Can't you change your fingerprint by making a small cut on it with a knife?

I disagree. Fingerprints have large entropy and are hashed by the firmware.

The right analogy is that they are equivalent to an unprotected security key (yubikey) that is on a string around your neck for everyone to see.

I can snoop a friend's phone if I know his pass code but I really can't easily do much if he only uses a fingerprint.

Reply to this note

Please Login to reply.

Discussion

On the yubikey analogy, you forget one important detail: you leave copies of your fingerprints (good enough to unlock your phone) on everything that you touch, everywhere you go - doors, door handles, cutlery, cups and bottles, furniture, stationery, push-buttons and so on. That's not the case with a yubikey, which is by design protected against cloning, unintentional as well as deliberate.

Also, fingerprints can be covertly photographed using a fairly basic camera, while the yubikey content, once again, is locked inside a secure chip inside the device.

So, if your friend uses a fingerprint only, you can take a few photos of the friend's fingers, or just take him to lunch.

You don't need to take my word for any of this - just give it an honest try. During a normal weekday, monitor the times you have left a fingerprint in a place where it can be easily retrieved by a stalker. You'll be surprised.

And I hope you were joking about the small cut :) Wouldn't suggest you give THAT an honest try.