Live data from Hacker News

FaceID Security [pdf]

images.apple.com

31–40 of 314 posts

Re: FaceID Security [pdf]

#31
post #26

Questions: * Does one explicitly set up their FaceID with the option to skip, like how TouchID works currently? I see (when...enabled) verbiage, which is a good sign. * "The probability that a random person in the population could look at your iPhone X and unlock it using Face ID is approximately 1 in 1,000,000 (versus 1 in 50,000 for Touch ID)" If you have a face that causes most people you meet to say "oh, you look…

Would be cool/weird if you could find out who they were and have a meetup.

I've met a few. Paths have moved on but it would have been cool to see if they could try unlocking my phone if this came out during my tenure in college.

Re: FaceID Security [pdf]

#32

> The probability of a false match is different for twins and siblings that look like you Apple mentioned this on stage, which to me was quite significant since they don't waste a single word during their keynotes. They still haven't given approximate collision chances and to me this must mean they think it's below the 1/50,000 touch id had. My understanding is fingerprint collisions are highly random. That is very d…

They said in the keynote the chance a random person could unlock your phone with FaceID is 1 in a million.

Re: FaceID Security [pdf]

#33
post #17

Earlier quoted context omitted.

No, any kind of biometric auth is vulnerable to the adversary forcing your physical compliance. However you can disable TouchID and FaceID both by pressing the power button five times in quick succession, after which it will require your passcode.

For the iPhone X it's hold both the power button and either volume button for 2 seconds.

I've had a remarkably difficult time getting this kind of thing to register when I try to take screenshots -- probably an issue with my case? -- so it is probably worthwhile to practice doing this ahead of time.

Re: FaceID Security [pdf]

#34
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

Re: FaceID Security [pdf]

#35
post #20

> The probability of a false match is different for twins and siblings that look like you as well as among children under the age of 13, because their Face ID Security September 2017 2 distinct facial features may not have fully developed. If you're concerned about this, we recommend using a passcode to authenticate. I was really hoping they'd provide the probability for identical twins, but maybe they don't have eno…

I believe the probability for identical twins is 1 in 1; they mentioned in the keynote that some people will have to stick with passcodes, including those with "evil twins". (Presumably if you trust your identical twin to not be evil, you don't care if they're able to unlock your phone.)

Identical twins aren't identical down to every last detail. What I'm curious about is if Face ID can pick up on any details that are different that humans wouldn't notice.

Also regarding the "evil twin" thing, evil twins came from another dimension so, aside from the goatee, they really were literally identical down to every last detail. It's unclear to me if that joke was meant as "your identical twin will be able to unlock your phone, so hopefully they aren't evil", or was just meant as "someone who looks like you might be able to unlock your phone". Probably a bit of both. But this is why I want to know what the actual probability is that an identical twin can unlock the phone. Maybe it really is 1 : 1, but maybe it's not.

Re: FaceID Security [pdf]

#36
post #32

> The probability of a false match is different for twins and siblings that look like you Apple mentioned this on stage, which to me was quite significant since they don't waste a single word during their keynotes. They still haven't given approximate collision chances and to me this must mean they think it's below the 1/50,000 touch id had. My understanding is fingerprint collisions are highly random. That is very d…

They said in the keynote the chance a random person could unlock your phone with FaceID is 1 in a million.

Twins and siblings that look like you are not random people.

Re: FaceID Security [pdf]

#37
"Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads over 30,000 infrared dots to form a depth map of the face, along with a 2D infrared image. [..] To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern. [..] the A11 Bionic chip [..] transforms this data into a mathematical representation and compares that representation to the enrolled facial data."

So it matches on a math model created using face data and 'a device-specific random pattern'. So unless someone cracks the algorithms used here, you need the device data to spoof the model, assuming the pattern is used in a way that you can't simply ignore it and generate matching models using just a spoofed face.

"We worked with participants from around the world to include a representative group of people accounting for gender, age, ethnicity, and other factors."

If the model is really hugely inclusive, it could be too general. But also it would be very difficult to get the same number of scans from some minority populations, and that could affect the functionality of the result.

"An additional neural network that’s trained to spot and resist spoofing defends against attempts to unlock your phone with photos or masks."

Gruesome thought: what if somebody obtained your face?

Additional thought: could we train the neural network to detect faces under duress and immediately lock the device?

Re: FaceID Security [pdf]

#38
post #32

> The probability of a false match is different for twins and siblings that look like you Apple mentioned this on stage, which to me was quite significant since they don't waste a single word during their keynotes. They still haven't given approximate collision chances and to me this must mean they think it's below the 1/50,000 touch id had. My understanding is fingerprint collisions are highly random. That is very d…

They said in the keynote the chance a random person could unlock your phone with FaceID is 1 in a million.

For random faces, yes, but for a twin or sibling it’s more likely; what’s interesting is that they haven’t said how much more likely. If it were less than 1/50k then you might have expected them to confirm that it was still more secure than Touch ID, though that’s not certain.

Re: FaceID Security [pdf]

#39

"Face ID confirms attention by detecting the direction of your gaze" So to the argument that police can force you to open your iPhone if secured with TouchID, is this perhaps more secure? If you refrain from looking at your phone?

No, any kind of biometric auth is vulnerable to the adversary forcing your physical compliance. However you can disable TouchID and FaceID both by pressing the power button five times in quick succession, after which it will require your passcode.

This is woefully insufficient for a feature I have been begging for forever...

I would prefer it to be a double-tap on the power button, or at the very absolute worse, a triple tap. Two buttons simultaneously five times? Impossible to do under any sort of external pressure/duress.

Re: FaceID Security [pdf]

#40
post #34
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

If the phone allowed multiple users that might be one way to do it. Just log in to another user.
Post reply on HN