this post was submitted on 02 Aug 2026
157 points (91.1% liked)

Cybersecurity

10398 readers
64 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[โ€“] CubitOom@infosec.pub -5 points 1 day ago (1 children)

I haven't misunderstood anything.

Biometrics is a compromise between security and convenience. It is a bad practice for anyone actually concerned with their security, and who values security over convenience.

You can use biometrics if you want. However, if you are going to craft analogies, try to depict the situation more accurately.

[โ€“] neatchee@piefed.social 6 points 1 day ago

The analogy is perfectly accurate.

An imperfect, simpler form of security vs a higher, more cumbersome form of security.

Where is the problem with that analogy?

Biometrics are not "bad practice for anyone concerned about security". They are one type of security that is sufficient and effective for certain risk profiles but not others. Users should make informed decisions based on their needs and the features of the security implementations they are considering.

Your hyperbole is, in fact, dangerous as it pushes people who do not understand security to blindly accept policies that are not good for their risk profile. We have proof that proper usage of biometrics is more consistent with end-users than proper usage of passwords. It's not just about convenience. It's also about adoption and proper compliance.

Absolutist policies and positions like yours do harm. Just look at how NIST recommendations have moved away from things like frequent password change enforcement because it leads to bad behavior (writing down passwords, etc)