Monash University · FACULTY OF CYBERSECURITY

FIT1093 Chap.8 Password and Biometric Authentication

- one subject, every graph, every model, every mark
7 Chapters5-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 8 of 10 · FIT1093

Password and Biometric Authentication

Week 8 turns from protecting data to verifying people. Entity authentication checks a user's identity before granting access, using one or more of three factors: something you know, such as a password; something you have, such as a phone or passport; and something you are, such as a face or fingerprint.

Workshop 8 opens with a bank account taken over despite three checks, because the password was stolen, the trusted phone was compromised or impersonated, and the facial-recognition alert flagged the login without blocking it.

The lesson is that multi-factor authentication helps only when each factor is hardened and any single failure stops the login.

Passwords depend on several assumptions: only the user knows the password, the user will not reveal it, others cannot guess it, and the server protects what it stores. Dictionary attacks break the last two, online against a login page or offline against a stolen table.

In the workshop's VaultBank case, unsalted SHA-2 digests let attackers look up most passwords in a table prepared in advance.

The fixes are a long random salt for every user, which makes precomputation infeasible and separates users who share a password, and a deliberately slow hash with many rounds, which makes every remaining guess expensive.

Biometrics, physiological or behavioural, work by enrolment and then verification, and they never match exactly, so the system accepts a login when a similarity score reaches a threshold.

The false acceptance rate measures how often impostors get in; the false rejection rate measures how often genuine users are refused. Raising the threshold lowers the first and raises the second, so the choice is a trade-off between security and usability. Assignment 2's first two tasks apply exactly these ideas.

In this chapter

What this chapter covers

  • 01

    Knowledge, possession and biometric factors

  • 02

    Multi-factor authentication and why a breach can still happen

  • 03

    Password assumptions and online and offline dictionary attacks

  • 04

    Salting and slow hashing for stored passwords

  • 05

    Estimating brute-force time from a measured hash

  • 06

    Enrolment, verification and match thresholds

  • 07

    False acceptance and false rejection rates

Worked example · free

Compute FAR and FRR from a face-recognition trial

Q [5 marks]. The mark allocation is our own practice weighting, not an official university scheme. In an invented trial, the owner tries to log in 40 times and is rejected 6 times; an impostor tries 25 times and is accepted once. Compute FAR and FRR, then say what raising the threshold would do.
  • 2FAR counts accepted impostor attempts over all impostor attempts: 1 ÷ 25 = 4%.
  • 2FRR counts rejected genuine attempts over all genuine attempts: 6 ÷ 40 = 15%.
  • 1A higher threshold demands closer matches, so FAR falls but FRR rises, trading usability for security.
FAR is 4% and FRR is 15%. Raising the threshold would reduce impostor acceptances further, at the cost of rejecting the genuine owner more often.
Sia tip — Divide each error count by the attempts of its own kind: impostor attempts for FAR, genuine attempts for FRR, never the combined total.
Glossary

Key terms

Multi-factor Authentication
Authentication that requires evidence from more than one factor, such as a password together with a phone or a fingerprint.
Dictionary Attack
A guessing attack that tries likely passwords from a list, either against a login service or against stolen password digests.
Salt
A random value stored with each password digest and hashed with the password, so identical passwords give different digests.
False Rejection Rate
The share of genuine attempts that a biometric system wrongly refuses, used as its measure of usability.
Match Threshold
The minimum similarity score at which a biometric system accepts a login attempt.
FAQ

Password and Biometric Authentication FAQ

Why did multi-factor authentication fail in the bank case?

The attacker had the password and a trusted phone, so two factors were already compromised, and the facial-recognition check flagged the login without blocking it. Each factor needs hardening, and a failed check must actually stop access.

How does salting stop precomputed password tables?

With a long random salt per user, an attacker would need a separate table for every possible salt, which is far too large to compute or store. Users with the same password also get different digests.

Why use a slow hash for passwords?

A slow hash with many rounds barely affects a server that checks one password per login, but multiplies the cost of every guess for an attacker trying millions of passwords from a stolen table.

Should a bank lower FAR or FRR?

Security against impersonation is measured by FAR, so a bank would usually raise the threshold to lower it. That increases FRR, meaning more genuine customers are rejected, so the choice balances security against usability.

What does Assignment 2 Task 2 ask about password hashing?

It compares SHA-512 at several round counts and SHA-256 using mkpasswd and John the Ripper, then asks for a recommendation that verifies a login in under 50 milliseconds and an estimate of brute-forcing 100 million passwords.

Study strategy

Assessment move

Make a three-column table for the factors, listing for each one an example, the main ways it is compromised and the matching countermeasure, and use it to analyse any account-takeover story in the order the workshop does. For passwords, practise explaining precomputed dictionary tables, salting and slow hashing as three separate fixes for three separate problems.

For biometrics, compute FAR and FRR from small invented data sets at two or three thresholds, always tabulating the four counts first, and say in a sentence what each threshold means for a user. Before submitting Assignment 2, check that every rate, timing and estimate in your report is traceable to a screenshot and that the units stay consistent.

Working through Password and Biometric Authentication in FIT1093? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Password and Biometric Authentication question and get a clear, step-by-step explanation grounded in how FIT1093 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 111 of your Monash University subjects - and 1,000+ Bibles across every Australian university.
Sia - your FIT1093 tutor, unlimited, worked the way the exam marks it
The full 5-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works
FIT1093 · Cybersecurity Tools and Techniques - independent study guide on the AskSia Library. More Monash University subjects · Microeconomics across all universities