Live data from Hacker News

FaceID Security [pdf]

images.apple.com

221–230 of 314 posts

Re: FaceID Security [pdf]

#221

Earlier quoted context omitted.

> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.

I heard in another comment in this thread it has focus detection, so you would have to look at the phone for it to unlock. Can not find any other source of this though.

> Can not find any other source of this though.

It's in the marketing materials for the phone, was mentioned multiple times on stage during the introduction, and is in the introduction to the whitepaper that this entire HN thread is about. So yeah - a couple of sources are available...

Re: FaceID Security [pdf]

#222
post #201

Earlier quoted context omitted.

Apple’s studies/metrics showed that basically no one (5-10%?) used passwords or pins before TouchID. You already have to educate them to use a password, is it that hard to say ‘and don’t use biometrics either’?

No, now you have an additional problem, because they might ignore the advice to use a password now that they think their device is secure by default

Would they? The only data we have says that even though people should secure things they don’t. Is it really going to be that different for people who have a REALLY good reason? I kind of doubt it.

And does it matter? If a government wants to repress they’ll do it. They’ll beat you or harass you or something like that.

“Well we think you’re trying to overthrow us but FaceID is turned off on your phone. I guess we’ll give up today. You’re free to go, have a nice time. ”

Re: FaceID Security [pdf]

#223

Earlier quoted context omitted.

It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.

I keep hoping that FaceID will also get FacePassword, where you have to show one or more expressions in order. Then it becomes a password, and the police can't force you to change your expression.

That's a pretty fantastic idea. I think even courts will find that the government can't compel you to change your face expression, as they tend to do that for anything the government can't physically force you to do anyway. For instance, they say the government forcing you to unlock with your fingerprint is legal, because the government's agents can use force to put your finger on the phone anyway. So it's legal. But the government can't force you to "remember" your password. So trying to do that is illegal.

Re: FaceID Security [pdf]

#224
post #41
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

Well, I understand that I kinda have to trust Apple but given Apple have my decrypted contents, shouldn't flagging something as highly sensitive be considered a bad move? There are circumstances that Apple are obliged to provide with law enforcement what they have, and can't tell you that they provided it. Having said that, nothing beats an unsynced phone with a long password. No faceId, no AI recognition, no iris, n…

> given Apple have my decrypted contents

Where exactly is Apple storing the entire content of your iOS device unencrypted? Hint - they're not...

[1] https://support.apple.com/en-us/HT202303

Re: FaceID Security [pdf]

#225

Earlier quoted context omitted.

Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode. Either way, let's say this attack you're talking about is possible. What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "…

>Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode. You don't need to shut off the phone to get into the hardware. >What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "tri…

> You don't need to shut off the phone to get into the hardware.

I'm genuinely curious if this has been done before and if you can provide examples.

Re: FaceID Security [pdf]

#226

Earlier quoted context omitted.

It's a competitive move; it gives Apple and their users a bragging point, causing competition an expensive countermove. Competition has to move to depth sensor cameras and more on their phones, while Apple is reducing the expense and improving the quality of theirs. The Face ID tech is immature today, but a quarter or three? The quarter after that once support issues have had a few cycles, and the Face ID team has it…

Pardon my ignorance. FR industry? Foreign Relations? First Responder? Flame Resistant? Google was no help. Edit: Oh, do you mean facial recognition?

FR = Facial Recognition.

Re: FaceID Security [pdf]

#227

Earlier quoted context omitted.

>Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode. You don't need to shut off the phone to get into the hardware. >What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "tri…

> You don't need to shut off the phone to get into the hardware. I'm genuinely curious if this has been done before and if you can provide examples.

I don't have anything handy, I'm afraid, but the idea is sound from an electronics perspective. Definitely raises the implementation cost of this attack, though.

Re: FaceID Security [pdf]

#228
post #163

Earlier quoted context omitted.

The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.

Searching through your phone seems like an action that would require a warrant.

Re: FaceID Security [pdf]

#229

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

> And I don't see people complaining about the state of home security... Home security is a really poor analogy. * Attacking everybody's house at once is not scalable, unlike attacking many people's electronic devices at once. Furthermore, defending against a SWAT team armed with a search warrant is nigh impossible, no matter what lock you put on your front door. * The contents of most people's houses is far more wei…

How do you attack everyone’s physical camera at once? Sure you could attack other implementation details of the device remotely and “at once” — but how is that relevant to the faceid use case?

Re: FaceID Security [pdf]

#230

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

The thing is I'm not really too concerned about my home's physical security (I lock the door, but the entire attack surface area is too large for my risk profile to lock it down extensively). If the cops want to search my house, they can kick the door in. If a thief wants to take something they can break a window. If a fraudster wants to trick my landlord into letting them in they could do so. As a result truly important property and information is fully secured using passcodes and pin numbers.
Post reply on HN