Live data from Hacker News

FaceID Security [pdf]

images.apple.com

81–90 of 314 posts

Re: FaceID Security [pdf]

#81
post #67

They should add some sort of integration for lost/stolen iphones that would allow them record face information of anyone who uses it after the phone has been reported stolen.

No, because they (and we) don’t want to be able to store face information server-side.

Re: FaceID Security [pdf]

#82
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

Some fingerprint access systems have this feature, where you scan a specific finger as your duress finger. If you use that finger it triggers duress mode, which can be configured as an alarm, silent alarm a simple log event or anything.

Re: FaceID Security [pdf]

#83
How would this work if you wear a burka for example (without having to "downgrade" to using a passcode, when the real alternative would have just been TouchID)? Or am I missing something... genuinely curious.

Re: FaceID Security [pdf]

#84
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

> I still wish it had an "unlock under duress" mode

The practical applications of this are close to nil.

The government will not be fooled for one second because they can cross reference enough sources to know if you are lying. All this will do is get you slapped with a felony:

https://www.popehat.com/2011/03/18/just-a-friendly-reminder-...

If it is a criminal instead, well, they don't have to tiptoe around moral, ethical or legal concerns. They already have a gun pointed at your head. You act funny, you get shot. Do you want to risk a bullet in your head?

I fail to see the advantage of this mode. Ultimately it will only get you into more trouble.

Re: FaceID Security [pdf]

#85
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

This sounds like a cool idea, but I don't think it would work in practice. The would-be thief, assuming he knows about the "duress mode" (which isn't a bold assumption considering the large black market for stolen iPhones), would recognize that you've logged in to something strange, that doesn't show any useful data. They'd just pull back the hammer on their pistol and tell you to try again.

It could just log in to a 2nd account... then you could go in and create files, install apps, etc.

Re: FaceID Security [pdf]

#86
post #34
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

Just say "its to fight terrorism" and everyone will have it. It'll be required by law soon there after.

Re: FaceID Security [pdf]

#87
post #55

I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…

It doesn't matter what Apple knows is true, they will say FaceID is better because why would they ever say that this new feature replacing the old one is worse?

They can also present the facts in a misleading way that makes FaceID seem better. At the end of the day, you can never truly trust the company to present a fair review of their own device, and that's why reviewers exist.

Re: FaceID Security [pdf]

#88
I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house.

Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them.

A house key is called a "key" though, so it must be a password, and thus must be secure! And biometrics are just usernames, so they're useless and insecure!

Sarcasm aside, my point is this. Even with the worst biometrics, your phone would be more secure than 99% of houses. And I don't see people complaining about the state of home security...

Ultimately, these username vs. password analogies are shallow understandings of security, and at best flawed.

Biometrics, passwords, house keys, secure dongles, etc. Those are _all_ keys. What they differ in is how reproducible they are, how easily they're lost, and how easily they're bypassed.

For example: Biometrics, when measured by devices with sufficient liveness tests, are robust against forgeries. That means they can't be stolen. This is in contrast to passwords and pincodes, which can be stolen by eyeballs, cameras, audio recording devices, etc. You can use FaceID or TouchID to unlock your phone in front of all the recording devices in the world, and yet still your biometric key won't be stolen.

See how that example comparison is far more interesting and enlightening than "biometrics are usernames, so they're pointless"?

* Of course, when I refer to household locks and keys, I mean your average household lock. There are, of course, premium locks with keys that can't be reproduced. But most houses have locks that you can sneeze on and open.

Re: FaceID Security [pdf]

#89
post #81
post #67

They should add some sort of integration for lost/stolen iphones that would allow them record face information of anyone who uses it after the phone has been reported stolen.

No, because they (and we) don’t want to be able to store face information server-side.

They wouldn't have to until the phone is reported stolen and the user enables it.

Re: FaceID Security [pdf]

#90
post #34
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

Not to mention incredibly difficult to pull off. It isn't like having two passwords, one distress password and one normal. An algorithm that needs to identify your face in any situation AND detect subtle characteristics? I don't see that being a reality with our current technology. Or at least without significant false positives. Though a two password feature would be nice and easy to implement.
Post reply on HN