HN Hall of Fame Weekly email

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com Essays & writing Essays & articles Security & privacy Class of 2016-04 Hall of Fame
Screenshot of blog.dustinkirkland.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 5 calendar years, with breakout response in 4 of them.

submissions
6
submitters
6
observed span
2013–2017
peak thread · 255 comments
587 pts
latest 20+ return · 2017-09-15
264 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake fingerprint, and then they'd have to enter…

gfodor·587-point thread·

Fingerprints are not passwords, but I don't think it's useful to think of them as usernames either. This is a much more pragmatic take on it by Troy Hunt, the person behind “Have I been pwned?”: https://www.troyhunt.com/face-id-touch-id-pins-no-id-and-pra... > The first point I'll make here as I begin talking about the 3 main security constructs available is that they're all differently secure.

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedicated spy agencies, a fingerprint login strikes a very good balance between usability and…

This article has been discussed in the past (about 2 years ago). https://news.ycombinator.com/item?id=6477505 I think that fingerprints are fine for low security things, but I would never use it as authentication for anything that touches my bank account.

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
4

100+ points or 50+ comments

Total points
1262

reference only — not used in Hall rules or ranking

Total comments
548

reference only — not used in Hall rules or ranking

Every submission

DateTitle as submittedByPointsComments
2013-10-01Fingerprints are Usernames, not PasswordsFirst breakout · Best threadjcastro587255
2014-10-23Fingerprints Are Usernames, Not Passwords (2013)sc90219102
2015-08-31Fingerprints are Usernames, not Passwords (2013)Jonhoo40
2016-03-14Fingerprints are Usernames not Passwordstosh44
2016-04-22Fingerprints are Usernames, not Passwords (2013)Hall inductionvincent_s18463
2017-09-15Fingerprints are usernames, not passwords (2013)Latest 20+ point returnl1n264124