Microsoft has aquired Digital Persona technology for their fingerprint sensor (keyboard & mouse), so It may be time to read this "old" review (posted before M$ even announce avaibility of it security device line) because it contains some comments you won't find elsewhere:
product name U are U, U.are.U
By Digitalpersona, Microsoft

{mosgoogle center}

Usage:

 You can create as many profile as needed, open a browser and go to the login page (Here I choose www.runryder.com as an example)


Put your finger on the sensor, the page do not exist in the keystore, so a page will popup. The title of internet page is use as key.

Enter the first credential, here the login and drag it to the right place in logon page. Repeat for all fields in page.
next time You go to that page, put your finger on the sensor and You're in!

 {mosgoogle center}

Bad:

  • Only working in Internet explorer, not working in any other browser: Opera or Mozilla 
    NEW: U.are.U is working in Firefox 1.0 but Microsoft fingerprint NOT 
  • Security by obscurity (which has be proven to be the worst strategy in history of cryptography): no mention to algorithm used, cipher strengths, no possible review of code. Would'nt it be good for customers, or sales to use clearly communicate on algorithm used?
  • Impossibility to do a backup of the keystore, web profiles... where is the repository of credentials? in windows SAM registry? If you lost your windows account (due to a crash or whatever), your only option is to use the small recovery utility provided, but you will have to remember your passphrase, and you have lost your web account profile.
  • Only working with Windows! Linux is gaining market share at the rate not seen before, why not opening some part to the community or developing a drivers?
  • In a browser, profile are depending on windows title -> clearly not enough if you have many credential on different pages which the same title. Maybe the software should use a variable html part of the content, url...
  • Dll mess, a lot of library are copied to windows/system32 but this is common under Windows...
  • Software version is 2.1, no update since 2002. I would like to see more options!
  • The manual do not give enough advices on how to increase security, which habits are bad, and basics security concepts.
  • Encrypting disk or directory is not possible: only files. You can right click on any file, choose encrypt

    and start encryption by putting one finger on the sensor:


    Decrypting is done by double clicking on a encrypted resource, and putting one finger on the sensor: EASY

{mosgoogle center}

Good:

  • Work perfectly with Windows, no problems with: lotus notes login, windows logon, web browsing...
    You are identifiedUnknow user
  • GUI for the average Joe user, nice and simple, very easy to use. Here the contextual menu:
  • Very fast regognition,
  • Fast Learning phase, in 5 minutes the device is working.
  • Nice design, the red color is a nice touch on your desk.
  • Price tags under 69$ in USA (but be careful it will cost You 270€ in Europe...)
  • Good integration in windows (here in system tray)

{mosgoogle center}

Conclusions/What I would like to see

  • Open source the code!!!!
  • Working with other browser, Mozilla has 18% of market now, all together alternate browser have less than 30% (see google geist here)
  • Use a know standard: PGP? for example (PGP disk for encrypting folder and partitions)
  • Name of algorithm used: Blowfish?, AES? and options to change cipher strength.
  • A file based keystore, a lot more easier for backup.
  • A linux version or plugin for Kwallet.

New What are the differences with the Microsoft version?

I've had the chance to see a Microsoft keyboard with the fingerprint reader in action, what a shame!!
  • Only basic functionnality are still in the driver.
  • No possibility to encrypt file with the device,
  • It is working ONLY in Internet explorer, not in Mozilla (Is it a surprise for You???).
  • Only "normal" windows are recognized by the system: no way to use  it under a terminal (rxvt - cygwin) where the digital persona just work.

I would stay away from the Microsoft version as long as they do not integrate new intersting capabilities. No need to mention that drivers are not compatible each other....

{mosgoogle center}

Overall

A product for geek, but due to lack of peer reviews on algorithms, it is certainly not a corporate device in any means. For example: why attacking the keystore if you can hook a backdoor to the activeX component in use? (should be easy to do with all Internet explorer issues...)

Links

This email address is being protected from spambots. You need JavaScript enabled to view it. sell them in usa at a good prices, also on ebay.com as well

	EHAG 
Industriestrasse 8
Oetwil am See, ZH 8618
Switzerland
+41 43 844 94 00
www.ehag.ch

COMEDIA
4 BIS ALLEE CHARLES V
VINCENNES, - 94300
France
33 1 43 28 48 48
www.comediatech.com

Others reviews:

