Live data from Hacker News

FaceID Security [pdf]

images.apple.com

191–200 of 314 posts

Re: FaceID Security [pdf]

#191

Earlier quoted context omitted.

https://www.theverge.com/2017/8/17/16161758/ios-11-touch-id-... is how you work around that issue. Keep in mind, you don't need to refuse to TouchID/FaceID forever, just for the timeout (which I do wish was configurable -- I think one hour is reasonable).

Here's the sequence of events: 1. You're walking, with your phone in your pocket. 2. Suddenly, a cop accosts you. You don't have time to react. 3. They detain and restrain you (with handcuffs or otherwise) 4. They pat you down and find your phone 5. They hold up your phone to your face to unlock it I know that people who've never been detained or interacted much with cops think that this is a completely unlikely situ…

As someone who has been stopped/questioned/detained before domestically and internationally (as well as at border checkpoints) as well as mugged, I can assure you that touch vs look is pretty much the same (definitively not light years in difference). The solution is to be proactive. If you are going to walk down the street in an at risk area, you hit the power button five times. If you are about to go through a CBP checkpoint, then do the same. When you go to sleep, do the same (admittedly TouchID is more susceptible here than FaceID).

FaceID / TouchID are a "convenience" to be used when you are comfortable with your surroundings. Can you be caught off guard even when you are paranoid? Of course, nothing is ever guaranteed in life, except death and taxes as the saying goes!

Re: FaceID Security [pdf]

#192

Earlier quoted context omitted.

It requires you to look at the phone to unlock. Close your eyes or look away and it won't unlock.

> It requires you to look at the phone to unlock. Close your eyes or look away and it won't unlock. Yeah, I'm going to say that this is an absolutely unrealistic expectation to have of someone who's just gotten detained and is concerned about having the contents of their phone viewed by law enforcement. "Make sure that you don't open your eyes at any point in the direction where they might be holding your phone" is c…

> is completely unactionable.

As is the assumption you won't be forced to touch your finger to the phone. I can assure you, if someone wants into your phone bad enough, they will break your fingers if thats what it takes.

Re: FaceID Security [pdf]

#193

Earlier quoted context omitted.

It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.

There is a way to quickly disable face id, presumably you would do so in most situations when facing police.

There's also a way to break in your house whilst you're gone or asleep. In the former case, if the device is in your house, would you've disabled FaceID? In the latter case, would you've disabled FaceID? Would you've disabled FaceID when you were going outside (with your device) and you'd be busted then? Answer in all these cases: Of course not.

So a PIN alone would've been more secure. It'd have cost the government more effort to crack. A strong password or TOTP would've been a better solution. Pref. 2FA w/both.

You could use FaceID as 2FA, but then people need to keep in mind that its a very weak chain in the 2FA. They still need a strong other factor ie. a strong password.

Re: FaceID Security [pdf]

#194

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

This is farcical.

Re: FaceID Security [pdf]

#195

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

My twin can't use his house key to get into my house.

Re: FaceID Security [pdf]

#196

Earlier quoted context omitted.

Until what's fixed in software? Your face being compromised? You can't fix a leaked secret in software.

You are implying that there is a "secret" based on that face mapping that can be copied out of the device and then used to either 1) gain access to a non-Apple system that has some kind of biometric face detection system or 2) can be used to reproduce a face like yours to unlock your phone without you present From the PDF: "Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads ov…

Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too.

This is trivial to do if the person is in custody. You could also profile a specific target and get their face walking past them on the street. You could do this in bulk in a public place.

Now your face is compromised and the person who stole it likely posesses your phone and is unlocking it now. You can't change your face, but it's too late anyway. You live in an oppressive regime, they found out you're gay from what they found in your phone, and you're going to be hanged in a week.

Re: FaceID Security [pdf]

#197
post #117
post #108

Earlier quoted context omitted.

https://danielmiessler.com/blog/why-biometric-data-breaches-... I submitted this earlier today but it didn’t get traction. Basically it could be done.

But your argument makes no sense. The attack isn't "someone stole the processed image ("stick figure") of my fingerprint", the attack is someone copied my fingerprint .

That’s TouchID. Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you?

The fingerprint argument isn’t an argument against FaceID. And it’s still kind of pointless because Apple put out figures a few years ago that TouchID lead to a ~50% INCREASE in locked phones.

You seem to be arguing that a secure passcode without biometrics is better. It seems that if the public can’t use biometrics they prefer NO security. So even with that ‘flaw’ it’s no worse (often MICH better) for everyone.

Re: FaceID Security [pdf]

#198

Earlier quoted context omitted.

You can't!? Wow, thanks for teaching me that. Did you even read what I wrote? You would turn off FaceID and revert back to a passcode/passphrase until it is fixed in software.

Until what's fixed in software? Your face being compromised? You can't fix a leaked secret in software.

[deleted]

Re: FaceID Security [pdf]

#199

Earlier quoted context omitted.

To the extent the police can legally compel you to provide access to a device, the means by which that access is protected does not impede their legal capability to do it and impose consequences for non-compliance.

That's the thing -- the police can't legally compel you to provide them access to your device, but if they can get it without you having to give them anything, by, say, pointing the phone at your face, it's fair game. I don't have time to look up the court precedents about this, but that's my understanding of the current state of the law.

I misread the upthread comment as implying that FaceID “passwords” were more legally secure than regular passwords, not just more legally secure than plain FaceID.

I agree that the description you provide is generally correct.

Re: FaceID Security [pdf]

#200

Earlier quoted context omitted.

You are implying that there is a "secret" based on that face mapping that can be copied out of the device and then used to either 1) gain access to a non-Apple system that has some kind of biometric face detection system or 2) can be used to reproduce a face like yours to unlock your phone without you present From the PDF: "Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads ov…

Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…

Ignoring the rediculous level of technical sophistication needed...

You can’t ‘get their face’ if they’re ‘walking by’, you have to go through the whole enrollment. How are you going to trick them into that?

Also even if they go through some Herculean process to get your ‘face hash’ Apple could simply change the hash algorithm and reset it. For all we know different phones will use a different per-device random seed in the algorithm and that attack wouldn’t work at all even if the algorithm isn’t changed.

Again, you’re talking about getting a fully accurate 3D model of someone’s face that passes the FaceID tests and can be used to trick the attention sensors. That’s an INSANE level of effort for Joe random.

This is not a realistic attack, and FaceID is not designed to secure anyone at any time from any government with unlimited funds and resources. It’s designed to be better than the trivial passcodes that almost no one used.

Post reply on HN