Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My ideal solution for an ultimate reset/unlock solution would be to show up and have my DNA sampled. Impossible for me to lose the reset key there, and with appropriate DNA extraction procedures, it is nearly impossible to spoof.


The issue with using permanent characteristics for auth is that you lose the ability to revoke one credential in favor of another.


That's not a problem if you have to physically show up though, since no one can spoof that.


As another person said, you're literally leaving it everywhere you go.

If you need a blood sample, then would donating blood be considered compromising security?

Identity is what your DNA is. Password is a secret. Your DNA is not a secret.


I think requiring you to be physically present and having a human take the sample in a prescribed manner serves as an effective 'password' - unless it's a live sample, the DNA is useless.


The movie Gattaca showed in detail how routine spoofing of a variety of IRL DNA samples could work.


I think there's a misunderstanding of what is possible with DNA[0]. We take DNA from dead stuff all the time.

I will agree with "you have to be physically present" is good enough password. This is Yubikey, which works fantastic. The problem with DNA is when it is compromised - you can't throw it away/change it without exorbant effort (bone marrow transplant? and then you're simply taking on someone else's identity? is that identity theft?).

[0] https://www.quora.com/Do-we-require-live-cells-when-extracti...


I think people are misunderstanding what is being suggested here. The idea is that, for example, to unlock your bank account, you have to go to the bank where trusted bank employees will extract your DNA and have it sequenced, resulting in you being given access again. Others cannot spoof being you in this scenario because they cannot implant your DNA in themselves.


Ah you're right. I've re-read it and it is physically present someone verifying you using your DNA.

Which I agree, that works great, but quite narrow in the the use cases at that point.


Consider if you're kidnapped and extracted DNA in unwilling manner


I've built something around it. It's not 100% but gets you to 99%. Dontport.com


I'd be curious to know what the 11 potential tests are. Your website doesn't seem to list them anywhere.


That's exactly what they did in the movie Gattica- it's hard but seems totally possible. I'd rather have multiple revokable keys.


Your DNA can show up all over the place.


>with appropriate DNA extraction procedures

Carriers have already demonstrated their complete across the board failure to have appropriate security procedures. Your DNA isn't hard to find, you leave it literally everywhere you go.

And do you really want mobile carriers creating a DNA database of their every customer? The same companies that already sell your location data to bounty hunters?

That's going to be a big no thank you from me.


While I basically agree, why do you think they'd need your actual DNA? Wouldn't it be hashed?


Consider identical twins, mothers, and organ donation or blood transfusion recipients.


This is where countries like India are going with Biometric Auth plus 2FA (though the implementation has issues). The government provides a public API for sending fingerprint or Iris scan data plus SMS 2FA to authenticate identity with a cost.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: