CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometricsBy Cara Candelario

Biometric Security: A Stolen Face Has No Reset Button

biometric security cannot be changed, shown as a face outline broken into glowing number points
A face outline split into glowing points shows biometric security and why biometric data cannot be changed. Illustration: CaraComp

Quick answer

What is biometric security and why is it risky if it's stolen?

Biometric security uses a body trait, such as a face or fingerprint, to confirm who someone is. The risk is permanence. A leaked password can be replaced in minutes, but a copied face stays useful to whoever holds it. Matches also get less reliable with blurry or dark images, so they need checking.

You can change a password in thirty seconds. You cannot change the shape of your face. That one fact is the whole reason biometric security deserves more attention than it gets. Your face is now a key that opens phones, offices, and police databases, and once that key is copied, there is no "forgot my face" button.

TL;DR

Biometric security turns your face into a string of numbers and checks how close it sits to another string, which works well in clean conditions, fails in messy real life, and leaves you with no way to reset a face that has been wrongly matched or stolen.

Biometric Security Explained: How a Face Becomes a Row of Numbers

Let's start with what a face scan is not. It is not a photo sitting in a folder, with a computer flipping through pictures until two look alike. That's the movie version.

What really happens is stranger. Software studies a photo and boils it down to a list of numbers. According to a technical explainer from Didit, that list usually holds somewhere between 128 and 512 numbers. Experts call it an "embedding" (a fancy word for a face turned into a point on a giant invisible map).

Picture a map with hundreds of directions instead of two. Your face lands on one spot. A photo of you taken last week lands very close by. A photo of a stranger lands far away. To compare two faces, the software measures the gap between the two spots. The measuring method is called Euclidean distance (basically, how far apart two faces are once you map them as points). Small gap, "same person." Big gap, "different person."

Notice the trick. The system never says "this is Dana." It says "this spot is 0.4 units from that spot." Someone then decides how small a gap counts as a match. That cutoff is a human choice, and it decides how many innocent people get flagged.

Why a data center full of face numbers is a risk

Those number lists have to live somewhere. Usually that's a data center (a building packed with servers that store company files). Companies keep these lists so they can compare your face at the door or on your phone screen later.

Here's the problem. A stolen list of numbers can be turned into a working key, because the same numbers that open the door also identify you. That is why biometric data (your face, voice, and fingerprints, the body stuff that's uniquely you) is handled so differently from a stolen credit card number. The bank can cancel the card. Nobody can cancel your cheekbones.

Authentication: the moment of matching

Authentication is just a fancy word for "proving you are you." There are three classic ways to do it: something you know, something you have, and something you are. A password is the first. A house key is the second. A face is the third.

The "something you are" kind feels magical because nothing has to be remembered. It also has a catch that the other two don't. You can replace a lost key. You can migrate to a new login when a company gets hacked. You cannot do either with a face.

Signing in with a face instead of a password

Think about what you do when a site leaks your login. You pick a new password, maybe a new PIN, and the old one is dead. The leak is annoying but finite. With fingerprint scans and face scans, the thing that leaked is the same thing you will be using for the rest of your life.

QuestionPassword or PINYour face
Can it be reset after a breach?Yes, in minutesNo, it cannot be changed
What does the security system store?A secret you choseNumbers built from your real features
Who sees it in daily life?NobodyEvery camera and every video you appear in
What is the policy risk?Weak habits, like reusing one passwordCopied for good, with no privacy undo button

Why Biometric Security Falls Apart Outside the Lab

You've probably seen a company claim its face matching is "99 percent accurate." That number is real. It just doesn't mean what most of us think it means. This article is part of a series, start with Facial St Louis One Number Jailed Wrong Man 17 Months.

Here's the catch. Those scores come from tests using clean photos: good light, straight-on faces, high-quality cameras. Real life doesn't look like that. Real life looks like a grainy video from a gas station ceiling camera at 2 a.m.

Video monitoring and the accuracy cliff

Let's look at what happens when the picture gets worse. According to a summary from AndOpen, an algorithm with a 0.1% error rate on sharp mugshots can see that climb to 9.3% on images captured "in the wild." That's roughly ninety times more mistakes from the exact same software.

