Live data from Hacker News

FaceID Security [pdf]

images.apple.com

51–60 of 314 posts

Re: FaceID Security [pdf]

#51
post #34

Earlier quoted context omitted.

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

If the phone allowed multiple users that might be one way to do it. Just log in to another user.

Or use all that machine learning to fake a normal user profile…

Re: FaceID Security [pdf]

#52
post #34

Earlier quoted context omitted.

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

If the phone allowed multiple users that might be one way to do it. Just log in to another user.

Xiaomi's MIUI has this feature, you can use different fingerprints to directly enter a "2nd Home" or something where all apps / data is segregated. It's not really designed to be too stealthy though as there's ways to switch back to the regular homescreen.

Re: FaceID Security [pdf]

#53
post #17

Earlier quoted context omitted.

For the iPhone X it's hold both the power button and either volume button for 2 seconds.

Actually, I think that’s the hard reset sequence - replacing the Home Power combo

From the PDF:

> After initiating power off/Emergency SOS by pressing and holding either volume button and the side button simultaneously for 2 seconds.

Re: FaceID Security [pdf]

#54

Questions: * Does one explicitly set up their FaceID with the option to skip, like how TouchID works currently? I see (when...enabled) verbiage, which is a good sign. * "The probability that a random person in the population could look at your iPhone X and unlock it using Face ID is approximately 1 in 1,000,000 (versus 1 in 50,000 for Touch ID)" If you have a face that causes most people you meet to say "oh, you look…

> I see (when...enabled) verbiage, which is a good sign.

Of course. See "Face ID requires a facial match — or optionally the passcode — at every wake." and "If you're concerned about [matching with a twin], we recommend using a passcode to authenticate."

Re: FaceID Security [pdf]

#55
I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID

- TouchID is already very fast

- I can give access to someone else with TouchID without giving my password

- It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID

- In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one

- I have to voluntary give my agreement with TouchID for an action (think apple pay)

All of that makes me think that they are trying to sell a feature that is only due to their engineering team unable to put TouchID on the Iphone X. By every real world metrics, TouchID is better in my opinion...

Re: FaceID Security [pdf]

#56
post #32

> The probability of a false match is different for twins and siblings that look like you Apple mentioned this on stage, which to me was quite significant since they don't waste a single word during their keynotes. They still haven't given approximate collision chances and to me this must mean they think it's below the 1/50,000 touch id had. My understanding is fingerprint collisions are highly random. That is very d…

They said in the keynote the chance a random person could unlock your phone with FaceID is 1 in a million.

Can someone help me understand why @gre got down-votes here? I don't get it.

As far as I remember, in the big reveal, they did make a point of saying that faceid had a much lower chance of of colliding than the fingerprintid system.

Re: FaceID Security [pdf]

#57
Recently I posted this theoretical spoofing attack in a comment. I'm glad to know they've put in the appropriate measure to detect it - randomly blinking the IR dot pattern, requiring any spoofed videos to react to the blinking with very near zero lag (likely sub-microsecond). Specifically, the last step in this process could be detected because the generated IR video would have a static dot pattern.

How to (not) hack FaceID: You'd need:

1. 2 phones (at least 1 with an IR camera, such as another Iphone X)

2. a helper app

3. access to 10+ photos of the victim (Facebook typically)

4. a small mirror

With the helper app:

1. capture the suspect's phone's unique IR dot pattern by shining their phone at white piece of paper, recording it with the helper app (the helper phone needs an IR camera of course, such as another Iphone X)

2. the app makes 3d model of persons face from the FB pictures

3. the app generates two animated videos of their face, 1 just a normal color video and another simulated "IR video" with the unique dot pattern applied

4. now you need to show the 2 videos to FaceID, using the mirror to show the color video to the color camera and the IR video the IR camera. Note: It's still TBD which wavelengths the IR camera are sensitive to and which wavelengths smartphone screens can put out, so the IR video device may need to be specially made...

Re: FaceID Security [pdf]

#58

Biometrics are UID's - not passcodes.

Literally the second paragraph

> Face ID doesn’t replace your passcode, but provides easy access to iPhone X within thoughtful boundaries and time constraints. This is important because a strong passcode forms the foundation of your iOS device’s cryptographic protection.

Re: FaceID Security [pdf]

#59
post #36
post #32

Earlier quoted context omitted.

They said in the keynote the chance a random person could unlock your phone with FaceID is 1 in a million.

Twins and siblings that look like you are not random people.

Now I'm imagining the FBI using its facial-recognition databases and tracking down people who look like the phone owner to wave an iPhone in front of their face.
Post reply on HN