All the biometric things I saw as finished smarthome products don’t look trustworthy or securely designed.
I want to put it together myself.
I need a fingerprint module tho, I can’t make those. But I wouldn’t want just any garbage product. I look for something with security guarantees similar to the fingerprint-scanner+secure enclave combinations in modern Pixel and Iphone.
- The device is hardened against secret extraction.
- The device is sealed in a way that nothing can be added without noticing. Like a tamper contact that wipes the data encryption secret when triggered.
- The fingerprint is never saved in a way, that a fingerprint can be reconstructed from it.
- The fingerprint is never saved in a way, that the data derived from a fingerprint on one device also works on another device.
- The device has finger liveness detection so that I can’t authenticate to it using a CNC carved carrot.