Live data from Hacker News

FaceID Security [pdf]

images.apple.com

91–100 of 314 posts

Re: FaceID Security [pdf]

#91
post #18

Good document, but I was really hoping they’d go deeper into how they tested some of the fraud detection stuff (masks, etc) or give us some statistics on the twin/family member issue.

It mentions infrared picture. Masks probably have a different infrared signature.

But so does your face if it's been wearing a balaclava in the cold (some parts will be cold and some will be warm...

Re: FaceID Security [pdf]

#92

Earlier quoted context omitted.

No, any kind of biometric auth is vulnerable to the adversary forcing your physical compliance. However you can disable TouchID and FaceID both by pressing the power button five times in quick succession, after which it will require your passcode.

5-clicks-in-quick-succession primarily activates the "Emergency SOS mode", as well as temporarily disabling TouchID. I think you should edit your post to reflect this.

It’s disabled until you enter your passcode again, correct, which is what you want. I am not sure what you thought I was saying? If you want to disable it permanently, you can do that in Settings, but doing that requires you to unlock the phone, at which point the adversary may take it and have free reign.

Re: FaceID Security [pdf]

#93

Earlier quoted context omitted.

No, any kind of biometric auth is vulnerable to the adversary forcing your physical compliance. However you can disable TouchID and FaceID both by pressing the power button five times in quick succession, after which it will require your passcode.

This is woefully insufficient for a feature I have been begging for forever... I would prefer it to be a double-tap on the power button, or at the very absolute worse, a triple tap. Two buttons simultaneously five times? Impossible to do under any sort of external pressure/duress.

Two buttons press and hold on iPhone X.

Power button 5x on any other phone.

Re: FaceID Security [pdf]

#94

The diagnostics section is super interesting.

Yes, this section hasn't previously been reported or commented on. I wonder if this is essentially an opt-in to add your face to the FaceID master dataset[0], or if it is to just allow the developers to see what issues users are having (and how frequently).

[0] - It's previously been reported (https://techcrunch.com/2017/09/15/interview-apples-craig-fed...) that Apple collected this dataset at great expense. The ATP podcast has an account of someone who took part of that data collection here: https://overcast.fm/+CdQoBnmk/1:15:23

Re: FaceID Security [pdf]

#95
post #55

I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…

It's a competitive move; it gives Apple and their users a bragging point, causing competition an expensive countermove. Competition has to move to depth sensor cameras and more on their phones, while Apple is reducing the expense and improving the quality of theirs. The Face ID tech is immature today, but a quarter or three? The quarter after that once support issues have had a few cycles, and the Face ID team has iterated, refactored and refreshed... This is a basic tech deployment they'll only improve.

The real question to me, a person in the FR industry, will Apple iterate their camera hardware and extend the perception depth range to be competitive in the larger FR surveillance industry? The general FR industry has to recognize multiple people at a distance, and then IoT-like control other hardware, a game Apple is not touching with Face ID - yet.

Re: FaceID Security [pdf]

#96

"Face ID confirms attention by detecting the direction of your gaze" So to the argument that police can force you to open your iPhone if secured with TouchID, is this perhaps more secure? If you refrain from looking at your phone?

Here's what police do today, and it will defeat this and all types of security: Follow you until you make a phone call, or do something that requires you to unlock your phone. Then multiple people descend on you and grab you and your phone.

That's if they're interested in looking at your phone for a particular reason, rather than randomly being nosy in a traffic stop.

Re: FaceID Security [pdf]

#97

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

That isn't taking into account how frequent relative to all such target objects an attack occurs. If a (much?) smaller percentage of houses get burglarized vs. number of phones broken into, then security requirements are not really comparable. (Note that I have zero idea of or even guess for the sizes of either, though.)

Re: FaceID Security [pdf]

#98
post #83

How would this work if you wear a burka for example (without having to "downgrade" to using a passcode, when the real alternative would have just been TouchID)? Or am I missing something... genuinely curious.

FaceID will be incompatible with burqas, just like TouchID is incompatible with gloves.

Re: FaceID Security [pdf]

#99
post #80
post #75

Earlier quoted context omitted.

> they are trying to sell a feature that is only due to their engineering team unable to put TouchID on the Iphone X I highly doubt it’s easier to add FaceID than TouchID to any phone.

I remember reading some articles about the difficulty to have a fingerprint sensor under a screen, it might well have been easier to have FaceID (easier does not mean easy)

They could have put the fingerprint sensor on the back, as several Android phones do.

Re: FaceID Security [pdf]

#100

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?
Post reply on HN