Now think about how police actually use it. They rarely match one great photo against another great photo. They take a still from a blurry store video, and they search it against a pile of crisp ID pictures. The video frame is dark, tilted, and tiny. The mugshot is bright and straight. The system is being asked to make its hardest comparison, not its easiest one.

And video monitoring makes this worse, not better. A camera that records all day produces thousands of frames. Pick the wrong frame, and the software will still return an answer. It always returns an answer. It never shrugs.

13
known times police in the U.S. have arrested an innocent person after a face match, and those are only the cases that came to light
Source: State of Surveillance, April 2026, compiled from ACLU records

Biometric monitoring treats some faces differently

Here's a number that surprised me. One submission reported to the U.S. government's testing lab NIST in January 2025 showed false-match rates running from 0.006% up to 2.15% across different groups of people, using the exact same settings. That's a 345-fold gap, as laid out by Antivirus Insider. You can find the wider benchmark story in a Federation of American Scientists report on bias in face matching.

What does "345 times" mean in plain English? Imagine a smoke alarm that goes off falsely once a year in one house and once a day in another, both cooking the same dinner. Nobody would call that alarm fair. Yet with biometric monitoring (software that watches or checks faces on an ongoing basis), that kind of unevenness is what the tests show. The technology isn't "objective." It has blind spots, and the blind spots land on real people.

Systems that miss: Detroit's 96 percent admission

In the real world, these gaps have a body count of ruined weeks. Detroit's police chief at the time, James Craig, acknowledged that the department's face search gave wrong results about 96% of the time if used alone to identify someone. Think about that. A system that wrong, and it stayed in use.

The official policy says a match is only a lead. Here is how police guidance is summarized by Recording Law:

An investigative lead that must be corroborated, not a positive identification.

Police guidance on face matches, as summarized by Recording Law

That sounds careful. But a lead that shows up on a screen with a confident score tends to get treated like an answer. Humans are wired that way. The computer said so.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

What Happens to Biometric Data Once Compromised?

When biometric data is compromised, whether stolen or wrongly matched, it cannot be changed. Your face stays the same, so the copy stays useful to whoever holds it. You can't cancel it like a credit card. The only real protection is stopping the damage before it happens. Previously in this series: Deepfake Voice Scam News Today 1 Verification Rule Stops It.

That's the aha moment of this whole topic. With a password, security is about what you can fix after a breach. With a face, security is only about what you can prevent beforehand.

The document behind one wrongful arrest

Want to see how this plays out? Take Robert Williams of Detroit, described in ACLU records. A blurry 2018 store video image of a thief was run through face search. The software tied it to the photo on his expired driver's license. That document, a plain old ID, was the bridge between a stranger on camera and a man at home with his family.

He was arrested in front of his family in January 2020 and held about 30 hours for a theft he did not commit. The match was wrong. The arrest was real.

He isn't alone. Randal Reid of Georgia spent six days in jail after a false match tied him to theft in Louisiana, a state he had never visited. Porcha Woodruff, pregnant, was arrested at her Detroit home in front of her children and held 11 hours. Nijeer Parks was jailed ten days in New Jersey and paid $5,000 for his defense. In July 2025, Angela Lipps, a grandmother from Tennessee, was jailed for nearly six months over bank thefts in North Dakota, where she had never been.

Different people, different states, same pattern: a face that looked "close enough" in a bad picture.

Why smart people trust a "99 percent" claim

Let's be fair to everyone who believed the big accuracy number. It is a true number. It just answers a narrow question: "How good is this software on clean, well-lit, front-facing photos?" Nobody asked it the real question: "How good is it on a dim, side-angle video frame matched against a database of a million faces?"

Here's the second trap. When you search a huge database, even a tiny error rate produces lots of wrong faces. Ask a million people "does this look like the suspect?" and a few of them will always look close enough. Bigger pools mean more lookalikes, which is why a 99 percent score can still hand back a stranger.

Biometric Security and Your Next Move

So where does that leave a normal person on a normal Tuesday night? Not helpless. A few things genuinely help.

