Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

Face and fingerprint unlock are convenience features with a security trade

Biometrics are excellent at making strong protection tolerable and poor at being secrets, because you cannot change them.

Close-up of a steel padlock on a mesh fence, symbolizing protection and security.
Photograph by Connor Scott McManus via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

There is a short answer about biometric authentication and a useful one, and they are not the same. What follows is the useful one.

The short version

  • Templates are stored locally in secure hardware, not as images.
  • A biometric cannot be revoked or changed once compromised.
  • Legal protection for a biometric differs from that for a passcode in some jurisdictions.

What is actually stored

The sensor captures a reading and derives a mathematical template describing distinctive features rather than storing an image. That template is held in a separate secure processor with its own memory, isolated from the main operating system.

The main system asks whether a match occurred and receives only a yes or no, never the template. This is why a device compromise does not straightforwardly hand over your fingerprint.

Matching is probabilistic

A biometric never matches exactly, so the system compares similarity against a threshold. That threshold sets the trade between falsely rejecting you and falsely accepting somebody else, and the two move in opposite directions. Manufacturers publish false acceptance figures, and the practical rates depend on sensor quality, dirt, moisture and how the template was enrolled.

Enrolling the same finger twice in different orientations measurably improves reliability.

You cannot change a fingerprint

A leaked password is replaced in a minute; a leaked biometric template is permanent. This is why biometrics are best used as a convenient unlock for a device that also holds a passcode, rather than as a credential sent to a server. Systems that transmit biometric data to a central database concentrate exactly the risk that local storage avoids.

In practice, regulation in several jurisdictions treats biometric data as a special category with stricter handling requirements for this reason.

Spoofing is a real but bounded risk

Fingerprint sensors have been defeated with lifted prints and moulds, and face systems using flat images have been defeated with photographs. Systems using depth sensing or infrared illumination resist photographs and are substantially harder to defeat. Attention detection, requiring open eyes looking at the device, defends against use while you are asleep or unconscious.

These attacks require effort and physical access, which places them well above the threat model of most people and well within that of some.

In several jurisdictions, compelling somebody to provide a fingerprint or face has been treated differently from compelling disclosure of a passcode. The reasoning turns on whether the act is testimonial, and case law is inconsistent and still developing. Practically, most devices offer a way to force passcode entry quickly, which is worth knowing before you need it.

The short version: this varies enormously by country and should not be assumed from anything read about one jurisdiction.

This is the general case; a specific device may behave differently by design.

Using biometrics well

Treat them as a way to make a long passcode tolerable, and set a long passcode behind them. Know the emergency gesture that disables biometric unlock on your device and requires the passcode. Avoid enrolling other people on a device holding your accounts, since the device cannot distinguish between authorised users afterwards.

In the datasheet, for anything where a compromise would be catastrophic, a hardware security key is a better second factor than a biometric.

The takeaway

A biometric is a convenient key, not a secret. Keep a strong passcode behind it and know how to force it.

Understanding the failure mode tells you more than the feature list does.

Questions readers ask

Is face unlock less secure than a fingerprint?

It depends on the implementation. Systems using depth or infrared sensing are broadly comparable to fingerprint sensors; those relying on a plain camera image are considerably weaker.

Where is my fingerprint stored?

As a mathematical template in a secure processor on the device, not as an image and not, in mainstream implementations, on a server. The main operating system cannot read it.

Data & Privacybiometricsauthenticationsecuritylaw
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas