this post was submitted on 22 Nov 2023
495 points (98.6% liked)

Technology

59666 readers
3142 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] 0xD@infosec.pub 6 points 1 year ago* (last edited 1 year ago) (1 children)

A username is not something "you are", it's something "you know". Biometrics are not nearly the same as usernames.

[–] Luci@lemmy.ca 1 points 1 year ago (2 children)

A username is something you are. It's you! You are 0xD.
A password is something you know. A security key is something you have.

When we interview security analysts you don't get past the first round if you disagree.

[–] feddylemmy@lemmy.world 8 points 1 year ago (1 children)

If your interview involves telling me a username is "something you are" rather than "something you know", I'm running away from that job as fast as I can.

[–] Luci@lemmy.ca -1 points 1 year ago (2 children)

Other people know your username.

How hard is this?

[–] Blueteamsecguy@infosec.pub 2 points 1 year ago

I guarantee you I know thousands of people's passwords as well, I just don't know the username associated.

[–] sirfancy@lemmy.world 0 points 1 year ago

By this same logic, other people could know your fingerprint since it's "something you are". No, other people cannot know your fingerprint. It's a complex mathematical equation to a computer. This is such a terrible take.

Source: CASP+ certified.

[–] 0xD@infosec.pub 4 points 1 year ago

No, this username is one of the names I've chosen for the accounts I use on lemmy. It does not identify me, it identifies the lemmy accounts that I just so happen to know the password for. I was just about to create an account with your username on another instance but meh, that's too much work. Just imagine me having done that and think about what you just wrote.

I would be vary of the people agreeing with you on something so basic yet so wrong.

An authentication factor is a unique identifier that shows that you possess something that others don't. Biometrics are something you are because your fingerprints, your retinas, or your DNA are (mostly) unique to you. A security key is something you have because unique cryptographic material is saved on the hardware device that cannot be replicated somewhere else (which is why many mobile authenticators really aren't). And a password is something you know because... Bla bla bla.

To be pedantic, a username is not a factor in this sense at all; It is an identifier for an account that you have to prove authorization for by presenting some kind of factor, sometimes multiple.