[...] recorded the brain activity of people [...] while they looked at a series of 500 images designed specifically to elicit unique responses from person to person [...]. Each image flashed on a monitor for only half a second.
Wasn't further addressed as far as I could see. I realize it's a research prototype, and perhaps they can condense that image set down once they figure out which are really good triggers, since spending 250 * 0.5 = 125 seconds = more than two minutes for an authenitication seems a bit much to be practical.
I'm a bit scared of what those (hypothetical, I don't know they exist) "power-images" might end up being, though.
— No.
— It won't replace passwords.
— Can I give it to the bad guy when I'm being held at gunpoint?
— No.
— It won't replace passwords.
Although apparently it can be "changed": https://www.schneier.com/blog/archives/2015/06/yet_another_n...
"If someone's fingerprint is stolen, that person can't just grow a new finger to replace the compromised fingerprint -- the fingerprint for that person is compromised forever. Fingerprints are 'non-cancellable.' Brainprints, on the other hand, are potentially cancellable. So, in the unlikely event that attackers were actually able to steal a brainprint from an authorized user, the authorized user could then 'reset' their brainprint," Laszlo said.
Presumably the resetting involves a new set of acronyms.
I still don't like the idea of using identity for authentication.