You unlocked your phone with your face. Can your face be stolen like a password?

  • CLOUDY podcasts
AI
One look at the screen and your phone unlocks in a fraction of a second. It feels like magic, but in reality, it is just mathematics. The system simply calculates the probability that it is really you. Katarína Remecká, CEO of Qubit Conference, explains in the 39th episode of the CLOUDY podcast why biometrics are not foolproof and why the balance between convenience and security may ultimately be a greater risk than most users realize.

Biometrics work differently from a traditional password or PIN. When unlocking your phone with your face, the phone does not look for a completely exact match. It compares your face with the stored record and calculates how closely they match. If the match is high enough, the phone recognizes you and unlocks. It is therefore not 100% certain, but rather a calculation of the probability that you are really you.

This leads to two types of errors:

  • False rejection: The phone may fail to recognize you even though you are the actual user. This can happen, for example, when your appearance changes or under difficult lighting conditions.

  • False acceptance: The phone may instead allow someone else to access it because their face is considered similar enough to yours.

The result is a trade-off between convenience and security. The stricter the system settings, the lower the chance that it will allow the wrong person in. At the same time, however, the risk of the system rejecting the actual user increases.

Why is your face different from a password?

You can change a password or PIN. You cannot change your face that easily.

This is one of the main challenges of biometrics. We regularly expose our biometric data without even thinking about it. Our faces appear in photos and videos on social media, our voices can be captured in recordings, and our fingerprints can remain on objects we touch.

“Putting that familiar Victory sign in a photo? Absolutely not. A good camera can now capture your fingerprints directly from the photo.” Katarína Remecká, CEO of Qubit Conference

Biometrics therefore offer a great deal of convenience, but they also rely on data that cannot simply be changed if it falls into the wrong hands.

Do companies really store photos of our faces?

Modern biometric systems often do not store a photo of your face in its original form. Instead, they create a mathematical representation that is used for comparison during future authentication.

Katarína Remecká explains this in the podcast using a simple analogy:

“It is like taking a dry bread roll and grinding it into breadcrumbs. With the breadcrumbs, you know they came from that bread roll, but you can never put them back together and recreate the original roll.”

This type of processing can help protect biometric data. However, it does not mean that biometrics are automatically risk-free. It is also important how a particular system creates, stores and protects biometric data.

Is voice the most vulnerable biometric data in the age of AI?

Voice is one type of biometric data whose misuse is becoming more accessible with the development of artificial intelligence. Today, creating a realistic voice clone may require only a short recording.

The problem is not limited to advertising. Voice clones can also be used in scams, for example in a phone call where the caller pretends to be a family member or colleague. For a person on the other end of the call, such a voice can be very difficult to distinguish from the real one.

How can your bank recognize you by the way you type?

There is also behavioral biometrics, a method of authentication that monitors how a person behaves when using a device.

This can include the speed and rhythm at which someone presses keys, the way they move a mouse or other characteristics of how they use a device. The system can compare these patterns with your usual behavior. If your behavior differs significantly from the established profile, the system may require additional authentication or take another security step. The user may not even know that this type of analysis is happening in the background.

Password vs. biometrics: what is the difference?

A password or PIN can be changed after a data breach. During authentication, the system checks whether you entered the correct information.

Biometrics work differently. The system compares your biometric characteristics, such as your face, voice or fingerprint, with a stored record. In some systems, it does not look for an exact match, but evaluates how closely the characteristics correspond.

The biggest difference appears when data is compromised. You can change a password. You cannot simply change a biometric characteristic that is linked to your body.

What should you take away from this?

Biometrics are not inherently either more secure or less secure than passwords. This does not mean that we should not use biometrics. On the contrary, they can be very practical and are an important part of modern security. However, the strongest protection often comes from combining several authentication methods, such as biometrics with a PIN, password or another factor.

You can listen to the full podcast episode on 👉 Spotify and 👉 Apple Podcasts, or watch it on 👉 YouTube.

decor

News and articles