As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
Face ID beaten by mask
51–60 of 244 posts
Re: Face ID beaten by mask
#52So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?
A fingerprint is just a really complex password that you leave on everything you touch. Your face is just a really complex password that is written on the front of your head. It should be self-evident that neither of these is "secure" for some level of "security", but they might be perfectly fine for the level of threat that you face, which is not likely to be particularly high. But I don't know you, so maybe you fac…
Re: Face ID beaten by mask
#53As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
It seems much more secure than fingerprints, since that was defeated much more quickly (within a couple days?), with easily lifted prints and a more cost effective (though still somewhat lengthy) method. This, in comparison, seems much harder and consequently further reduces the realistic attack scenarios where people have to be worried. For most people this is a non-issue. (It mostly already was a non-issue with fin…
I think the biggest difference in time was given by the "attacker" trying to understand what the FaceID system is looking for exactly, as an algorithm. But once they know that, future attacks should be much faster. Like if they try to bypass someone else's phone, it shouldn't take another 7 days. It could even be hours.
With TouchID they already knew what to do - clone someone's fingerprint. There's no machine learning algorithm that needs to be reverse-engineered there.
Re: Face ID beaten by mask
#54Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.
Re: Face ID beaten by mask
#55The 1st point is, everything went much more easily than you expect. You can try it out with your own iPhone X, the phone shall recognize you even when you cover a half of your face. It means the recognition mechanism is not as strict as you think, Apple seems to rely too much on Face ID's AI. We just need a half face to create the mask. It was even simpler than we ourselves had thought. Interesting. I expected this t…
Re: Face ID beaten by mask
#56I hope this does not result in me getting 3D face scanned as I pass through border control
Re: Face ID beaten by mask
#57Would it be possible to just capture the IR beams with a camera, and use a projector to send to the phone's sensor a new set of IR points as they would appear if they were projected on an actual 3D model? This would allow to use only a digital model of a face, without the need for printing it.
Re: Face ID beaten by mask
#58Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.
They realize that at Apple too. Face/Touch ID can be forcefully disabled for enterprise. However for an average Joe this is not a threat.
Re: Face ID beaten by mask
#59As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
Re: Face ID beaten by mask
#60As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
You are correct. Face recognition, like any other biometric, is a bit of a farce. The face doesn't unlock the phone. The face is read by software which then generates some string of numbers, essentially a hash of the face/print, than then unlocks the phone. That hashing process can be hacked/intercepted/replicated just as with any other password. Biometrics is a convenience feature, not security device. But the real reason that biometrics aren't used in highly secure environments it the difficulty of repudiation. If/when a break-in does occur, how exactly does everyone reset their faces? It's like asking everyone to reset their passwords and everyone then using the same passwords. What you have to do is install a new hashing regime and rescan everyone's faces.
The best system, the one that is used most everywhere, is three-factor: (1) A card you carry/scan. (2) A password/code you enter into a pad. (3) An old man behind glass, usually a retired soldier, who has been in the job for years and knows everyone in the building. That old man can recognize people better than any biometric scanner.