FIT1093 Chap.8 Password and Biometric Authentication
Password and Biometric Authentication
Week 8 turns from protecting data to verifying people. Entity authentication checks a user's identity before granting access, using one or more of three factors: something you know, such as a password; something you have, such as a phone or passport; and something you are, such as a face or fingerprint.
Workshop 8 opens with a bank account taken over despite three checks, because the password was stolen, the trusted phone was compromised or impersonated, and the facial-recognition alert flagged the login without blocking it.
The lesson is that multi-factor authentication helps only when each factor is hardened and any single failure stops the login.
Passwords depend on several assumptions: only the user knows the password, the user will not reveal it, others cannot guess it, and the server protects what it stores. Dictionary attacks break the last two, online against a login page or offline against a stolen table.
In the workshop's VaultBank case, unsalted SHA-2 digests let attackers look up most passwords in a table prepared in advance.
The fixes are a long random salt for every user, which makes precomputation infeasible and separates users who share a password, and a deliberately slow hash with many rounds, which makes every remaining guess expensive.
Biometrics, physiological or behavioural, work by enrolment and then verification, and they never match exactly, so the system accepts a login when a similarity score reaches a threshold.
The false acceptance rate measures how often impostors get in; the false rejection rate measures how often genuine users are refused. Raising the threshold lowers the first and raises the second, so the choice is a trade-off between security and usability. Assignment 2's first two tasks apply exactly these ideas.
What this chapter covers
- 01
Knowledge, possession and biometric factors
- 02
Multi-factor authentication and why a breach can still happen
- 03
Password assumptions and online and offline dictionary attacks
- 04
Salting and slow hashing for stored passwords
- 05
Estimating brute-force time from a measured hash
- 06
Enrolment, verification and match thresholds
- 07
False acceptance and false rejection rates
Worked example · free
Compute FAR and FRR from a face-recognition trial
- 2FAR counts accepted impostor attempts over all impostor attempts: 1 ÷ 25 = 4%.
- 2FRR counts rejected genuine attempts over all genuine attempts: 6 ÷ 40 = 15%.
- 1A higher threshold demands closer matches, so FAR falls but FRR rises, trading usability for security.
Key terms
- Multi-factor Authentication
- Authentication that requires evidence from more than one factor, such as a password together with a phone or a fingerprint.
- Dictionary Attack
- A guessing attack that tries likely passwords from a list, either against a login service or against stolen password digests.
- Salt
- A random value stored with each password digest and hashed with the password, so identical passwords give different digests.
- False Rejection Rate
- The share of genuine attempts that a biometric system wrongly refuses, used as its measure of usability.
- Match Threshold
- The minimum similarity score at which a biometric system accepts a login attempt.
Password and Biometric Authentication FAQ
Why did multi-factor authentication fail in the bank case?
The attacker had the password and a trusted phone, so two factors were already compromised, and the facial-recognition check flagged the login without blocking it. Each factor needs hardening, and a failed check must actually stop access.
How does salting stop precomputed password tables?
With a long random salt per user, an attacker would need a separate table for every possible salt, which is far too large to compute or store. Users with the same password also get different digests.
Why use a slow hash for passwords?
A slow hash with many rounds barely affects a server that checks one password per login, but multiplies the cost of every guess for an attacker trying millions of passwords from a stolen table.
Should a bank lower FAR or FRR?
Security against impersonation is measured by FAR, so a bank would usually raise the threshold to lower it. That increases FRR, meaning more genuine customers are rejected, so the choice balances security against usability.
What does Assignment 2 Task 2 ask about password hashing?
It compares SHA-512 at several round counts and SHA-256 using mkpasswd and John the Ripper, then asks for a recommendation that verifies a login in under 50 milliseconds and an estimate of brute-forcing 100 million passwords.
Assessment move
Make a three-column table for the factors, listing for each one an example, the main ways it is compromised and the matching countermeasure, and use it to analyse any account-takeover story in the order the workshop does. For passwords, practise explaining precomputed dictionary tables, salting and slow hashing as three separate fixes for three separate problems.
For biometrics, compute FAR and FRR from small invented data sets at two or three thresholds, always tabulating the four counts first, and say in a sentence what each threshold means for a user. Before submitting Assignment 2, check that every rate, timing and estimate in your report is traceable to a screenshot and that the units stay consistent.
Working through Password and Biometric Authentication in FIT1093? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Password and Biometric Authentication question and get a clear, step-by-step explanation grounded in how FIT1093 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.