First, notice where your face is being used as a key. Phones, gym doors, office badges, airport lines. Ask whether there's a password or PIN option instead. If there is, take it for anything you don't want tied to your body for life.

Second, pay attention to local rules. Researchers note that across more than 20 places that have banned police use of face matching, no wrongful arrest has been reported. That's a small sample, but it matches the math: no search, no false match.

Third, know your own paper trail. If you were ever wrongly matched, you'd want to know who to call first: a lawyer, the police department's records office, or your state's civil liberties group. Writing those names down now is cheap. Up next: Proof Of Identity 3 Tiers That Decide Who Gets Turned Away.

At CaraComp, where the daily work is teaching how face comparison really works, the lesson we repeat most is simple: a match score is a measurement, not a verdict. Somebody still has to check the work with other evidence, like where the person was and what the video really shows.

What You Just Learned About Biometric Security

  • Faces become numbers and the match is just a measured gap between two points on a map.
  • The lab gap is huge because 0.1% error on clean photos can become 9.3% on real-world images.
  • The 345 times gap shows that one system can treat groups of people very differently.
  • A face has no reset so prevention is the only protection that works.
Key Takeaway

Biometric security has one weakness a password never has: a face cannot be changed, so once compromised, the damage has no reset. Treat a match as a clue to check, not an answer to trust.

Here's the thought to carry to bed tonight. Every password you own can be thrown away and replaced. Your face is the only key you will ever have that you can't swap out. So the next time a door, an app, or a camera asks for it, ask the question that matters: if this copy ever gets out, where would I even begin to look?

Biometric Security: Frequently Asked Questions

Does biometric access control really make workplaces safer?

Sellers of biometric access control say it gives businesses better control over who enters a building, and that it simplifies daily operations because nobody loses a badge. Those benefits are real for some sites. The tradeoff is that the stored face or fingerprint data cannot be changed if it leaks. A badge can be cancelled. A face cannot. A company weighing the switch should also ask how it would migrate away from the system later.

What is the best time to ask a company to delete my face data?

Right now is usually the best time, because the longer a company holds biometric data, the longer it can be leaked or shared. Some states have introduced privacy bills that give residents a right to ask. Rules differ by place, so check your own state. Start with the account settings of a major platform you already use, where deletion options are often found. Acting early helps protect people's biometric data before a problem appears.

Have any cities passed legislation against police face matching?

Yes. Researchers compiled by State of Surveillance note that more than 20 places have passed legislation limiting or banning police use of face matching, and no wrongful arrest has been reported in a city with an active ban. That is a small sample and not a guarantee. Still, it fits the math. Some states have introduced similar bills, though the details differ widely, so local rules are worth checking.

Can a company migrate from face scans to something safer?

A company can migrate to a new login method, such as a password, a PIN, or a mix, and it can do so quickly. What it cannot do is recall the faces it already collected if those were stolen. Biometric data cannot be changed, so once compromised, the copy stays useful to thieves. This is why experts urge companies to store as little face data as possible and to delete it on a schedule.

Are fingerprint scans safer than face scans?

Neither is fully safe, because both are biometric traits that cannot be changed. Fingerprint scans on a phone are often stored only on the device, which limits exposure. Face matching by police, by contrast, compares a video still against large databases, where lookalikes cause errors. The risk depends less on the body part and more on where the data is stored, who can search it, and what happens if it leaks.

What is biometric monitoring and where does it show up?

Biometric monitoring means software that checks or tracks faces, voices, or fingerprints on an ongoing basis, such as cameras that scan a crowd or doors that log who enters. It relies on video feeds and a system that compares faces to a stored list. The accuracy depends heavily on video quality. Blurry footage and poor light raise the odds of a false match, so the result should be confirmed with other evidence.

Is a password or PIN better than biometric authentication?

For many everyday accounts, a strong password or PIN has one big advantage: it can be reset the moment something goes wrong. Biometric authentication adds convenience and can add security when it is stored safely on your own device. The best setup often combines both. The key difference is recovery. A leaked password is an annoyance. A leaked face template, kept in a data center, is a permanent problem.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search