From: planet biometrics
The European Union Agency for Network and Information Security (ENISA) has launched a new survey that pours cold water on the concept of using biometrics in eFinance and ePayment systems.
ENISA is a centre of network and information security expertise for the EU, its member states, the private sector and Europe’s citizens. It works with these groups to develop advice and recommendations on good practice in information security.
The results of the survey show that very few professionals incorporate biometrics as an eIDA method solution for e-banking. According to ENISA, the rationale behind this phenomenon is that institutions must be able to comply with the General Data Protection Regulation (GDPR – a new Regulation about personal data Protection, which is expected to be applicable to all sectors, and expected to be approved by the European Parliament in 2014).
According to the report, there are high associated risks to using biometrics – mainly due to the potential of attacks to a centralised data base storage of biometrics parameters. The risk of compromise of the biometric information DB (even if it’s encrypted, hashed, etc.) is real and non-acceptable for CISOs and directors of the e-banking sector, says ENISA.
Another important factor is usability, since current technologies do not provide 100% accuracy. ENISA says there are still issues related to the False Rejection Rate (FRR) and the False Acceptance Rate (FAR), which remain open even in scientific experiments or proof of concepts.
Leave a Reply