Live data from Hacker News

FaceID Security [pdf]

images.apple.com

141–150 of 314 posts

Re: FaceID Security [pdf]

#141
post #116

Earlier quoted context omitted.

It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption. My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.

> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.

It doesn't activate unless you look at the lock screen, so you can just refuse to look at it?

https://www.wired.com/story/iphone-x-faceid-security/

Re: FaceID Security [pdf]

#142

Earlier quoted context omitted.

> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.

It requires you to look at the phone to unlock. Close your eyes or look away and it won't unlock.

> It requires you to look at the phone to unlock. Close your eyes or look away and it won't unlock.

Yeah, I'm going to say that this is an absolutely unrealistic expectation to have of someone who's just gotten detained and is concerned about having the contents of their phone viewed by law enforcement.

"Make sure that you don't open your eyes at any point in the direction where they might be holding your phone" is completely unactionable.

Re: FaceID Security [pdf]

#143

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

I have a house with a standard lock. A couple years ago someone decided to kick the front door in while I was at work. We have shitty house locks because the entire system is terribly insecure and strengthening one link in the chain is pointless.

There are better doors out there:

https://www.youtube.com/watch?v=Bk48kU6fGWc

Re: FaceID Security [pdf]

#144
post #141

Earlier quoted context omitted.

> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.

It doesn't activate unless you look at the lock screen, so you can just refuse to look at it? https://www.wired.com/story/iphone-x-faceid-security/

> It doesn't activate unless you look at the lock screen, so you can just refuse to look at it?

Have you ever been detained?

As far as I'm concerned, "refuse to look at it" is useful as a prevention tactic as not having any lock at all.

Re: FaceID Security [pdf]

#145
post #18

Good document, but I was really hoping they’d go deeper into how they tested some of the fraud detection stuff (masks, etc) or give us some statistics on the twin/family member issue.

It mentions infrared picture. Masks probably have a different infrared signature. But so does your face if it's been wearing a balaclava in the cold (some parts will be cold and some will be warm...

Just guessing here, but veins and blood flow are visible in infra red [1]. A color camera can also measure pulse using small color variations.

[1] https://software.intel.com/en-us/articles/pulse-detection-wi...

Re: FaceID Security [pdf]

#146
post #138
post #42

I was really unhappy about FaceID last week, but if the attention sensing tech works reliably, I think it's probably better --- including under duress --- than TouchID.

i wonder if the feds can compel you to open your eyes

It would seem to be extremely difficult for them to compel you to aim them at a fixed point in space.

Re: FaceID Security [pdf]

#147
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

>I still wish it had an "unlock under duress" mode

I has something else: Don't unlock under duress. You press one of the buttons five times, and the police or a robber can't use your biometrics to unlock it.

It's not the same thing as what you're looking for, but interesting still.

Re: FaceID Security [pdf]

#148
post #116

Earlier quoted context omitted.

It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption. My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.

> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.

Well there is something, you can close your eyes at least.

Re: FaceID Security [pdf]

#149

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

You turn it off until it's been confirmed secure again. This is not much different from any security issue in software -- you disable the functionality until it's secure again.

The only risk is if somebody cracks the entire FaceID model and Apple cannot fix it in software. But even then, you would still disable FaceID and either return your phone or wait for a recall.

Re: FaceID Security [pdf]

#150
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

Love this idea. And doing it with your face allows much easier plausible deniability over something with your hands/touchID.
Post reply on HN