Earlier quoted context omitted.
That doesn't really make sense. If they take your phone while you're gone or asleep, FaceID is worthless to the attacker anyways because they'd either not be attentive or they wouldn't have your face at all . On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked. Either way, you'd be covered. The only situation w…
> On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked. You know how and where Ross Anderson was busted? This is peanuts to beat. You bust the target whilst they're on a dinner having a drink, or right after they went asleep. The government knows your current position, and knows when you're asleep. Once this has…
FaceID Security [pdf]
271–280 of 314 posts
Re: FaceID Security [pdf]
#272Earlier quoted context omitted.
That’s TouchID. Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you? The fingerprint argument isn’t an argument against FaceID. And it’s still kind of pointless because Apple put out figures a few years ago that TouchID lead to a ~50% INCREASE in locked phones. You seem to be arguing that a secure passcode without biometrics is…
"Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you?" Plenty of phones and cameras have 3D capability. That kind of tech is already being used in cosmetology courses to 3D print a model of your own face and hair for hairstyling practice. It wouldn't be that difficult to make a warm 3D mask to fool the infrared camera and sensor…
I mean sure you can knock someone out and use a handheld 3D scanner to get a whole bunch of good shots of them but that’s hardly someone walking down the street and you getting a quick grab of their face.
My point isn’t that it’s impossible it’s that it’s not feasible for any normal person or group without a large and noticeable undertaking. These are not reasonable threat models for normal people.
Re: FaceID Security [pdf]
#273Earlier quoted context omitted.
Or I guess our detection of risk differs. I have never been detained when I didn't have a "hair on my neck raise" with enough time to disable my phone. If you are in such high risk situations continuously that "be proactive when you're at-risk" is appreciably the same as "don't use FaceID ever", then I say you are doing something very wrong and not just incidentally being stopped for a suspicion of possibly doing som…
Even for long alphanumeric passcodes, a pipe wrench has a 99.99% effectiveness in passcode discovery, given sufficiently bad actors. https://xkcd.com/538/
The biometric attacks being discussed here are ones that could quite plausibly be used against you in many/most districts in the US, and be totally legal for the police to use.
Re: FaceID Security [pdf]
#274Earlier quoted context omitted.
Apple wants this to work in total darkness. So color wouldn’t work. Do we know if they’re projecting IR light (besides the dot pattern) that they could use to look for blood vessels?
Yes. The iPhone X has something literally called the "Flood illuminator" which projects IR light. This is one of the many reasons FaceID is not reactively available to previous iPhones via a software update. > The flood illuminator produces infrared (IR) light, part of the electromagnetic spectrum that's invisible to the naked eye, to illuminate your face; https://www.forbes.com/sites/jvchamary/2017/09/16/how-face-i.…
I guess that leads back to my question (in another comment) about whether or not face paint would effect it.
Re: FaceID Security [pdf]
#275Earlier quoted context omitted.
I seriously doubt they’re using actual infrared emissions (as in heat measurements), I imagine it’s just used as a simple B&W camera so they don’t need visible light.
Since I’ve been downvoted and I can no longer edit, let me try to explain my theory: I’m guessing they only use the camera to read the positions of the dots projected onto the face. I don’t think they care about the ‘color’ of the face or how hot it is thermally. They’ve said they’re projecting the infrared dots? Have they said they’re doing any other kind of infrared illumination like the kind that can show blood ve…
Now I’m even more curious about the face paint.
Re: FaceID Security [pdf]
#276Earlier quoted context omitted.
You are implying that there is a "secret" based on that face mapping that can be copied out of the device and then used to either 1) gain access to a non-Apple system that has some kind of biometric face detection system or 2) can be used to reproduce a face like yours to unlock your phone without you present From the PDF: "Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads ov…
Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…
Second, the point of using an IR image (in addition to the depth image) is that a simple 3D print is not going to provide valid spoofing - it will not match the IR absorption profile of a live face. Additionally, they are also likely testing for liveness by looking for changes from image to image, even if it’s just saccades of the eyes.
Third, Apple implies that they are taking a sequence of images. They can, for example, look for changes in IR images associated with blood flow correlated with your heartbeat, which prove you are alive and may be distinguishing from individual to individual. The secure enclave could also request specific changes in the images that can’t be predicted in advance, thus foiling attempts at feeding in canned images.
In short, I don’t think it’s anywhere near as simple as you propose.
Re: FaceID Security [pdf]
#277Earlier quoted context omitted.
Reading the linked PDF: > To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern. and > An additional neural network that’s trained to spot and resist spoofing defends against attempts to unlock your phone with photos or masks. It's effectiveness is yet to be seen, but the implementation details count…
I just honestly don't believe it could be effective. The randomized pattern could be detected with an infared camera, and neural nets are easily fooled.
Re: FaceID Security [pdf]
#278Earlier quoted context omitted.
That’s TouchID. Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you? The fingerprint argument isn’t an argument against FaceID. And it’s still kind of pointless because Apple put out figures a few years ago that TouchID lead to a ~50% INCREASE in locked phones. You seem to be arguing that a secure passcode without biometrics is…
"Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you?" Plenty of phones and cameras have 3D capability. That kind of tech is already being used in cosmetology courses to 3D print a model of your own face and hair for hairstyling practice. It wouldn't be that difficult to make a warm 3D mask to fool the infrared camera and sensor…
Re: FaceID Security [pdf]
#279Earlier quoted context omitted.
I keep hoping that FaceID will also get FacePassword, where you have to show one or more expressions in order. Then it becomes a password, and the police can't force you to change your expression.
That's a pretty fantastic idea. I think even courts will find that the government can't compel you to change your face expression, as they tend to do that for anything the government can't physically force you to do anyway. For instance, they say the government forcing you to unlock with your fingerprint is legal, because the government's agents can use force to put your finger on the phone anyway. So it's legal. But…
Re: FaceID Security [pdf]
#280Earlier quoted context omitted.
Apple’s studies/metrics showed that basically no one (5-10%?) used passwords or pins before TouchID. You already have to educate them to use a password, is it that hard to say ‘and don’t use biometrics either’?
No, now you have an additional problem, because they might ignore the advice to use a password now that they think their device is secure by default