Enabling fingerprint or facial login for devices and/or accounts
People can access devices and accounts with biometric information (such as a fingerprint or facial scan). The unique biometric information is linked to a passphrase/password. This helps reduce security friction during the login process.
Why is it important?
Biometric information is something you are. Because it is something you are, it is unique and hard to compromise.
The information can be linked to the password/passphrase protecting an account and used as an alternative method to login. This encourages use of stronger passwords as they don’t need to be typed in as often.
Priority Tier
Behaviours in SebDB are ranked by their impact on risk. Tier 1 behaviours have the biggest impact, Tier 4 behaviours the least.
Risk Mitigated
Account Compromise
Account compromise happens when unauthorised people access them.
Data Theft
Data theft is the intentional stealing of data.
Further reading
https://www.ncsc.gov.uk/collection/biometrics https://researchbriefings.parliament.uk/ResearchBriefing/Summary/POST-PN-0578#fullreport https://ieeexplore.ieee.org/document/8590812 https://www.worldscientific.com/doi/abs/10.1142/S0219467801000086 https://www.theseus.fi/bitstream/handle/10024/44684/Babich_Aleksandra.pdf