Live data from Hacker News

FaceID Security [pdf]

images.apple.com

111–120 of 314 posts

Re: FaceID Security [pdf]

#111

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

I have a house with a standard lock. A couple years ago someone decided to kick the front door in while I was at work. We have shitty house locks because the entire system is terribly insecure and strengthening one link in the chain is pointless.

[deleted]

Re: FaceID Security [pdf]

#112

Earlier quoted context omitted.

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

You can turn it off. Or you can apply a threat model and determine whether the people for whom TouchID/FaceID is keeping your phone secure against would have the resources to mount such an attack.

How do you change biometric keys once they're compromised?

You can turn it off.

Is "don't use a lock" really the answer to "my key was stolen"?

Re: FaceID Security [pdf]

#113
post #63
post #34

Earlier quoted context omitted.

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

How did you arrive at the "0.0001%" figure? Of what population is that a percentage? I strongly dislike this kind of waving away an important feature request. These days anybody crossing the border of the USA could be asked to unlock their phone. I'd say that's at least a larger percentage of the "population" (whatever population you meant) than "0.0001%".

> I strongly dislike this kind of waiving away an important feature request

I could easily say I dislike people making up rediculous corner cases and demanding new technology be designed for it and being deployed.

Are there any authorization methods on any kind of mainstream devices that provide that capability?

I tend to agree that it’s not actually useful and would be incredible hard to implement, all for a case where most people will just give in to avoid harm and forget the option, if it’s even on, exists so they can’t activate it.

Re: FaceID Security [pdf]

#114

Earlier quoted context omitted.

You can turn it off. Or you can apply a threat model and determine whether the people for whom TouchID/FaceID is keeping your phone secure against would have the resources to mount such an attack.

How do you change biometric keys once they're compromised? You can turn it off. Is "don't use a lock" really the answer to "my key was stolen"?

I think it's more a case of "use a different lock". That is, use a passcode.

Re: FaceID Security [pdf]

#115

Earlier quoted context omitted.

You can turn it off. Or you can apply a threat model and determine whether the people for whom TouchID/FaceID is keeping your phone secure against would have the resources to mount such an attack.

How do you change biometric keys once they're compromised? You can turn it off. Is "don't use a lock" really the answer to "my key was stolen"?

Turning off FaceID isn't "don't use a lock", it's "use a password instead."

Re: FaceID Security [pdf]

#116

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption.

My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.

Re: FaceID Security [pdf]

#117
post #108

Earlier quoted context omitted.

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

https://danielmiessler.com/blog/why-biometric-data-breaches-... I submitted this earlier today but it didn’t get traction. Basically it could be done.

But your argument makes no sense. The attack isn't "someone stole the processed image ("stick figure") of my fingerprint", the attack is someone copied my fingerprint.

Re: FaceID Security [pdf]

#118
post #18

Good document, but I was really hoping they’d go deeper into how they tested some of the fraud detection stuff (masks, etc) or give us some statistics on the twin/family member issue.

It mentions infrared picture. Masks probably have a different infrared signature. But so does your face if it's been wearing a balaclava in the cold (some parts will be cold and some will be warm...

I seriously doubt they’re using actual infrared emissions (as in heat measurements), I imagine it’s just used as a simple B&W camera so they don’t need visible light.

Re: FaceID Security [pdf]

#119

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

> Even with the worst biometrics, your phone would be more secure than 99% of houses. And I don't see people complaining about the state of home security...

1. Many (most?) people have more private information on their phones than they do in their house, and there is different risks of each being compromised, so there should be different standards.

2. My impression of the security community is that pretty much everyone uniformly agrees that home security is garbage and needs to be improved.

Re: FaceID Security [pdf]

#120

Recently I posted this theoretical spoofing attack in a comment. I'm glad to know they've put in the appropriate measure to detect it - randomly blinking the IR dot pattern, requiring any spoofed videos to react to the blinking with very near zero lag (likely sub-microsecond). Specifically, the last step in this process could be detected because the generated IR video would have a static dot pattern. How to (not) hac…

Theoretical countermeasure: I get an IR visible tattoo that you can't see in my Facebook pictures but FaceID can. I think the level of equipment needed to pull your attack off couldn't be done off-the-shelf. It seems reasonable that IR camera would scan in detail greater than that of a typical display (say, 500ppi) and it needs 100,000dpi resolution. Then you need bigger displays, advanced optics to reduce it to the expected size without distortion, and so on...
Post reply on HN