugg - social media that will NEVER require:
                          ❌ Facial recognition
                          ❌ Fingerprint scans
                          ❌ Biometric data of any kind

                          Why? Because we chose a business model that doesn't need surveillance.

                          emilyenco@todon.nlE This user is from outside of this forum
                          emilyenco@todon.nlE This user is from outside of this forum
                          emilyenco@todon.nl
                          wrote sidst redigeret af
                          #42

                          @capitainesam looks like you tagged a random person.

                          1 Reply Last reply
                          0
                          • capitainesam@mastodon.socialC capitainesam@mastodon.social

                            When your password leaks:
                            → Change your password
                            → Problem solved

                            When your biometric data leaks:
                            → You can't change your face
                            → You can't change your fingerprints
                            → The compromise is permanent
                            → Your biometric data is in breach databases forever

                            This is why facial recognition for age verification is dangerous.

                            #Biometrics #Privacy #Discord

                            celeste_42bit@infosec.exchangeC This user is from outside of this forum
                            celeste_42bit@infosec.exchangeC This user is from outside of this forum
                            celeste_42bit@infosec.exchange
                            wrote sidst redigeret af
                            #43

                            @capitainesam One of the 1.000.000.000 reasons.

                            Same with ID. It has a biometric photo on it. If scanned accurately, it can, AND WILL, be used to identify you.

                            1 Reply Last reply
                            0
                            • ill_logic@mastodon.socialI ill_logic@mastodon.social

                              @jfml @capitainesam I would hope that your phone takes a "fingerprint" of your fingerprint, i.e. enough to verify but not reconstruct.

                              celeste_42bit@infosec.exchangeC This user is from outside of this forum
                              celeste_42bit@infosec.exchangeC This user is from outside of this forum
                              celeste_42bit@infosec.exchange
                              wrote sidst redigeret af
                              #44

                              @ill_logic @jfml @capitainesam every proper implementation hashes the fingerprint, just like you don't store clear text passwords in the shadow file...

                              The question is, is this a proper implementation on phones...

                              jfml@mastodon.artJ 1 Reply Last reply
                              0
                              • capitainesam@mastodon.socialC capitainesam@mastodon.social

                                When your password leaks:
                                → Change your password
                                → Problem solved

                                When your biometric data leaks:
                                → You can't change your face
                                → You can't change your fingerprints
                                → The compromise is permanent
                                → Your biometric data is in breach databases forever

                                This is why facial recognition for age verification is dangerous.

                                #Biometrics #Privacy #Discord

                                cedriclevasseur@framapiaf.orgC This user is from outside of this forum
                                cedriclevasseur@framapiaf.orgC This user is from outside of this forum
                                cedriclevasseur@framapiaf.org
                                wrote sidst redigeret af
                                #45

                                @capitainesam I don't think it's true.
                                If I compare to SSH keys. My face is the password of my private key.
                                Generating another private key with the same password is still possible and it's a different key.

                                1 Reply Last reply
                                0
                                • capitainesam@mastodon.socialC capitainesam@mastodon.social

                                  When your password leaks:
                                  → Change your password
                                  → Problem solved

                                  When your biometric data leaks:
                                  → You can't change your face
                                  → You can't change your fingerprints
                                  → The compromise is permanent
                                  → Your biometric data is in breach databases forever

                                  This is why facial recognition for age verification is dangerous.

                                  #Biometrics #Privacy #Discord

                                  jake4480@c.imJ This user is from outside of this forum
                                  jake4480@c.imJ This user is from outside of this forum
                                  jake4480@c.im
                                  wrote sidst redigeret af
                                  #46

                                  @capitainesam the ultimate argument against the stupidity of moving away from just using passwords. All this biometric stuff can go take a leap. I'll never use any of it.

                                  1 Reply Last reply
                                  0
                                  • capitainesam@mastodon.socialC capitainesam@mastodon.social

                                    Subscription model = we serve users, not advertisers.

                                    No ads = no need for behavioral tracking
                                    No tracking = no biometric data to "verify" you
                                    No biometric data = nothing permanent to breach

                                    Simple.

                                    charlesdelavalleepoussin@mastodon.socialC This user is from outside of this forum
                                    charlesdelavalleepoussin@mastodon.socialC This user is from outside of this forum
                                    charlesdelavalleepoussin@mastodon.social
                                    wrote sidst redigeret af
                                    #47

                                    @capitainesam

                                    Won't the law require you to to biometric ID?

                                    zuthal@floofy.techZ 1 Reply Last reply
                                    0
                                    • dancingtreefrog@mastodon.socialD dancingtreefrog@mastodon.social

                                      @capitainesam So maybe you combine biometrics with password/passkey?

                                      One of the foundational stories of cyberpunk illustrated a defense against biometrics fraud. The hackers targeted a victim that used fingerprint login. They managed to get a copy of the victim's fingerprint and used it.

                                      Then the victim's security system kicked in - because the victim always deliberately *failed* the first finger login and used their *second* finger login...

                                      S This user is from outside of this forum
                                      S This user is from outside of this forum
                                      skaphle@social.tchncs.de
                                      wrote sidst redigeret af
                                      #48

                                      @dancingtreefrog @capitainesam GrapheneOS supports a pin as second factor for biometrics

                                      1 Reply Last reply
                                      0
                                      • dancingtreefrog@mastodon.socialD dancingtreefrog@mastodon.social

                                        @vrek @capitainesam I seem to recall that it was William Gibson's Neuromancer; the incident that lead to the main character's nervous system being crippled by the Russian mafia. But it's been awhile since I read it, I could be mistaken.

                                        trurl@mastodon.sdf.orgT This user is from outside of this forum
                                        trurl@mastodon.sdf.orgT This user is from outside of this forum
                                        trurl@mastodon.sdf.org
                                        wrote sidst redigeret af
                                        #49

                                        @dancingtreefrog @vrek @capitainesam I think you're describing Orson Scott Card's "Dogwalker," which involves intuiting a password but failing to realize that the target always miskeyed the first time until too late.

                                        "Neuromancer" does have a character who is neurologically crippled by their employer (with a "wartime Russian mycotoxin"). ("He'd made the classic mistake, the one he'd sworn he'd never make. He stole from his employers.")

                                        V 1 Reply Last reply
                                        0
                                        • trurl@mastodon.sdf.orgT trurl@mastodon.sdf.org

                                          @dancingtreefrog @vrek @capitainesam I think you're describing Orson Scott Card's "Dogwalker," which involves intuiting a password but failing to realize that the target always miskeyed the first time until too late.

                                          "Neuromancer" does have a character who is neurologically crippled by their employer (with a "wartime Russian mycotoxin"). ("He'd made the classic mistake, the one he'd sworn he'd never make. He stole from his employers.")

                                          V This user is from outside of this forum
                                          V This user is from outside of this forum
                                          vrek@mastodon.social
                                          wrote sidst redigeret af
                                          #50

                                          @trurl @dancingtreefrog @capitainesam thanks for the clarification. I have been avoiding Orson Scott card because of his actions at conventions previously, although I have read enders game. That said I'm due for a re-read of nueromancer.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper