Home Reviews About
Twenty of Time

Biometric Authentication Is a Risky Choice for Everyday Devices

Fingerprint scanners on phones, face unlock on laptops, voice verification at call centres: the modern Australian routinely hands over a piece of their body to a corporate server just to check a balance or read a message. The trade feels harmless because the gesture itself takes less than a second. What lingers afterwards is something far more durable than a password, and far harder to revoke.

The pitch from device manufacturers has been remarkably consistent for the past decade. Biometric checks are framed as a frictionless upgrade to the old password routine, supposedly safer because they cannot be guessed. The reality is messier. Your face, fingerprint, voice and iris patterns are biological identifiers that, once exposed, cannot be reissued. A compromised password can be changed on a Monday morning. A compromised fingerprint is yours for life.

This piece walks through why convenience-driven authentication deserves a second look. It examines the technical weaknesses, the regulatory gaps that leave Australians exposed, the commercial appetite for harvesting such data, and the practical alternatives that work without surrendering a piece of who you are.

The Illusion of Seamless Security

Biometric systems feel modern because they replace effort with presence. Lift the phone, glance at it, and a secure enclave inside the hardware checks a mathematical template against a stored one. The marketing around this workflow suggests that anything simpler must be safer. In practice, the opposite is often true.

A fingerprint can be lifted from a glass you touched at a Melbourne café, then printed onto a silicone sheet and used against a phone sensor within minutes. Researchers at universities in Tokyo and Tsinghua have repeatedly demonstrated such spoofing, and the demonstration kits cost less than a takeaway dinner in Brisbane. Face matching can be fooled by a high-resolution photograph held at the right angle, and voice prompts by a synthesised sample pulled from a social media clip.

The hardware companies know this. That is why premium devices ship with infrared dot projectors, depth sensors and liveness detection. Yet millions of mid-range handsets sold across Australia still rely on a single camera and a software comparison. The security gap between a flagship model and a budget device is enormous, and most consumers do not realise which side of that gap they sit on.

When Your Face Becomes a Leaked Dataset

Even when the hardware resists spoofing, the software behind it rarely keeps your template local. Many vendors upload the reference template to their cloud for synchronisation across devices, and that synchronisation is where exposure begins. A breach at a biometric vendor is qualitatively different from a breach of passwords. Password dumps can be rotated. A template leak of fifty million faces cannot.

Australia felt this acutely when major companies reported incidents in recent years. The Office of the Australian Information Commissioner has logged a steady rise in notifications under the Notifiable Data Breaches scheme, and a growing share involve biometric or behavioural identifiers. The number remains small in raw terms, but the trajectory is the worry. A single leaked template can be cross-referenced with footage from CCTV in Sydney's CBD, from passport control at airports, from any public camera that captures your features in passing.

There is also the question of secondary use. A template stored for phone unlock can quietly serve as a training set for a vendor's facial analysis product. The user never consented to that purpose, and the terms of service usually bury the allowance under language no reasonable reader would parse. If you want a closer look at the way seemingly harmless software leaks identity markers, the analysis of browser extension exposure walks through similar territory.

Australia's Patchwork of Privacy Protections

Australian privacy law has moved, but it has not caught up with the deployment curve. The Privacy Act 1988 treats biometric information as a subset of personal information, which means it inherits the same protections as a phone number or a postal address. The Australian Privacy Principles require organisations to handle it with care, yet they do not impose the heightened safeguards a unique, irrevocable identifier deserves.

The Office of the Australian Information Commissioner can investigate complaints and issue determinations, and the regime does carry penalties. Compared with the European Union's GDPR treatment of biometric data as a special category requiring explicit consent, the Australian framework feels lighter. A bank in Perth can collect a voiceprint for telephone verification with a single click-through, and the customer has limited practical recourse to refuse without losing access to services.

