JP Morgan Chase has told staff moving into its new headquarters in New York that they must share their biometric data to access the multibillion-dollar building.

The investment bank had previously planned for the registering of biometric data by employees at its new Manhattan skyscraper to be voluntary.

However, employees of the US’s biggest bank who have started work at the headquarters since August have received emails saying that biometric access was “required”, according to communications seen by the Financial Times.

  • whotookkarl@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    29
    arrow-down
    3
    ·
    edit-2
    22 hours ago

    Biometrics aren’t passwords they are usernames, passwords necessarily change I’m not changing my fingerprints or iris or bhole or whatever they want to scan. With how easy it is to copy someone’s bio markers vs stealing their password this would be a huge security risk if they want to use it for entry to secured facilities.

    • Echo Dot@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      2 hours ago

      I hate it when people steal my eyes and I have to get new ones. My mother’s maiden name is so much more secure.

    • Evotech@lemmy.world
      cake
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      19 hours ago

      It’s usually used as a second factor. You have your I’d card (something you have) and your bio (something you are). add that with a password (something you know) and you are pretty good

    • FreedomAdvocate
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      16 hours ago

      You think it’s easy to steal someone fingerprint or iris in a way that will work on scanners?

      How?

    • Basic Glitch@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      29
      arrow-down
      1
      ·
      edit-2
      1 day ago

      Lmao my thoughts exactly. Not just the general public, if enough Republicans get nervous and finally vote to subpoena those files, they might have to be legally taken by force.

      Who had “If House Republicans would just fucking vote for accountability, the villain officially breaking the law and protecting pedophiles would be the CEO of a big bank?” on their bingo card. 🙋‍♀️

      Curious why they would want to protect a pedophile protector and those bank files. Unless…?

      “Survival of the fittest! It’s the natural order of things. Let nature take it’s cour… Hey, excuse me! You’re not supposed to be here without a biometric scan!”

      • BigMacHole@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        14
        arrow-down
        3
        ·
        1 day ago

        LoL! This post is STUPID! WHY would Republicans vote AGAINST Pedophiles AND rich People? Those are their ONLY Voting Blocks!

    • FarceOfWill@infosec.pub
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      I don’t think so, these places are ones that have the “yes, actually mossad” threat vector to defend against.

      Like the general public already wouldn’t get in.

  • HubertManne@piefed.social
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    17 hours ago

    Ooooh. I wonder what I can get into if I kidnap the ceo and scoop out an eyeball?! So exciting.

  • snooggums@piefed.world
    link
    fedilink
    English
    arrow-up
    29
    ·
    1 day ago

    Staff: “But we don’t have to if we work remotely, right.”

    JP Morgan Chase: “No remote work.”

  • CompactFlax@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 day ago

    I feel like there’s some kind of middle ground between the notoriously insecure HID style building access card and providing biometrics.

    I wonder if this has anything to do with a RTO push and people badging in for others. But then VPN usage would show that…

      • Deestan@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Well, I do. But it’s because the security layers on the wifi are more strict than on the VPN to such a degree that I can’t actually connect to it from my work laptop.

        • borari@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          If you can connect to the company vpn from the companies WiFi, they’ve configured their networks wrong.

          • rainwall@piefed.social
            link
            fedilink
            English
            arrow-up
            5
            ·
            edit-2
            23 hours ago

            Some companies do “internet only” wifi where there is no routing to internal services for anyone, radius or not. A VPN is required, even when at work, to access anything internal wirelessly. Its a perfectly reasonable config that lowers the risk of breach of your internal network by exposing less of it over the air.

            This is also the nominal config for most zero trust networks, but that’s more a consequence of the “always on” nature of those VPN connections since you never have unencryted traffic anywhere, regardless of origin point.

          • Atherel@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            20 hours ago

            Our servers are in a data center and not in the office building. We work remote most of the time and are only in office for important meetings and other things where it’s just easier to work together when sitting on the same table. If you don’t work with confidential data like HR or top management where you have physical things nobody else should see, you don’t have a personal desk because there are more people working than workplaces.

            So the office is just “another place to work”. Wifi and LAN are just for internet, you can’t access internal services without VPN. Makes it way easier to manage instead of having to different routes to maintain.

          • Deestan@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            22 hours ago

            Not quite like that. There is an internal wifi that I can’t get onto, and a public “guest” wifi that half of the tech staff uses and VPNs from.

            Basically the protected wifi only really works on locked-down windows machines, and those aren’t usable for most developers. It’s mostly mac and linux there, and while the protected wifi is supposed to work on those, the IT staff don’t know how.

            • Dionysus@leminal.space
              link
              fedilink
              English
              arrow-up
              1
              ·
              20 hours ago

              locked-down windows machines

              I’ve worked in IT since we used Netware with Windows 3.1

              While I totally get what’s being said, it still makes me chuckle.

    • HakunaHafada@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 hours ago

      2FA the access card? Swipe your badge, receive a prompt on your phone “Are you trying to badge in at $BUILDING?”, hit allow, be granted access to building.

      Another option would be badge + PIN code.

  • FreedomAdvocate
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    6
    ·
    16 hours ago

    Biometric access requires staff to scan their fingerprints or eye to gain access through security gates in the lobby instead of swiping their ID badges.

    You could not sign me up fast enough to be able to open my office’s door with my fingerprint or eye.

    The systems that handle biometric logins for gigantic companies are usually pretty bulletproof and have been audited many times.

    I’m guessing people on here will think this is the second coming of the devil though lol. I can only imagine the outrage if FaceID/TouchID didn’t already exist on phones and Apple/google/etc added it in 2025 🤣