• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

How Biometrics are Worse than Passwords

By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
May 12, 2016, 11:26 AM ET

There’s good news for consumers weary of getting their identity hacked. The password system, which is the source of so many data breaches, is getting phased out.

The bad news is that biometrics systems, which are starting to replace the password, come with some big security risks of their own.

The idea of biometric security, if you’re unfamiliar, is that people use some distinct body attribute—such as a fingerprint, iris, or heart rate—to prove one’s identity instead of a password. Such features are already common in everyday devices like Apple’s iPhone, which allows its owner to authorize a payment with a fingerprint.

The advantage of biometric security features is that they are very hard to copy, and consumers don’t have to remember them. Contrast this with passwords, which hackers can break because they are obvious (many people still use standbys like “12345”) or through the guessing power of a computer.

Get Data Sheet, Fortune’s technology newsletter.

Unfortunately, biometric data can also be hacked. There have already been a number of large scale breaches, including a 2015 incident in which the fingerprints of 5.6 million workers were stolen from the Federal Government Office of Personnel Management.

Even worse, when biometric security is compromised, the damage is long-lasting. You can change your password after a data breach, but you can’t change your fingerprint.

The looming risk for consumers is that more organizations, including companies and governments, will build databases of biometric identifiers in order to conveniently identify them. Such databases are a security risk and, for companies, a legal minefield.

As a new report by PricewaterhouseCoopers points out, different countries have widely different privacy laws about the collection and transfer of biometric data. Any company who holds such data—either directly or through a third party cloud computing provider—will find themselves in a world of regulatory pain if that data is stolen or misused.

For a closer look at biometrics and passwords, watch:

The news isn’t all bad, however. There’s a growing awareness that the solution to protecting biometric data is for companies to not retain this sensitive information in the first place. Instead, advises the PwC report, the alternative is they should rely on a system where the biometric information is stored only on the user’s device rather than a centralized server.

In practice, this involves a consumer grafting one or more biometric identifiers, perhaps a thumbprint and a voice signal, onto a phone or computer. Then, when the consumer does business with a third-party like PayPal or another website, his or her device and the website swap confirmation signals (sort of like the two sets of codes used in nuclear security) in order to verify identity.

This, for example, is how the iPhone’s Apple Pay (AAPL) works. Apple does not actually transmit a copy of the user’s thumbprint to a merchant, but instead, it provides a one-time confirmation signal to authorize the payment. Such arrangements are already becoming standardized, through protocols such as one called FIDO, that include device makers and companies in the tech and financial industries.

The bottom line is that, as governments and companies embrace biometrics, they should resist the temptation to create central databases and expose consumers to even greater risks than the insecure world of passwords.

About the Author
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Fortune, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon

Latest in Tech

AITech
Nvidia’s CEO says AI adoption will be gradual, but when it does hit, we may all end up making robot clothing
By Marco Quiroz-GutierrezDecember 6, 2025
1 hour ago
Mark Zuckerberg laughs during his 2017 Harvard commencement speech
SuccessMark Zuckerberg
Mark Zuckerberg says the ‘most important thing’ he built at Harvard was a prank website: ‘Without Facemash I wouldn’t have met Priscilla’
By Dave SmithDecember 6, 2025
3 hours ago
AIMeta
It’s ‘kind of jarring’: AI labs like Meta, Deepseek, and Xai earned some of the worst grades possible on an existential safety index
By Patrick Kulp and Tech BrewDecember 5, 2025
15 hours ago
Elon Musk
Big TechSpaceX
Musk’s SpaceX discusses record valuation, IPO as soon as 2026
By Edward Ludlow, Loren Grush, Lizette Chapman, Eric Johnson and BloombergDecember 5, 2025
15 hours ago
data center
EnvironmentData centers
The rise of AI reasoning models comes with a big energy tradeoff
By Rachel Metz, Dina Bass and BloombergDecember 5, 2025
15 hours ago
netflix
Arts & EntertainmentAntitrust
Hollywood writers say Warner takeover ‘must be blocked’
By Thomas Buckley and BloombergDecember 5, 2025
15 hours ago

Most Popular

placeholder alt text
Economy
Two months into the new fiscal year and the U.S. government is already spending more than $10 billion a week servicing national debt
By Eleanor PringleDecember 4, 2025
2 days ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
2 days ago
placeholder alt text
Success
Nearly 4 million new manufacturing jobs are coming to America as boomers retire—but it's the one trade job Gen Z doesn't want
By Emma BurleighDecember 4, 2025
2 days ago
placeholder alt text
Success
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant 'state of anxiety' out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
2 days ago
placeholder alt text
Real Estate
‘There is no Mamdani effect’: Manhattan luxury home sales surge after mayoral election, undercutting predictions of doom and escape to Florida
By Sasha RogelbergDecember 4, 2025
2 days ago
placeholder alt text
Big Tech
Mark Zuckerberg rebranded Facebook for the metaverse. Four years and $70 billion in losses later, he’s moving on
By Eva RoytburgDecember 5, 2025
19 hours ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.