← Back to list

When Your Body Becomes a Password

The body was never a password. It was always a crime scene, a weapon, a database, and a koala. Biometrics just forgot to read the fine…

Darwin Gosal · 2026-04-02 10:24 · 0 claps · 35.9 min read paywalled
#biometrics #digital-identity #cybersecurity #privacy-rights #surveillance-capitalism
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

When Your Body Becomes a Password

The body was never a password. It was always a crime scene, a weapon, a database, and a koala. Biometrics just forgot to read the fine print.

For most of us, biometrics enters life in a small, polished gesture. A thumb rests on glass. A face tilts toward a screen. A gate opens. A bank app unlocks. The machine recognises us, and for a brief moment, the future seems to have arrived in the most agreeable possible form: no password to remember, no token to carry, no tedious ritual of proving that we are ourselves.

It is an intoxicating idea. Why rely on something as flimsy as a password when the body itself can serve as proof? Passwords can be forgotten. Cards can be lost. OTPs can be intercepted. But your face is with you. Your fingerprint is with you. Your eyes, your voice, your stride, your heartbeat — these seem harder to misplace, and more obstinately, uncomfortably, authentically you.

And so the logic of biometrics has always carried a certain seduction. It promises a kind of elegant shortcut through the chaos of modern identity. It tells us the body can do what memory cannot. It offers the fantasy that who you are might be measured directly, rather than mediated through knowledge, paperwork, or the quiet, daily humiliation of trying to remember whether your password was “Fluffy2019” or “Fluffy2019!

The deeper one goes into the subject, however, the stranger it becomes. Much stranger. Strange enough, in fact, that one begins to suspect the field has a secret personality — that behind its sober technical conferences and sensor specifications and fractions-of-a-percent accuracy claims, biometrics is the most inadvertently philosophical corner of all of engineering. It is a discipline that periodically falls down the stairs and lands in something important.

The stairs in question are remarkably well-populated with incident.

I. The Menagerie

Let us begin with a brief tour of the biometric zoo, because the sheer variety of what has been seriously proposed, rigorously tested, and in some cases commercially deployed as a means of identifying a human being is its own kind of argument. Not an argument against the field — just a recurring reminder that the field has opinions about the body that the body does not necessarily share.

Broadly, biometrics falls into three families. Anatomical biometrics captures the visible architecture of the body: fingerprints, faces, irises, ear shapes, lip prints, the geometry of the hand. Physiological biometrics goes deeper, sensing internal structures and signals: vein patterns, DNA, heartbeat waveforms, thermal signatures. And behavioural biometrics identifies not what you are, but how you move through the world — your voice, your gait, your signature, the rhythm of your typing, the way you hold a phone.

This taxonomy sounds orderly, almost elegant. It is the kind of taxonomy that implies everything is under control. It is, in this respect, misleading.

Because within each family there are entries that expand the definition of “practical biometric” beyond what most people would consider optimal. Ear shape recognition, for example, is a legitimate field — IEEE published a study in 2007 achieving 97.8% rank-one recognition using 3D ear geometry alone, and the ear has the appealing property of remaining stable from age 8 to about 70, while the face continues quietly rearranging itself. The ear also does not change after cosmetic surgery, which has delighted forensic researchers and almost certainly nobody else.

Then there is tongue print recognition, which emerged from Hong Kong Polytechnic University in 2009 and which has a compelling property that no other biometric can claim: the tongue’s involuntary squirm during protrusion makes it simultaneously static and dynamic, a biometric that contains its own liveness test, because — and this is the sort of sentence that looks strange in a peer-reviewed paper — nobody can reasonably stick out your tongue except you, and a corpse absolutely cannot do it. Pattern Recognition published this in perfect seriousness, which is one of the things about academia that one has to admire.

Lip prints — cheiloscopy — have been a going concern since Edmond Locard proposed them in 1932, which means they have been seriously studied for longer than computer science has existed, and one suspects Locard would be surprised to learn his legacy is mostly confined to Poland, the last country that still admits lip print evidence in court with any regularity. A 2017 forensic science study found that expert agreement on lip print classification had a kappa value of roughly 0.15 to 0.25 — “poor to fair,” in the study’s diplomatic language, which is the statistical equivalent of experts reliably disagreeing with each other while maintaining straight faces. The identical twins, at least, have different lip prints, which is the one bullet point in the field’s favour.

Body odour biometrics also exists — the human olfactory signature is chemically distinct and surprisingly stable — and while the authors of relevant papers write about it with full scientific sobriety, the reader cannot help imagining the deployment context with a mixture of fascination and alarm. There are also fingerprints of the knuckle, knuckle print identification being a well-established subfield since a 1989 forensic paper, with modern deep learning systems now achieving 98.6% accuracy. The University of Dundee recently launched a citizen science app called Knuckle Down ID, inviting the public to anonymously photograph their knuckles to help police match suspects from crime scene footage showing only hands. One imagines the focus group meeting that named this app went quite smoothly.

And then, occasionally, someone publishes a paper called “The Nipple-Areola Complex for Criminal Identification.”

Researchers at Nanyang Technological University did exactly this in 2019, constructing the NTU-Nipple-v1 dataset of 2,732 images and training a U-Net segmentation algorithm called, with complete architectural inevitability, **DeepNipple**. The forensic motivation was real and serious: perpetrators of sexual crimes against children often obscure their faces and tattoos but leave their chests visible, and nipple-areola patterns are genuinely distinctive. The paper was peer-reviewed, the dataset was curated, the algorithm was tested. It won no prizes for the most reassuring citation in a corporate background check, but it was not being proposed for that purpose. Biometrics, like pathology, does its most important work in situations most people would prefer not to think about.

Still. DeepNipple. One takes a moment.

II. The Gummy Bears That Changed Everything

The great seduction of fingerprints is their apparent inevitability. We leave them everywhere. They are free to collect, cheap to scan, socially acceptable in a way that nipple recognition currently is not, and so deeply embedded in popular culture — crime novels, police procedurals, airport kiosks — that they have acquired the feeling of truth. The fingerprint feels like bedrock.

In 2002, a Japanese cryptographer named Tsutomu Matsumoto bought roughly ten dollars of materials from a hobby shop and undermined that bedrock in an afternoon.

Matsumoto was a mathematician, not a professional fake-finger scientist. What he discovered was that gelatin — the same substance used to give gummy bears their particular textural philosophy — when poured into a mould of a real fingerprint, produced a flexible fake finger that defeated eleven commercially available fingerprint scanners at an eighty percent success rate. The fingerprint moulds could be made from a live finger pressed into hobby-shop plastic, or from a latent print lifted off a glass with superglue fumes, photographed, printed onto a transparency, and etched into a copper PCB mould before casting. The resulting transparent gelatin finger could be worn over a real finger, so that guards watching the sensor would see a human digit apparently being placed on the sensor. The evidence, when finished, could be eaten.

Bruce Schneier noted in his newsletter: “He’s a mathematician, not a professional fake-finger scientist. He used $10 of ingredients you could buy, and whipped up his gummy fingers in the equivalent of a home kitchen.” The field has never entirely recovered from this observation.

Matsumoto’s paper was published in 2002. By 2008, the Chaos Computer Club’s Jan Krissler — a man who operates under the alias “Starbug” with the confidence of someone who has fully committed to the bit — had obtained German Interior Minister Wolfgang Schäuble’s fingerprint from a water glass at a public event, lifted it with superglue fumes, and published it in the CCC’s magazine Die Datenschleuder along with a ready-to-use transparent film that readers could press onto their own fingers to impersonate the minister at biometric readers across Germany. The magazine’s print run was four thousand copies. The stunt was in protest of Germany’s introduction of biometric passports. The irony was not lost on anyone.

Six years later, Krissler returned to the Chaos Communication Congress stage to announce that he had now reconstructed Defense Minister Ursula von der Leyen’s thumbprint using only press photographs taken from roughly three metres away with a standard 200mm camera lens, combined from multiple angles using VeriFinger software. No physical contact required. The minister need never have been within touching distance. The fingerprint, in other words, had been stolen from a photograph taken at a public event, as efficiently as a pickpocket lifts a wallet, except the victim didn’t feel a thing and couldn’t ask for it back. He also demonstrated, at the same congress, that Samsung’s Galaxy S8 iris scanner could be bypassed using an eye photograph printed on paper with a contact lens laid on top — unlocking the phone instantly every time.

This was a demonstration of something the field prefers not to dwell on. A password is a secret you keep. A fingerprint is a secret you leave on every surface you’ve ever touched — on glasses, door handles, polished tables, elevator buttons, and, as Japanese researcher Isao Echizen announced in 2017, on your own fingertips as they flash across a selfie at up to three metres away. Echizen demonstrated that the V-sign — the peace sign, the ubiquitous East Asian photo pose — provides enough fingerprint detail to reconstruct a usable copy. “Just by casually making a peace sign in front of a camera,” he told reporters, “fingerprints can become widely available.” Billions of peace-sign selfies have been posted to social media. Echizen developed a transparent titanium oxide film that can hide fingerprints while preserving scanner compatibility. It is not yet commercially available, because life is structured this way.

III. The Things You Leave Behind You

The problem with fingerprints as a secret is thus established. The problem with faces is different, and in some ways worse.

Faces are not secrets at all. A face is a public broadcast — constant, unavoidable, streaming at every angle into every CCTV system in every city in the world, paused at airports, catalogued by app developers, scraped from social media profiles, indexed by companies no one has heard of, and matched against databases whose existence is rarely announced before they’re needed.

Clearview AI, when it was exposed by a journalist in 2020, had assembled 3 billion scraped facial images from the open internet. By 2025 that number had grown past 60 billion. A BuzzFeed News investigation found that 7,000 individuals from nearly 2,000 public agencies had used the platform, including the NYPD, which had conducted over 11,000 searches. Officers had used it to investigate protesters, to look up Capitol insurrectionists, and — less officially — to search for friends, family members, and possibly ex-partners. The company settled a class action lawsuit in 2025, but the settlement was creative: Clearview, which lacked liquid assets, gave class members a 23% equity stake in the company itself. The people whose faces were scraped now own a piece of the enterprise that scraped them. This is either poetic justice or something more cynical than poetry usually handles.

The ACLU, for its part, ran its own experiment in 2018. It built a database of 25,000 publicly available mugshots, ran it through Amazon’s Rekognition service using Amazon’s own default settings, and compared it against photographs of every sitting member of Congress. Total cost: twelve dollars and thirty-three cents. Twenty-eight legislators were falsely matched to criminal mugshots, including civil rights icon John Lewis. Nearly 40% of the false matches were people of colour, who made up only 20% of Congress. Amazon’s response was that the ACLU should have used a 99% confidence threshold instead of the 80% default. The ACLU’s response to that response was, roughly, that Amazon had set the default.

The deployment of facial recognition in the real world has produced results ranging from the embarrassing to the genuinely devastating. In the Chinese city of Ningbo in 2018, a traffic camera designed to identify and publicly shame jaywalkers displayed Dong Mingzhu — chairwoman of Gree Electric, known as China’s “Queen of Air Conditioning” — on a wall-mounted shame screen, complete with name and partial government ID number. The camera had mistaken her face on a passing bus advertisement for an actual pedestrian. The algorithm, in a technical sense, had been perfectly correct: there was a face there. It had simply not paused to consider whether the face was doing any walking.

In Detroit in 2020, a man named Robert Williams was arrested in his driveway in front of his wife and daughters, aged two and five, for allegedly stealing luxury watches from a Shinola store. He had been flagged as only the ninth-best match by the facial recognition software. An investigator confirmed the match by watching grainy footage — without being present during the theft. During his interrogation, Williams held the suspect’s photo next to his own face and told the detective: “This is not me. I hope y’all don’t think all Black people look alike.” The detective replied: “The computer says it’s you.” Williams had been 24 miles away at the time of the theft, driving home from work, and had posted a Facebook Live video of the commute. He was held for 30 hours. He later settled with the city for $300,000 — a number that represents, among other things, the going rate for 30 hours in jail on the word of a confidence interval.

Williams was not alone. At least seven wrongful arrests in the United States have been attributed to facial recognition errors, and in nearly every case the wrongfully arrested person was Black. Porcha Woodruff, eight months pregnant, was arrested in Detroit for a carjacking. Nijeer Parks spent ten days in a New Jersey jail for a shoplifting he couldn’t have committed in a town he’d never visited and a car he couldn’t drive. Angela Lipps — a grandmother in Tennessee — spent more than five months in jail after Clearview AI linked her to bank fraud in North Dakota, a state she says she had never visited. She was released on Christmas Eve 2025. The algorithm, presumably, was not available for comment.

The Rite Aid case is its own chapter. From 2012 to 2020, the pharmacy chain deployed facial recognition in hundreds of stores, generating a watchlist of tens of thousands of suspected shoplifters. The FTC found that in one five-day period, over 900 separate alerts in 130-plus stores — from New York to Seattle — all claimed to match a single image in the database. Staff were instructed to “push for as many enrollments as possible.” Customers were followed, searched, called police on, and publicly accused in front of their families based on these matches. Eighty percent of Rite Aid stores were in majority-White areas; 60% of the stores using the technology were in majority non-White neighbourhoods, a distribution that was either a coincidence or a policy, and in either case not a flattering one. In December 2023, the FTC banned Rite Aid from using facial recognition for five years and ordered “algorithmic disgorgement” — the deletion of all collected data and every model trained on it. This is the regulatory equivalent of demanding someone not only return the stolen property but forget they took it.

And then there is Madison Square Garden, which decided to dispense with government intermediaries entirely. Since 2022, MSG Entertainment has used facial recognition to identify and bar lawyers from firms engaged in litigation against the company. Attorney Kelly Conlon — chaperoning her daughter’s Girl Scout troop to see the Rockettes at Radio City Music Hall — was identified by the cameras and escorted out before reaching her seat. Her firm was suing an MSG-owned restaurant; she herself was not even working on the case. MSG had scraped attorney headshots from law firm websites and built a real-time watchlist covering, potentially, the entire rosters of 90-plus firms. Owner James Dolan offered the following philosophical position: “If somebody sues you, that’s confrontational. If you’re being sued, you don’t have to welcome the person into your home.” An appeals court agreed. The face, in Dolan’s hands, had become a civil blacklist. No government warrant required. No public interest claimed. Just a database, a camera, and a private border drawn around a basketball arena.

IV. The Voice That Was Not Yours

Voice biometrics occupies a peculiar zone of false intimacy. A voice feels personal in a way that a fingerprint does not — we recognise people’s voices before we recognise much else about them, associate them with personality and presence, trust them in darkness when faces are invisible. Banking institutions have leaned on this intimacy heavily, deploying voice authentication as a frictionless alternative to PIN codes, on the reasonable assumption that it is difficult to sound exactly like someone else.

This assumption is being tested.

In 2024, a finance worker at UK engineering firm Arup joined a video conference call and authorised a wire transfer of $25 million. Every other participant on the call — including the company’s CFO — was an AI-generated deepfake. The employee had initially suspected a phishing attempt but the live video conference overcame his doubt. All those people, all those faces, all those familiar voices. All synthetic.

Sam Altman told the U.S. Federal Reserve in 2025 that AI has “fully defeated” voice authentication. “A thing that terrifies me,” he said, “is apparently there are still some financial institutions that will accept voiceprint as authentication.” Modern voice cloning requires as little as three to five seconds of sample audio — the length of a voicemail greeting, a social media clip, or a brief segment of a meeting recording. The intimacy of the voice, which made it feel like a reliable anchor to identity, turns out to have been the thing that made it so useful to steal: it is widely shared, publicly available, and apparently quite reproducible.

This does not mean voice biometrics is worthless. It means the window of assumption between “this is hard to fake” and “this is trivially fakeable” can close faster than security systems can respond — a pattern that appears repeatedly across the field, like a motif that has not been resolved.

V. The Clever Ones and What They Built in Their Garages

Somewhere between the gummy bears and the $25 million deepfake call lies a rich and somewhat alarming tradition of researchers who decided to determine, empirically, how secure biometric systems actually were, rather than how secure their manufacturers claimed.

The results have occasionally been spectacular.

In 2017, cybersecurity firm Bkav bypassed Apple’s Face ID within one week of the iPhone X’s launch using a composite mask: a 3D-printed frame, hand-sculpted silicone nose, and eyes printed on paper. Total material cost: approximately $150. Apple had designed Face ID to resist “Hollywood-level silicone masks” and claimed one-in-a-million false acceptance rates. Bkav’s vice president Ngo Tuan Anh said afterwards: “It was even simpler than we ourselves had thought.”

Journalist Thomas Brewster tested a £300 replica of his own head — created using 50 cameras in a dome, a technology developed for video game animation — against five consumer smartphones. The OnePlus 6 opened instantly, without any security warnings. Samsung and LG phones were also fooled. Only the iPhone X and Microsoft Windows Hello resisted, protected by infrared dot projection that 2D cameras cannot replicate. The lesson was sharp: the security of face recognition depends almost entirely on whether the hardware is doing real 3D mapping or simply looking at a picture, and many devices, including many being sold to millions of people, were doing the latter while marketing themselves as biometrically secure.

Carnegie Mellon’s CyLab went further in 2016, asking a subtler question: what if you didn’t want to impersonate one person, but wanted to become anyone the algorithm recognised? They created adversarial eyeglass frames — printed with specific pixel patterns on glossy photo paper using an ordinary inkjet printer at a cost of approximately twenty-two cents per pair — that defeated Face++ (used by Alibaba for payments) at 90% success rates. In tests, a white male researcher was identified as Milla Jovovich 87.87% of the time. A South Asian female researcher was misidentified as a Middle Eastern male. The glasses were shared with the TSA, which recommended passengers remove their glasses during screening, a recommendation that somewhat misses the point, since the glasses in question were designed to look unremarkable.

NYU Tandon researchers created **DeepMasterPrints** — GAN-generated synthetic fingerprints exploiting the fact that phone sensors only capture partial prints. At a 1% false match rate, a single DeepMasterPrint could spoof 77% of subjects. Earlier work by Nasir Memon showed that a dictionary of just five synthetic “master fingerprints” could match over 60% of unique subjects. These are, in effect, biometric skeleton keys. They won Best Paper at IEEE BTAS 2018, which is the most politely alarming way the academy has ever said “you should probably know about this.”

Tel Aviv University completed the set with nine synthetic “master faces” — AI-generated using StyleGAN and evolutionary optimisation — that could match 42 to 64% of identities across three leading face recognition systems. The master faces tended to be older white males without glasses or facial hair, reflecting the demographic composition of the training data, a finding with implications that go somewhat beyond algorithm design. A single generated face, not belonging to any human being, could unlock one in five identities in tested systems.

VI. The Butt, the Toilet, the Tongue, and Other Frontiers

We have now arrived at the portion of the essay where the reader who thought biometrics was a topic about phone unlock screens begins to understand what they have walked into.

Dr. Shigeomi Koshimizu at Tokyo’s Advanced Institute of Industrial Technology built a car seat embedded with 360 pressure sensors that maps the geometric pressure signature of the driver’s posterior across 39 dimensional features, achieving 98% accuracy in identifying specific individuals. The proposed application was anti-theft: only the registered driver could start the car. Koshimizu told the press, without any apparent awareness of how this would read: “Recognition tends to be compromised by different clothes — sensors read different signals from a pair of trousers and a pair of jeans.” He also suggested that office furniture makers could replace passwords with posterior scans.

This is the seat-biometrics version of a problem that runs through the whole field: a technically sound solution proposing to collect data that, in any other context, would be considered impolitely intimate. The car seat was supposed to reach market by 2014 and did not, which is perhaps the most predictable sentence in this essay.

The smart toilet takes this logic and carries it to its most perfectly absurd destination, which is also, and this needs to be said clearly, a genuine scientific paper from Stanford University published in Nature Biomedical Engineering in 2020. The system combines a urinalysis strip, a pressure sensor, a urine flow camera, and an anal-print scanner that analyses the “distinctive features” of the individual user. The anal scanner stores identifying data for up to ten users. The research motivation is sincere: continuous health monitoring for colorectal cancer markers, kidney function, and metabolic conditions requires knowing which biological material belongs to which household member when multiple people share a bathroom. This is a real engineering problem with real diagnostic stakes. The solution simply happens to involve a camera in the toilet bowl pointed at the anus.

The paper provoked the predictable mixture of mockery and sober commentary. The mockery, though, tends to dissolve when one sits with the logic: if continuous health surveillance is the goal, the toilet is actually the most natural collection point in the home. The absurdity is not in the goal but in the collision between the goal and the social meaning of the body part being scanned. Biometrics is frequently a story about what happens when measurement runs ahead of comfort.

There is, for completeness, the gut microbiome. A 2015 Harvard study in *PNAS* showed that gut microbiome profiles could uniquely identify over 80% of individuals up to a year later, without requiring any human DNA at all. A 2024 Stanford Medicine study tracking people over six years confirmed that individual-specific gut bacteria are paradoxically the most stable personal signal over time — more stable, in some dimensions, than fingerprints. Your bacteria are more reliably you than your fingerprints. This is either reassuring or profoundly unsettling, depending on your philosophical mood.

The microbiome also carries sensitive health information — sexually transmitted infections, mental health conditions, dietary patterns — meaning that a “biometric” identifier derived from your gut bacteria is simultaneously a credential and a dossier. The smart toilet, seen from this angle, is not the end of a line of absurdity but the beginning of a conversation about what happens when passive surveillance of bodily function becomes cheap, accurate, and continuous.

VII. The Pentagon’s Laser and the Holy Grail

The Department of Defense’s Combating Terrorism Technical Support Office funded a project called Jetson. Jetson uses a laser vibrometer to detect the unique mechanical signature of a person’s heartbeat through clothing, at a distance of up to 200 metres, with over 95% accuracy, requiring approximately 30 seconds of contact with a stationary target.

Unlike fingerprints or faces, cardiac signatures are essentially impossible to disguise, alter, or deliberately produce. The heart does not perform for the camera. It does what it does, regardless of whether the person wearing it knows they are being identified.

CTTSO’s Steward Remaly told MIT Technology Review, in what may be the field’s most casually enormous aside: “I don’t want to say you could do it from space, but longer ranges should be possible.”

Even without a pre-existing database, the system can re-identify someone by linking a figure seen at one location to the same cardiac signature detected later elsewhere. Separately, Wenyao Xu at SUNY Buffalo built a shorter-range radar-based cardiac sensor achieving 98% accuracy at 20 metres. The Pentagon’s version was specifically requested by Special Forces for use in the field.

The cardiac biometric is something genuinely new in the field’s history: an identifier the subject cannot physically resist, modify, or opt out of through any action short of cardiac surgery. You cannot disguise your gait convincingly, but you can try. You cannot scrub your face from public photos, but you can wear a mask. Fingerprints can even be temporarily dissolved by bromelain, the enzyme in pineapple juice, which South Malayan cannery workers discovered involuntarily in 1951 and which Nature duly reported as an industrial dermatitis study without apparently grasping they were also documenting a fingerprint countermeasure. The heart alone admits no such workaround.

This raises a natural question that the field has spent considerable effort trying to answer: if the body’s most reliable, most unforgeable signal is the one you cannot consciously control — is there a biometric that combines that permanence with the one property that traditional credentials have and the body does not? Namely, the ability to be changed if it falls into the wrong hands?

It turns out there is. And it requires reading your mind.

EEG-based authentication uses the unique patterns of neural electrical activity to identify individuals, achieving 95–99% accuracy in research conditions. But its truly singular property is this: the authentication signal is task-dependent. The user thinks about a specific image, phrase, or mental scenario to generate the pattern. If the template is ever compromised, the user simply switches to a different thought. Modern research has the sensors moving toward consumer-grade in-ear earbuds, slowly but credibly.

EEG also provides what security professionals call natural liveness detection. A brain under duress — held at gunpoint, compelled by a court order, present but uncooperating — cannot reproduce normal authentication patterns. Coercion becomes detectable in the signal itself. It is, in theory, the authentication method that cannot be extorted.

This is the holy grail the field has been circling: a biometric as unforgeable as a heartbeat, as privacy-preserving as a password, revocable like a credit card, and resistant to coercion by design. The fact that it requires electrodes and thirty seconds and is nowhere near mass deployment is, for now, beside the point. It is useful to know where the logic of biometrics ultimately leads — to the one credential that works precisely because it is not a body part, but a thought.

And then to look, with that ideal freshly in mind, at what is actually being deployed.

VIII. Two Kinds of Failure

Before we proceed, it is worth stepping back to name something that the parade of evidence makes easy to miss: the failures in this essay are not all the same kind of failure. They are, in fact, two completely different problems wearing the same general expression of embarrassment.

The first is a security failure. Gummy bears defeating fingerprint scanners. A $150 mask defeating Face ID. Twenty-two-cent glasses turning a researcher into Milla Jovovich. Nine AI-generated faces matching 40% of the population. These are cases where the biometric system was outsmarted — where a clever adversary found a cheaper, faster, more elegant path around the credential than the system’s designers anticipated. The implicit promise of biometrics — “this is harder to fake than a password” — turns out to be conditional, temporary, and in some cases laughably overstated. These failures are genuinely funny, in a deeply unsettling way. They reveal that the body, as a secret, leaks constantly and can be reproduced in a kitchen.

The second kind of failure is harder to laugh at, because it involves the system working exactly as designed.

This is an infrastructural failure — or more precisely, it is what happens when a functional system is pointed at a messy reality it was not built for, or handed to an institution whose interests do not align with the people it identifies. The Aadhaar system did not fail the 2.5 million Indian families who lost food rations. It authenticated them correctly: their worn-smooth fingertips genuinely did not match their enrolled templates. The system worked. The people starved. Clearview AI’s facial recognition almost certainly matched Angela Lipps correctly to some image in its database. The identification may have been technically accurate. The woman was innocent.

The distinction matters because the fixes are completely different. Security failures demand better sensors, liveness detection, adversarial training, multi-factor fusion. Infrastructural failures demand different questions entirely: Who controls the database? Who can compel its use? What happens when the system is accurate but the premise is unjust? One set of failures is an engineering problem. The other is a political one, and no amount of improved accuracy resolves it.

What follows is mostly about the second kind.

IX. The Body Fails Its Own Standards

Biometrics asks the body to be a reliable credential. The body, with characteristic indifference, declines.

Consider adermatoglyphia — the inherited genetic condition in which people are born without fingerprints at all. It was described by Swiss dermatologist Peter Itin in 2007 after four Swiss families presented with the same remarkable paperwork problem. He named it “immigration delay disease,” which is a medical term that somehow also functions as a comprehensive policy critique. In a world designed around fingerprint verification, these people are not curiosities; they are infrastructure failures. Their bodies declined to sign the specification document.

The body can also refuse the specification later in life, without warning. Capecitabine (sold as Xeloda) causes hand-foot syndrome in 50 to 60% of patients undergoing chemotherapy, which — among its other considerable cruelties — can erase fingerprints entirely. This turns out to be a problem not only medically, but geographically. In December 2008, a 62-year-old Singaporean man was detained for four hours at an American airport because immigration officers could find no fingerprints to scan. His oncologist subsequently published a “travel warning” in Annals of Oncologya paper whose existence represents one of the stranger moments in the history of medicine, being essentially a doctor’s letter to the field saying “please remember that your patients may need to enter countries.” A PMC review identified at least 20 affected oncology patients, some of whom never recovered their prints.

These two cases — born without fingerprints, or losing them to treatment — are joined by a third, which is structural: fingertip ridges fade significantly with age, and among people whose hands do physical work, they can become effectively unreadable. India’s Aadhaar system — the world’s largest biometric database, at 1.4 billion enrolled individuals — found that fingerprint authentication worked only about 95% of the time, because millions of adult Indians had fingertip ridges worn smooth by years of agricultural and industrial work. The system’s director had to add iris scanning as a fallback, which solved the authentication problem but created a different one: rural Indians queuing at welfare offices, submitting to iris scans in bright sunlight, having failed fingerprint verification, navigating a system designed for bodies it had not entirely anticipated.

