Exchanging mugshots to make crypto passwords

recursive PDAA Romanian computer scientist has come up with a new way to generate secure communications pairing between devices like PDAs: get their owners to take photos of one another, and use the biometrics of their faces to generate the password. [image by James Jordan]

The PDA compares the two photos and generates a security code for making a safe connection. The users can then use this connection to exchange confidential information. The photos are stored as a template that contains the essential features for recognition.

I haven’t read the full paper, but it strikes me that there’s an obvious flaw here – in that anyone stealing one of the two devices can use the pre-generated connection key, meaning it’s still only as secure as whatever password or locking system its owner has installed on it (clever crypto types, please feel free to explain why I’m wrong about that). But even so, an interesting proof-of-concept.

Unbreakable quantum crypto! Or, er… not.

Another frustration of science news-following – the contradictory stories. According to the BBC, a conference in Vienna saw the launch of “the world’s first computer network protected by unbreakable quantum encryption. [Hat tip to Darren ‘Orbit’ Turpin]

Meanwhile, at Trondheim in Norway, another researcher has discovered that quantum cryptography can be hijacked by shining a bright light into the equipment. Someone sort these people out with an RSS reader!