Live data from Hacker News

FaceID Security [pdf]

images.apple.com

101–110 of 314 posts

Re: FaceID Security [pdf]

#101

Earlier quoted context omitted.

No, any kind of biometric auth is vulnerable to the adversary forcing your physical compliance. However you can disable TouchID and FaceID both by pressing the power button five times in quick succession, after which it will require your passcode.

> However you can disable TouchID and FaceID both by pressing the power button five times in quick succession This seems effective "on paper, but not in practice." Even if you're innocent, it is one of the most nerve-racking experiences to go through. In the heat of the moment, what if you used an old 5s method to deactivate TouchID instead of whatever method works for the X?

It works fine for me, but if you have a more practical suggestion, can you expand on that? What do you think would work better?

Re: FaceID Security [pdf]

#102
post #55

I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…

- More secure (Face ID uses more data points)

- Less user-interaction to authenticate (though as you point out this is also a negative)

- Allows for other UX improvements, e.g., maintaining screen lighting while phone is being observed but not manipulated

- My speculation: capacity to add additional faces will be added with SW (or next HW) update

__

I don't understand your point #3. How do you think someone would unlock your phone with Face ID?

Re: FaceID Security [pdf]

#103
post #83

How would this work if you wear a burka for example (without having to "downgrade" to using a passcode, when the real alternative would have just been TouchID)? Or am I missing something... genuinely curious.

FaceID will be incompatible with burqas, just like TouchID is incompatible with gloves.

What about an IR transparent burqa?

Re: FaceID Security [pdf]

#104
post #80
post #75

Earlier quoted context omitted.

> they are trying to sell a feature that is only due to their engineering team unable to put TouchID on the Iphone X I highly doubt it’s easier to add FaceID than TouchID to any phone.

I remember reading some articles about the difficulty to have a fingerprint sensor under a screen, it might well have been easier to have FaceID (easier does not mean easy)

Gruber:

> Apple made this decision well over a year ago. Perhaps the fundamental goal of iPhone X was to get as close as they could to an edge-to-edge display. No chin whatsoever. There were, of course, early attempts to embed a Touch ID sensor under the display as a Plan B. But Apple became convinced that Face ID was the way to go over a year ago. I heard this yesterday from multiple people at Apple, including engineers who’ve been working on the iPhone X project for a very long time. They stopped pursuing Touch ID under the display not because they couldn’t do it, but because they decided they didn’t need it. I do believe it’s true that they never got Touch ID working, but that’s because they abandoned it in favor of Face ID early.

> I don’t know why recent supply chain rumors suggest Apple was scrambling to get Touch ID working on iPhone X as late as this summer, and no one at Apple seems to know either. Disinformation campaign from competitors?

Re: FaceID Security [pdf]

#105

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

You can turn it off.

Or you can apply a threat model and determine whether the people for whom TouchID/FaceID is keeping your phone secure against would have the resources to mount such an attack.

Re: FaceID Security [pdf]

#106

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

I have a house with a standard lock. A couple years ago someone decided to kick the front door in while I was at work. We have shitty house locks because the entire system is terribly insecure and strengthening one link in the chain is pointless.

Re: FaceID Security [pdf]

#107
post #55

I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…

- More secure (Face ID uses more data points) - Less user-interaction to authenticate (though as you point out this is also a negative) - Allows for other UX improvements, e.g., maintaining screen lighting while phone is being observed but not manipulated - My speculation: capacity to add additional faces will be added with SW (or next HW) update __ I don't understand your point #3. How do you think someone would unl…

For their Point #3 I'm guessing they are saying if they are sleeping or a mugger points their phone at their face. Fortunately, Face ID has focus detection, so if you aren't looking at it then it won't unlock. Which makes point #3 moot as well.

Re: FaceID Security [pdf]

#108

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

https://danielmiessler.com/blog/why-biometric-data-breaches-...

I submitted this earlier today but it didn’t get traction.

Basically it could be done.

Re: FaceID Security [pdf]

#109
post #35

Earlier quoted context omitted.

I believe the probability for identical twins is 1 in 1; they mentioned in the keynote that some people will have to stick with passcodes, including those with "evil twins". (Presumably if you trust your identical twin to not be evil, you don't care if they're able to unlock your phone.)

Identical twins aren't identical down to every last detail. What I'm curious about is if Face ID can pick up on any details that are different that humans wouldn't notice. Also regarding the "evil twin" thing, evil twins came from another dimension so, aside from the goatee, they really were literally identical down to every last detail. It's unclear to me if that joke was meant as "your identical twin will be able t…

Assuming the hardware isn't being pushed to the accuracy limit for the sake of processing time, perhaps there could be an "enhanced security" mode that requires a more thorough check? I suspect their 1:1,000,000 false-positive number is an extrapolation of the maximum allowable difference in measurement. They probably could have set that "fudge factor" to a value that corresponds to something like 1:1,000,000,000 and increased false negatives to 50%.

Maybe it needs to see more "liveliness" and a few degrees head rotation?

Overall I think with the alertness test, the 48-hour passcode lockout, the "press the lock button 5 times" panic mode, and a limit on all attempts is enough to discourage most three letter agencies. It seems to have been enough with TouchID.

Re: FaceID Security [pdf]

#110
post #80

Earlier quoted context omitted.

I remember reading some articles about the difficulty to have a fingerprint sensor under a screen, it might well have been easier to have FaceID (easier does not mean easy)

They could have put the fingerprint sensor on the back, as several Android phones do.

And they could also install a hardware keyboard. Neither of which is going to happen. Just because you can do something doesn't mean you should.
Post reply on HN