Live data from Hacker News

Face ID beaten by mask

bkav.com

51–60 of 244 posts

Re: Face ID beaten by mask

#51
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

It's definitely a better situation than an attacker being able to steal your fingerprint off a glas or other everyday object. Copying a fingerprint requires very little skill.

Re: Face ID beaten by mask

#52
post #22
post #13

So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?

A fingerprint is just a really complex password that you leave on everything you touch. Your face is just a really complex password that is written on the front of your head. It should be self-evident that neither of these is "secure" for some level of "security", but they might be perfectly fine for the level of threat that you face, which is not likely to be particularly high. But I don't know you, so maybe you fac…

Advanced fingerprint recognition devices recognize things that are not left on things that you touch. They look under the skin at blood vessel and measure body capacitance and other statistics. That's why there is the weird light on the "biometrics" device in the airport, to be able to see through the outer layers of skin.

https://en.wikipedia.org/wiki/Finger_vein_recognition

Re: Face ID beaten by mask

#53
post #36
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

It seems much more secure than fingerprints, since that was defeated much more quickly (within a couple days?), with easily lifted prints and a more cost effective (though still somewhat lengthy) method. This, in comparison, seems much harder and consequently further reduces the realistic attack scenarios where people have to be worried. For most people this is a non-issue. (It mostly already was a non-issue with fin…

TouchID was spoofed in 2 days and FaceID in 7 days. Still, I feel like the difference in time is not that relevant.

I think the biggest difference in time was given by the "attacker" trying to understand what the FaceID system is looking for exactly, as an algorithm. But once they know that, future attacks should be much faster. Like if they try to bypass someone else's phone, it shouldn't take another 7 days. It could even be hours.

With TouchID they already knew what to do - clone someone's fingerprint. There's no machine learning algorithm that needs to be reverse-engineered there.

Re: Face ID beaten by mask

#54
post #6

Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.

They realize that at Apple too. Face/Touch ID can be forcefully disabled for enterprise. However for an average Joe this is not a threat.

Re: Face ID beaten by mask

#55
post #4

The 1st point is, everything went much more easily than you expect. You can try it out with your own iPhone X, the phone shall recognize you even when you cover a half of your face. It means the recognition mechanism is not as strict as you think, Apple seems to rely too much on Face ID's AI. We just need a half face to create the mask. It was even simpler than we ourselves had thought. Interesting. I expected this t…

There was also a rumor that Apple was having trouble with FaceID recognizing people (it even happened to Craig Federighi on stage!), and they made the security less strict so it recognizes people more easily. For all we know, FaceID doens't have that "1 in a million" False Acceptance Rate" anymore, but only 100,000 which would be a lot closer to a fingerprint.

Re: Face ID beaten by mask

#57
post #34

Would it be possible to just capture the IR beams with a camera, and use a projector to send to the phone's sensor a new set of IR points as they would appear if they were projected on an actual 3D model? This would allow to use only a digital model of a face, without the need for printing it.

You'd need a very precise IR projector. That's likely very far away from a DIY home made solution in terms of costs.

Re: Face ID beaten by mask

#58
post #6

Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.

They realize that at Apple too. Face/Touch ID can be forcefully disabled for enterprise. However for an average Joe this is not a threat.

Can you require both face and password?

Re: Face ID beaten by mask

#59
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

Another thing is that an attacker only gets a few chances to use the face unlock before the phone requires a pin. How many tries did it take them while having to re-enable FaceId after locking the phone? IMO, it's only 'broken' if they can get the face right the first time without causing the phone to lock itself.

Re: Face ID beaten by mask

#60
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

>> For spies, spooks, government agents etc. I suspect that Face ID would always be a no-no

You are correct. Face recognition, like any other biometric, is a bit of a farce. The face doesn't unlock the phone. The face is read by software which then generates some string of numbers, essentially a hash of the face/print, than then unlocks the phone. That hashing process can be hacked/intercepted/replicated just as with any other password. Biometrics is a convenience feature, not security device. But the real reason that biometrics aren't used in highly secure environments it the difficulty of repudiation. If/when a break-in does occur, how exactly does everyone reset their faces? It's like asking everyone to reset their passwords and everyone then using the same passwords. What you have to do is install a new hashing regime and rescan everyone's faces.

The best system, the one that is used most everywhere, is three-factor: (1) A card you carry/scan. (2) A password/code you enter into a pad. (3) An old man behind glass, usually a retired soldier, who has been in the job for years and knows everyone in the building. That old man can recognize people better than any biometric scanner.

Post reply on HN