Live data from Hacker News

FaceID Security [pdf]

images.apple.com

251–260 of 314 posts

Re: FaceID Security [pdf]

#251
I'm pretty late to this and I'm sure this will get buried...

> Face ID data doesn’t leave your device, and is never backed up to iCloud or anywhere else. Only in the case that you wish to provide Face ID diagnostic data to AppleCare for support will this information be transferred from your device. Enabling Face ID Diagnostics requires a digitally signed authorization from Apple that’s similar to the one used in the software update personalization process. After authorization, you'll be able to activate Face ID Diagnostics and begin the setup process from within the Settings app of your iPhone X.

What is preventing the government from compelling Apple to give up this key, and intercept your diagnostic data?

Re: FaceID Security [pdf]

#253
post #190

Earlier quoted context omitted.

The problem with biometrics is not username vs password, biometrics are password. The problem is that these are client-side protections, and there's no data sent to a server that can verify the identity. And you can't build a remote identity verification with this data, because there's no way for the user to change it and revoke it (let alone it's very privacy sensitive). The biometric access control systems (the one…

> The problem with biometrics is not username vs password, biometrics are password. Yes, that is the problem. No, biometrics are not password. Please stop spouting this nonsense? Biometrics are akin to username; they suggest your identity, but don't authenticate you. They should not be used as password because they cannot be changed, and cannot be kept secret. A password (or better, TOTP authentication) can be change…

That's not entirely true either, though. Biometrics cannot be revoked but they don't need to be. Biometrics are just using your face/finger/etc to provide a basis for which to verify identity. If someone is able to fraudulently unlock FaceID on a consistent basis, then Apple just needs to change what information is being generated or secured. Infrared cameras and dot projection offer so many different variations of how that information can be used that the only way someone could break the security permanently would be to make a copy of your face 100%. Just because a specific infrared dot pattern of your face is copied doesn't mean that every dot pattern or feature of your face is useless. Maybe the next iteration of FaceID will also count the pores on your face or the number of hairs. A fingerprint/face cannot be revoked but the method of detection/recognition can be both revoked and changed.

Re: FaceID Security [pdf]

#254
post #34
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

They wouldn't have to do any work. It'd be an OS level implementation. In the same way that you can customize what apps receive/show notifications, you could choose which apps are sandboxed in the "duress" mode. Anything outside of that would be optional security for developers to implement.

Re: FaceID Security [pdf]

#255

Earlier quoted context omitted.

It could be something as simple as having one eye closed when under duress(sorry, monoculars!). It only takes one unlock attempt to then lock it down. Bonus with this is that LE couldn't hold the phone up to your face while you are sleeping to unlock it.

I see two problems with that. 1) Everyone now knows that the duress signal is one eye 2) people with one eye (or at least as far as the algorithm is concerned) cannot use the service. Which say, you got beat up and one eye was swelling you might accidentally set it into duress mode, when you need the full mode and you bypass the password override. I just think that a duress mode with facial recognition (that also has…

I think the point was that the user would get to choose what their duress trigger would be. For some it would be one eye, for others a tongue, for still others it might be a swipe on the phone or 3 taps and a swipe...

Re: FaceID Security [pdf]

#256
post #251

I'm pretty late to this and I'm sure this will get buried... > Face ID data doesn’t leave your device, and is never backed up to iCloud or anywhere else. Only in the case that you wish to provide Face ID diagnostic data to AppleCare for support will this information be transferred from your device. Enabling Face ID Diagnostics requires a digitally signed authorization from Apple that’s similar to the one used in the…

Diagnostic data still wouldn't provide anything of value as both sides need to give up the key for it to be useful.

Re: FaceID Security [pdf]

#257

I'd like to know how iPhone X users control (play pause) apps directly from their lockscreens. That no longer works right? Isn't that a major disadvantage?

You have access to control center from anywhere in the OS. There's a "Now Playing" piece that comes up with a single swipe from the bottom of the screen. If you're not looking at the screen, Now Playing still displays on the lock screen.

Re: FaceID Security [pdf]

#258
post #163

Earlier quoted context omitted.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.

In the United States, the Supreme Court does not allow warrantless cell phone searches. https://en.wikipedia.org/wiki/Riley_v._California

The police holds up the phone, pointing towards the suspect:

Detective: "Is this yours?"

_Suspect glances in the direction indicated, phone unlocks._

Detective: "Nevermind, I got it from here."

-----

At least TouchID required physical assault to get you to unlock the phone. FaceID on the other hand can be defeated with perfectly legal attention grabbing techniques.

Re: FaceID Security [pdf]

#259
post #193

Earlier quoted context omitted.

There's also a way to break in your house whilst you're gone or asleep. In the former case, if the device is in your house, would you've disabled FaceID? In the latter case, would you've disabled FaceID? Would you've disabled FaceID when you were going outside (with your device) and you'd be busted then? Answer in all these cases: Of course not. So a PIN alone would've been more secure. It'd have cost the government…

That doesn't really make sense. If they take your phone while you're gone or asleep, FaceID is worthless to the attacker anyways because they'd either not be attentive or they wouldn't have your face at all . On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked. Either way, you'd be covered. The only situation w…

> On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked.

You know how and where Ross Anderson was busted?

This is peanuts to beat. You bust the target whilst they're on a dinner having a drink, or right after they went asleep. The government knows your current position, and knows when you're asleep. Once this has become the status quo, rest assured cops with a police warrant wouldn't enter anymore at 6 AM right before you wake up but at 1 AM right after you went asleep (but before your FaceID would time out).

> (which would be very rare since it would just require you to squeeze both sides and you'd have the chance to do that while performing the action of handing your phone over).

Law enforcement will adapt very quickly to that if this becomes the status quo. They'll first and foremost bust your hands, so that you are unable to lock your phone. Then they hold the phone before you and voila, unlocked.

Re: FaceID Security [pdf]

#260

Earlier quoted context omitted.

I see two problems with that. 1) Everyone now knows that the duress signal is one eye 2) people with one eye (or at least as far as the algorithm is concerned) cannot use the service. Which say, you got beat up and one eye was swelling you might accidentally set it into duress mode, when you need the full mode and you bypass the password override. I just think that a duress mode with facial recognition (that also has…

I think the point was that the user would get to choose what their duress trigger would be. For some it would be one eye, for others a tongue, for still others it might be a swipe on the phone or 3 taps and a swipe...

I think with current technology that'd make the training prohibitive unless you boiled it down to a few options. Which would still likely result in false positives. I mean, this stuff isn't magic.

OR you could use the face as a username, as many suggest, and a short 4 pin password. You could easily have a duress password option (which as far as I know doesn't exist), still quickly log in, AND have fairly good security.

Post reply on HN