The Biometric Promise

Biometric authentication — fingerprints, face scans, iris recognition, voice prints — offers undeniable convenience. No passwords to remember, no tokens to carry. Your body IS the key.

But biometrics carry fundamental risks that passwords don't. Understanding these risks is essential for making informed security decisions.

Key Risks

Irrevocability: If your password is compromised, you change it. If your fingerprint is compromised, you can't change your fingerprint. Biometric data, once stolen, is compromised forever.

Spoofing: Fingerprints have been successfully cloned from photographs, high-resolution scans, and even residue left on surfaces. Face recognition has been defeated by photographs, 3D-printed masks, and even siblings.

Legal requests: Rules about compelled device unlocking depend on jurisdiction, facts and current case law. Do not assume a password can never be compelled or that biometrics always receive different treatment. Seek qualified legal advice for an actual request.

Environmental Failures: Wet, dirty, or injured fingers can fail fingerprint recognition. Masks, sunglasses, and lighting conditions can defeat face recognition. These failures often come at the worst possible time.

Database Breaches: When a service stores your biometric template and that database is breached, your biometric data is exposed permanently. Unlike passwords, you cannot rotate your fingerprints.

Best Practices

Biometrics are best used as a convenience layer, not a security layer:

Use biometrics for device unlock, but keep a strong PIN/password as backup • Don't use biometrics as the sole authentication for high-security accounts • Prefer on-device biometric processing (Apple's Secure Enclave, Android's StrongBox) over server-side biometric storage • Understand the legal implications in your jurisdiction regarding biometric compulsion • Combine biometrics with passwords for multi-factor authentication — biometrics as "something you are" plus password as "something you know"

For ZeroLatch, distinguish account sign-in from the delivery’s recovery mode. Simple allows authorised service-managed key recovery. Private requires a separate password or ZeroLatch phrase. Neither arrangement makes an infected device or compromised inbox safe.