Between September 2016 and June 2017, after Aadhaar was made mandatory in Rajasthan for food rations, at least 2.5 million families lost access due to authentication failures. Human Rights Watch and Amnesty International have documented cases where authentication failures contributed directly to starvation. Motilal Oram, an elderly woman in Jharkhand, was denied food rations and pension for the last 16 months of her life after her biometrics stopped being recognised. She died in July 2024. The system that couldn’t find her fingerprints kept her records intact. The database’s integrity was fine. The woman was not.

The chimera cases occupy a separate register of biological surrealism. In 2002, Lydia Fairchild of Washington State applied for government assistance and was required to submit DNA testing. The results showed she was not the genetic mother of her own children. Prosecutors considered fraud charges. A court-appointed observer witnessed the birth of her third child and took immediate DNA samples, which also showed she was not the mother. Her attorney, by some investigative miracle, located the case of Karen Keegan — a Boston woman recently described in the *New England Journal of Medicine* whose reproductive organs carried a completely different genome from her blood and cheek cells. Fairchild was a chimera: her DNA varied by organ. Her cheek — the standard swab site — and her reproductive system carried entirely different genetic identities. Both were her. Neither, by the database’s logic, was her.

Researchers now estimate that chimerism may be significantly more common than the roughly one hundred known cases suggest: a 2012 study found that 37 of 59 autopsied women harboured male Y-chromosome cells from prior pregnancies. The body, it turns out, routinely carries material from other bodies. This is not a biometric edge case. It is a fundamental property of biology that biometrics has been politely ignoring.

And then there are the koalas.

Koalas evolved fingerprints completely independently from primates — their last common ancestor with humans is somewhere north of 100 million years ago — producing whorls, loops, and arches virtually indistinguishable from human prints under a microscope. The finding was made by biological anthropologist Maciej Henneberg at the University of Adelaide in the mid-1990s, which means we have had roughly thirty years to contemplate the implications and have mostly chosen not to. A koala, touching a surface at a crime scene, would leave what any standard forensic database would classify as a human fingerprint. There is no documented case of this causing investigative confusion. There is also no documented case of anyone installing koala-detection in a fingerprint scanner. The assumption that fingerprints are human is foundational, unexamined, and — if you have ever met a koala near a crime scene — probably worth revisiting.

X. When the Weakest Link Becomes Your Finger

Security engineers use a concept called the “weakest link.” Any system is only as strong as its least secure component. For traditional authentication, the weakest link is usually social engineering, password reuse, or the kind of phishing email that arrives on a Friday afternoon. The advantage of this is that all of those attacks are non-violent.

Biometrics can change this equation.

In 2005 in Kuala Lumpur, accountant K. Kumaran had his Mercedes S-Class protected by a fingerprint immobiliser — the car would not start without biometric confirmation. Four men with machetes found this inconvenient. They forced Kumaran to press his finger on the sensor, bundled him into the back seat, and drove off. When they needed to restart the car later, they cut off the tip of his index finger and left him by the roadside. The car was worth approximately $75,000 locally, after import duties. The equation, from the attackers’ perspective, was straightforward: the credential was attached to the man, so the credential had to be detached from the man.

Brazilian ATM crime adopted similar logic when banks began requiring fingerprint verification for withdrawals. Several documented cases involved the severing of fingers at ATMs, forcing staff to modify their machines to require live fingerprints — which is to say, fingerprints attached to a person whose body temperature, pulse, and electrical conductance confirmed that the credential was still, at the moment of presentation, in use by the credential’s original owner.

One UK auditor named Kieran Higgins lost a fingertip to a crane accident in 2021 and later discovered that his Samsung Galaxy A20 still unlocked for his preserved severed fingertip sitting in a container. Consumer fingerprint sensors do not perform liveness detection. Dead tissue, separated from the body, remains biometrically valid. This is either a forensic curiosity or a business continuity concern, depending on your threat model.

In 2018, detectives investigating the death of Linus Phillip — an unarmed Black man shot by police in Florida — went to the funeral home and pressed his fingers against his smartphone while his fiancée, Victoria Armstrong, watched. The phone did not unlock: capacitive sensors require the slight electrical charge that circulates through living tissue. But the attempt was made, and the attempt was witnessed, and the attempt was, according to cybersecurity expert Joseph Steinberg, an example of a logic that deserves articulating clearly: “Granting police greater search rights if they first kill a person creates an unacceptable moral hazard.” The police’s response was presumably that the person was already dead. This is technically true and philosophically insufficient.

XI. The Fifth Amendment Wants a Word

For most of legal history, biometrics and the law maintained a relatively stable arrangement. Physical evidence — fingerprints at a crime scene, a DNA sample from a blood stain — could be collected and admitted. A suspect could be required to provide a handwriting sample, to walk in a lineup, to speak a specific phrase so a witness could identify the voice. These were acts of presentation, not disclosure of knowledge, and the Fifth Amendment’s protection against compelled self-incrimination had historically been read as applying only to testimony — things you know, not things you are.

The smartphone collapsed that distinction.

A fingerprint-protected phone is not merely a body part being presented to a sensor. It is the act of unlocking a device that contains potentially incriminating communications, documents, and photographs — the encrypted contents of a mind made portable. Is pressing a finger on a sensor an act of testimony? Is it closer to being compelled to hand over the key to a lockbox, or to being compelled to tell someone the combination?

On January 10, 2019, Magistrate Judge Kandis Westmore in Oakland, California denied a warrant seeking authority to compel any person found at a residence — not just suspects, not named individuals, anyone present — to press a finger, thumb, iris, or face to unlock any device found during the search. She wrote: “If a person cannot be compelled to provide a passcode because it is a testimonial communication, a person cannot be compelled to provide one’s finger, thumb, iris, face, or other biometric feature to unlock that same device.”