{mosgoogle center}

comments powered by Disqus

You might like also

Antec Skeleton Design Case
Nice case especially since I got it for 1/3 of its price (40€ at the flea market: a bargain) The Antec Skeleton is a truly revolutionary enclosure. With a unique design that allows for unprecedented airflow, a front 92mm fan, and a top three speed 250mm fan with multicolor LED customization, the Skeleton goes utterly unmatched in stylish cooling. Factor in the layered component trays for top-notch convenience, as well as the rack mount quality side rails, and you have …
2913 Days ago
Give a new life to your Synology disk station: change its cooling fan
After some years of use, you’ll notice the increase noise coming from the cooling system. Any ventilator on the market, even the more expensive, or the more silent will wear off and start making noise. Replacing the ventilator is done in less than 2 minutes if you follow this little how to. Choosing the right ventilator Don’t pay too much, better choose a cheap model and replace it every year or two Below 19 dB, it is difficult to hear …
2913 Days ago
I win a Synology DS710+ & DX510 yesterday
I did win a Synology DS710+ & DX510 by filling out a survey, after having read an official tweet of Synology Inc.(http://twitter.com/Synology) about the contest 3 weeks ago. The funny part is that I bought a Synology DS1010+ (704CHF/692$) and 4TB of disk (280CHF/275$) at the same time… On the picture above, this is my current small datacenter :-) DS 408 has four disks of  1TB in RAID5, so a volume of 2.7TB since 2008 DS1010+ has two disks of …
3239 Days ago
Playing AVI, MKV on Samsung TV? no chances
I have to apologize a bit: I did try the following: NAS Synology DS408 as DNLA server + Samsung 8700 LED 3D and most format are recognized (some exotic wmv audio codecs were not working but who has wmv anyway) When I did try with USB, nothing was working. My father has a Samsung LED 7000 46 inch of december 2009 and this model dont play anything at all though USD and DNLA, I did bought a WD live media …
3251 Days ago
Samsung C8700 55’’ Review
Preview  – full post  09 July 2010   The Samsung UE 55 C8700 (LED TV 140cm, 200Hz, wifi ready, 3D Ready)  is the current Flagship of premium TV (the Samsung C9700 is basically a 7700 repackaged in a thinner casing).   …
3300 Days ago
NETGEAR WNR854T, Wireless Router, RangeMax NEXT, Gigabit
If you are in the business for a new router, just avoid NETGEAR. I like their product, but this is the second SH... router I bought from them (and they were not cheap) NETGEAR DG834 has NEVER work more than 8 hours without interruption! after 5 bios upgrade... see my previous article here... The latest I've bought, 13 months ago at www.spartacus.ch (company is no more existing, www.brack.ch&160; is now in charge of customer care) has just died 5 minutes …
3957 Days ago
HP Nw 9440 review
I receive my new notebook yesterday, it replace my HP NX7000 (3 years old). The HP NX 9440 is showing impressive performances, especially when running eclipse and multiple aplication in the backgroung.The specifications are as follow: Intel® Core™ 2 Duo Processor T7600 2.33 GHz 4 MB L2 cache 667 MHz front side bus 3 GB (667 MHz) DDR2 SDRAM NVIDIA Quadro FX 1500M graphics controller with 512 MB of dedicated video memory 100 GB (7200 rpm) SATA LightScribe DVD+/-RW with …
4556 Days ago
Treo 650 review
I am also hunting for a smartphone, and I found One of the best review to date on the treo 650 at Spug.netBeside, The (un-official) Treo 650 wifi drivers (by Shadowmite) for this smartphone. The best portal for the treo is Treo centralThe PalmOne page where You can buy itPresentation page at Engadget.comUpdate: Unlocking code for the GSM Treo 650 is: *#*1234# and then the center D-pad button. …
5277 Days ago
No Thumbnail was found
Good+ Unix based (apache software)+ telnet interface for advance user with a full CLI+ a lot of functionnaliies, every protocol is available.+ Very fast switching. According to Tom's hardware one of the fastest in its class.+ Very configurable (real business class router not home consummer crap)+ Built in USB and 1394 FTP server support+ Nice GUI interface,+ SUPER stable under emule Load!!!! 1000 connections wthout any loss of performances. A restart each 6 months or less!!!+ affordable: 90 (USR9105) to …
5288 Days ago
JVC GZ-MC200 tapeless Camcorder Review
While searching for a comcorder across internet, I found this model which look very promising, except low light performance and the poor hunting auto focus...anyway at 890euro on ebay, it is a winner.... The JVC Everio records DVD Quality video in MPEG-2 with AC-3 audio. It has a maximum bit-rate of 8.88Mbps. Directly recording video onto a 4GB CF Micro Hard-drive or SD Memory CardJVC Everio GZ-MC200 Camcorderinfo.comI4U Future Technology centerCNET reviewJVC Everio GZ-MC100 same specs, different case Camcorderinfo.comUpdate: The …
5302 Days ago