Some sectors have begun tightening their own rules. The Australian Signals Directorate, through the Essential Eight maturity model, now recommends multi-factor authentication for federal entities, with hardware tokens rated more strongly than biometric factors. State governments in Victoria and New South Wales have trialled biometric identity checks for services, then walked them back after community pushback. The pattern suggests Australians are wary when asked, but the default offered to them by consumer technology remains biometric.

How Biometric Data Flows to Brokers

The technical case against biometrics would matter less if the commercial ecosystem treated the data with restraint. It does not. Adtech firms, data brokers and analytics platforms have a long history of buying, selling and matching identifiers that were collected for narrow purposes. Biometric templates are simply the newest, most valuable addition to the inventory.

Once a face vector exists inside a vendor's infrastructure, it can be matched against social media images, against loyalty programme photos, against images scraped from public sources. The result is a profile that follows a person across devices and contexts. Australia has no comprehensive federal regime that mirrors the European right to be forgotten, and the accreditation of data brokers by the Australian Competition and Consumer Commission has focused more on consumer protection than on identity protection.

Even where the broker claims anonymisation, research has repeatedly shown that biometric templates are notoriously difficult to anonymise because the underlying features are themselves identifying. A 2023 analysis of several large leaks found that re-identification of individuals from supposedly scrubbed templates was possible in over 80 per cent of cases. The promise of privacy through obscurity collapses when the identifier is your skeleton.

Practical Replacements Worth Considering

Replacing biometric authentication does not mean reverting to the chaos of fifteen forgotten passwords. The category of solutions worth considering relies on something you have, not something you are. Hardware security keys plugged into a USB port or tapped via NFC now support most major services, including banks operating in Australia, and they cannot be phished, guessed or spoofed from a distance.

For accounts that demand a software factor, a long passphrase stored in a reputable password manager offers far better security than a fingerprint prompt. The manager locks behind a master passphrase you can actually remember, then fills in unique, generated strings for every other service. If you travel between Sydney and Adelaide and log into hotel wifi along the way, the risk surface shrinks considerably when each site gets a different password by default.

Two-factor authentication through authenticator apps, or through short codes sent to a separate SIM, rounds out a layered approach. None of these tools rely on a part of your body, which means none of them create a permanent record that outlives a breach. They also cost less than a single morning coffee per year, which makes them realistic for households juggling multiple devices.

Shifting the Way You Think About Identity

The deeper problem with biometric authentication is philosophical. Every time a system asks for your fingerprint or your face, it trains a generation of users to treat their own bodies as credentials. That framing has consequences beyond security. It normalises the idea that access to a phone, a bank account or a government service is conditional on surrendering something irreducibly personal.

Australians have shown, through consistent polling and through the backlashes against myGov ID expansions and Centrelink verification trials, that they notice when the line moves. The conversations at kitchen tables in Fremantle and Townsville sound similar: people want to know where the template goes, who can request it, and how it gets deleted when the relationship ends. These are fair questions, and they deserve explicit answers rather than a settings menu buried three layers deep.

Adopting alternatives does require a small recalibration of habits. Carrying a hardware key, typing a passphrase, opening an authenticator app: each step adds seconds. Those seconds, multiplied across a year, are still cheaper than the hours a person spends untangling the fallout of identity theft. The trade is real, and for most everyday devices, it favours the slower path.

The takeaway worth holding onto is this. Biometric systems sell convenience by borrowing against a resource you cannot replenish. Passwords, passphrases and physical tokens borrow only against your memory and your pocket, both of which you control. Choose the credential you can revoke, and treat your face, your fingerprint and your voice as private material that does not need to leave the device it sits on.

When the next phone, laptop or bank app asks for a thumb on the sensor, pause for a moment. Read the settings menu, look for a fallback, and weigh the cost of giving away a permanent identifier against the few seconds saved. The decision compounds. Small refusals, repeated across thousands of interactions, build a buffer that a single breach cannot drain. For deeper reading on the habits that hold this together, the brain food archive collects essays on the wider practice of digital self-respect.