A circuit split now exists. The D.C. Circuit ruled in January 2025 — in a case arising from the Capitol breach — that compelling a fingerprint to unlock a phone violates the Fifth Amendment. The Ninth Circuit has gone the other way. The question that will eventually reach the Supreme Court is deceptively compact: is a fingerprint a key, or a confession? The answer will determine whether the body’s most commonplace biometric is closer, legally, to a piece of physical evidence or to the contents of a mind. And given that police can be compelled to justify access to the contents of a mind but not to a piece of evidence at a scene, the stakes are rather higher than they first appear.

XII. Russia Uses Facial Recognition to Conscript Men It Will Not Otherwise Find

The implications of biometrics at the state level are not always visible in individual cases. Sometimes they are visible in aggregate.

Moscow’s network of 125,000-plus cameras, combined with facial recognition, has been used against political dissenters for years. Activist Arina Yaroslavtseva was detained twice in a single day in different districts. After Russia’s 2022 mobilisation, the system was extended to track down men evading military conscription. When a conscript filed a court appeal, local offices flagged him as a “draft dodger,” triggering automatic detention by cameras in the metro. Men who were actively pursuing legal remedies were arrested on the basis of their faces during their commutes. The European Court of Human Rights ruled in Glukhin v. Russia in July 2024 that this violated the right to privacy and freedom of expression. Russia, which had left the Council of Europe in March 2022, found this ruling easy to disregard.

In the Rohingya crisis, UNHCR collected fingerprints, iris scans, and photographs from 1.2 million refugees in Bangladeshi camps and subsequently shared the biometric data with Myanmar’s military government — the same military that had conducted the genocide forcing them to flee. Human Rights Watch exposed this in 2021. Refugees who learned of the sharing went into hiding. A scholar observing the case remarked: “Targeted identification of persecuted populations to facilitate targeted killings has long been a tactic of genocidal regimes, only this time the data is digitised.” In Afghanistan, Western donor governments left behind biometric equipment and data, which the Taliban accessed after the 2021 withdrawal. The biometrics collected to identify collaborators who should receive aid became, in different hands, a list of people to be found.

The security promise of biometrics tends to be framed from the perspective of the individual authenticating to a system they trust. The civil liberties problem with biometrics tends to appear when that framing is reversed — when the body is being identified by a system the individual never chose to interact with, in service of an authority the individual has reason to fear.

XIII. The Permanence Problem

All of which brings us back to the gummy bear.

What made Matsumoto’s gelatin fingers so devastating was not merely the ease of construction. It was the implication. A stolen password can be reset. A fraudulently cloned credit card can be cancelled. The entire architecture of modern credential security rests on the assumption that a compromised secret can be retired and replaced. Biometrics snap that assumption like a dry twig.

In August 2015, hackers breached the United States Office of Personnel Management and exfiltrated 22.1 million records, including 5.6 million fingerprint records of federal employees and security clearance holders. FBI Director James Comey called it “a very big deal from a national security perspective.” The CIA withdrew officers from its Beijing embassy. Director of National Intelligence James Clapper, with unusual frankness, told a conference that “you have to kind of salute the Chinese for what they did.”

The OPM initially stated that “the ability to misuse fingerprint data is limited.” This statement was widely criticised. Not because the risk was immediate — but because it was permanent. After the Target breach in 2013, forty million credit cards were reissued within weeks. Cards can be cancelled and replaced because the relationship between a card number and an account is administrative. The relationship between a fingerprint and its owner is biological. It cannot be cancelled. It cannot be reissued. The 5.6 million fingerprints are out there, for use in any system that accepts them — including any future system that does not yet exist — for the indefinite future.

This is the hidden tax that runs through every story in this essay. The Chaos Computer Club can lift a politician’s fingerprint from a water glass and publish it to four thousand readers, and unlike a leaked password, there is no patch. Isao Echizen can reconstruct a fingerprint from a peace-sign selfie and issue a warning, and unlike a phished credential, there is nothing to rotate. Sam Altman can declare that AI has defeated voice authentication, and unlike a compromised PIN, no one can issue a new voice. The $25 million deepfake wire transfer will be studied, and security protocols will be tightened, but the voices used to build the synthetic CFO will remain in whatever training data captured them.

Security researcher Joseph Lorenzo Hall put the asymmetry plainly: “You only have 10 passwords — if you’re lucky to have all your fingers.” The BioStar 2 breach in 2019 exposed over one million unencrypted fingerprints stored as plaintext across 1.5 million locations globally. The data included police stations and banks. The fingerprints were stored not as encrypted hashes — as passwords are supposed to be — but as raw images, meaning they could be directly transplanted into spoofing attacks. The administrator usernames were “admin.” The passwords were “admin.”

Password hygiene is a tedious concept. Biometric hygiene has no widely accepted implementation, because the concept has not yet been fully invented.

XIV. The Doppelgänger, the Chimera, and the Transplant

The body, as a credential, has one additional complication that the engineering literature tends to underplay: it sometimes behaves as if it belongs to more than one person.

A 2022 study in Cell Reports by Manel Esteller at the University of Barcelona examined 32 pairs of unrelated human lookalikes — people who appeared strikingly similar but shared no family connection — photographed by Canadian artist François Brunelle as part of his “I’m Not a Look-Alike!” series. Using three facial recognition algorithms, 16 of the 32 pairs scored as “compatible” — the same classification given to identical twins. Genetic analysis revealed that nine of these 16 pairs shared significantly more genetic variants than chance would predict, particularly in genes controlling bone structure, skin pigmentation, and water retention. German researchers at Darmstadt separately confirmed that doppelgänger pairs yield “very high similarity scores resulting in a significant increase of false match rates.” We assume the face is unique because we experience it that way in daily life. The assumption may be statistically incorrect at scale.

The transplant cases go further. When surgeons at a Polish hospital transplanted a hand onto a 32-year-old man in 2006, using a hand from a brain-dead 43-year-old donor with a criminal record, they produced a person who now permanently carries the biometric identity of a deceased stranger. A forensic technician fingerprinted the transplanted hand nine times over 40 months. No significant changes. The recipient did not acquire the donor’s identity in any social, legal, or psychological sense. But his fingerprint is now permanently enrolled in Poland’s AFIS database under the donor’s name. UCLA’s transplant programme has since begun conducting extensive criminal background checks on donors specifically because the fingerprints transfer. There is currently no legal framework for what it means to carry another person’s biometric credential in your skin.

And then there is the most extreme version of fingerprint modification: the historical record of people who tried to destroy their own. John Dillinger paid $5,000 in 1934 for a surgeon to acid-burn his fingertips. The prints grew back, largely intact. Robert Phillips in 1941 grafted chest skin onto his fingertips; he was caught using the ridge patterns around the graft perimeter. A 2010 Detroit drug dealer had toe-print skin grafted onto his fingertips in Mexico; the result was permanently curled fingers that attracted more attention than they deflected. The fundamental irony is documented in forensic literature: deliberate mutilation attempts produce distinctive scarring that becomes a new identifying feature, often making subsequent identification easier. The body’s response to attempts at erasure is, characteristically, to become more distinctive.

XV. What Refusing to Fit Actually Means

We have come a long way from the thumb on glass.

We have visited the gummy bear that defeated eleven scanners, the $0.22 glasses that turned a researcher into Milla Jovovich, the laser that reads your heartbeat through your jacket at 200 metres, the toilet that knows who you are, and the man whose transplanted hand belongs to a criminal database. We have met a grandmother who spent five months in jail on the word of an algorithm, a woman whose DNA wouldn’t admit she was the mother of her own children, and a peace sign selfie being reverse-engineered from nine feet away. We have noted that koalas — who share our fingerprints through sheer evolutionary coincidence, having had no communication with us on the matter for 100 million years — could theoretically contaminate a crime scene, and that no one has updated the scanner to ask.

What these stories share is not absurdity, though absurdity is present. What they share is a recurring collision between two things: the body as it actually is — noisy, contingent, changeable, shared, legally contested, politically targeted, biologically obstinate — and the body as biometric systems need it to be: stable, unique, unforgeable, and above all, measurable.

The gap between those two versions of the body is the whole subject.

Biometrics is one of the most revealing technologies humans have built, because it fails in ways that expose assumptions. When the algorithm gets Robert Williams wrong, it is not simply making an accuracy error — it is revealing whose faces were represented in the training data. When 2.5 million Indian families lose access to food because their fingerprints are worn smooth, it is not simply a system failure — it is revealing that the system was designed in a context where bodies are not worn smooth. When the Rohingya refugees’ iris scans reach the hands of their persecutors, it is not a data management problem — it is a demonstration that a credential system is only as safe as the most dangerous person who might eventually hold the database.

These are not bugs in specific implementations. They are consequences of a structural choice: treating the body as infrastructure.

Infrastructure is neutral by design. It serves whoever operates it. The fingerprint that opens the welfare office unlocks the same door for the person hunting the welfare recipient. The face that clears customs is the same face that clears a surveillance dragnet. The heartbeat that proves you are not a spoof is the same heartbeat that announces you to a laser pointed at your chest from a building you can’t see.

The irreversibility that makes biometrics convenient — the fact that you cannot forget your face, lose your heartbeat, or misplace your DNA — is the same property that makes a breach permanent, a watchlist indelible, and a database, once created, immortal. You can change your password after a breach. The 5.6 million people in the OPM database cannot change their fingerprints. They are breached forever. The feature is the bug.

XVI. The Body Refuses

A thumb rests on glass. A gate opens. In that moment, everything seems elegant and modern and solved.

But somewhere in that moment, the field’s full inventory of complications is waiting. The koala that evolved our fingerprints independently and would like, it seems, no credit for the confusion it could cause. The transplant recipient carrying a stranger’s credential. The grandmother in Tennessee spending Christmas Eve in jail. The laser reading a heartbeat through a jacket on a street in Kabul. The gummy finger dissolved in a cup of tea. The toilet that knows. The brain that can, uniquely and beautifully, change its password. The Rohingya database, passed hand to hand.

The body is not, as it turns out, a clean primary key in any database. It is noisy, changeable, shared between chimeras and their children, worn smooth by honest labour, capable of impersonation by marsupials who did not ask for this responsibility, accessible to surgeons and lasers and $0.22 glasses, illegible to the fingerprint sensor at the airport when the chemo kicks in. It insists on remaining biological in a field that would prefer it to be more like a serial number.

This is not an argument against biometrics. It is the argument biometrics needs. The best deployments are those that have absorbed these complications rather than ignored them — that use biometrics for what it is actually good at, back it with fallbacks, design for edge cases, and treat accuracy rates as probabilities rather than promises.

The body is not a password. A password can be wrong. The body is something that stubbornly persists, changes, leaks, scars, grows old, surprises the algorithm, outruns the specification document, and ultimately refuses, with quiet biological authority, to be reduced to any single measurement of itself.

That refusal is not a flaw. It is the oldest security feature on the planet, and it has been in continuous development for rather longer than any of the systems currently trying to read it.


메타데이터
post_id
1d957f06cd88
slug
when-your-body-becomes-a-password-1d957f06cd88
url
https://medium.com/@darwingosal/when-your-body-becomes-a-password-1d957f06cd88
canonical_url
https://medium.com/@darwingosal/when-your-body-becomes-a-password-1d957f06cd88
author_url
https://medium.com/@darwingosal
status
ok
fetched_at
2026-07-11 13:37:47