Fingerprints have been known as a way of identifying individuals for centuries – being used as a way of signing contracts, for instance. However, it wasn’t until 1901 that Scotland Yard started identifying criminals using fingerprints and set up the Fingerprint Bureau.
Since then, of course, fingerprints have increasingly been used as forms of ID: paying for school dinners, providing access to the gym, or unlocking your smartphone (and probably several apps within that phone).
Because they are unique, and can’t be easily shared, fingerprints are a good way of proving who you are and —if there’s a match with the print stored on the device—providing you (and no-one else) with access to your phone, your bank account or a building.
Fingerprints aren’t the only way of identifying yourself so that a system will let you in. Increasingly, people are using iris scans, voice recognition, and face recognition—even vasal analysis (structure of veins) and gait recognition.
The issues with biometrics
None of these biometric identification methods are perfect, of course:
- Some recognition systems such as face scans require training, and biased training input can mean demographic variations (such as race and gender) can cause recognition problems.
- The part of the body being used as a biometric can become damaged due to illness and injury, or changed temporarily, for instance by pregnancy or the use of contact lenses. This makes it more difficult for the system to confirm identity.
- And errors are always possible: false identification as well as incorrect rejection.
There are concerns about potential state use of biometrics, and various human rights and privacy issues to be considered too. Then there are the ethical questions, such as; what should be done if the captured biometric data reveals a medical issue.
There’s a lot to think about if moving beyond the simple fingerprint. Using biometrics to catch fraudsters.
The future of Biometrics
The ICO’s report discussing the future for biometrics predicts (among other things) that biometric techniques for interview analysis and staff training will start to be used in the next 4-5 years. For example, the use of augmented reality devices for immersive training is likely to include gaze tracking and heart-rate monitoring.
The report expresses concern about the use of emotional AI (also known as affective computing) for interviews, staff training or monitoring, in which highly sensitive data may be collected via subconscious behaviours and physiological responses, and then analysed. This might reveal emotional state, workplace engagement and medical data relating to mental health. While this might be useful to employers to identify possible insider threat, or to spot potential external fraudsters, it is clearly extremely sensitive information.
The Information Commissioners Office considers biometric data to be special category data wherever it’s used to identify people, learn something about them, make a decision about them or treat them differently in any way. Special category data needs careful handling and protection, and you should conduct a data protection impact assessment (DPIA) for this special category data.
Biometrics and Security
Information about the biometric has to be stored somewhere, either locally (such as on a phone) or centrally (in a police database, for example) so that it can be compared to the person. To secure the biometric information, the data that is stored is not an image of the fingerprint (for example) but an encrypted version, which is stored as the reference copy, and any unencrypted image of the original, deleted. This means that the reference copy could be cancelled if compromised, recreated and the new version re-encrypted.
Staff should be trained in the handling of biometric data, including how to store and process it securely, how to control access to the data, and how to erase it when it is no longer needed.
Fraud
A significant concern is the ease with which criminals can now fake people’s voices. Audio deepfakes are synthetic voices that sound genuine—if you get a call from someone who says they are your boss (or grandson) and sounds like them, asking you to send money to a particular account, you are quite likely to do it. You might then find that you’d been conned.
Is your own voice recorded online somewhere? It could be cloned and used to persuade someone to do something they wouldn’t ordinarily do: it only takes 5 minutes of audio, and doesn’t take much technical skill. You could unwittingly be the cause of someone else being defrauded.
Face scans
And what about face scans? TikTok’s privacy policy says it will collect biometric data from US residents in the form of faceprints and voiceprints, and Facebook has captured face recognition data in the past, to enable tagging. If a ‘faceprint’ has been captured, then, just like a voice, it could result in a deepfake, or an attempt to get through biometric access control.
We recommend that you make staff aware of the dangers of deepfakes (both audio and video) as part of your regular and routine security awareness training, and put in place policies to mitigate the risks. For example, you could consider creating a policy that an unexpected request to make a payment should always be double-checked using a different communications channel – no matter who it appears to come from.
Summary
If you are currently using, or thinking about using, biometric data, we recommend that you should:
- Review the ICO’s guidance on special category data, and make sure you identify the legal basis for using such data.
- Conduct a DPIA, consider the potential risks involved in the use of biometric data within your company, and think through how you’ll mitigate those risks, whether this will be through technical means or updating your policies, procedures and training.
Whether or not you will use biometric data in your organisation, we suggest you warn your staff about the risks of attacks based on impersonation using biometric data, and provide them with training. This will help protect them in their personal lives as well as protecting your business.
