From face image to disposable face tokens
A vendor-neutral map placing any face verifier between an unaltered capture and a sealed token, then asking what a breach of each store hands an attacker.
Seven papers for identity architects, security reviewers, privacy counsel and recovery teams. Each examines one question and provides claims you can test against a real deployment.
Explore the library7 of 7 entries
A vendor-neutral map placing any face verifier between an unaltered capture and a sealed token, then asking what a breach of each store hands an attacker.
A passkey assertion proves that some unlocked device signed; the person is inferred. How one ceremony keeps possession intact and adds a verified person.
A face outlives everything, so a recording of it is always worth keeping. Where the quantum-safe property of the face token applies, and where it stops.
Support calls are where an authentication program is routed around. Why training cannot close the gap, and how a backchannel check replaces the interview.
Enrollment, not cryptography, sets the schedule. Tokens minted in bulk from existing images; a joiner, mover and leaver lifecycle tied to the directory.
For reviewers: what a total database loss yields, why there is no OP-side session, enumeration resistance, and the limit beside every claim.
How a deployment with no face images admits its first users, through a provisioned shell or domain-gated signup, and how little a first-use hijack is worth.