Live data from Hacker News

Face ID beaten by mask

bkav.com

71–80 of 244 posts

Re: Face ID beaten by mask

#71
post #6

Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.

Biometrics are usernames not passwords

That such a meaningless slogan. Passwords and biometrics have different pros and cons, but they are the same in that they increase security.

Biometrics should never be used on the sole authentication method

* Biometrics is always better than no security.

* Biometrics done well is certainly better than a 4-digit PIN.

* Biometrics on an iDevice is in fact always used with something else, which is device itself: Touch/FaceID on an iPhone can only be used to access that particular iPhone. Ie. if you manage to steal my fingerprint, you can only use it to access the devices that I have set up to use my fingerprint. This means that my fingerprint alone is not of any value, unless you can also gain physical access to my phone. Compare this with a password which, if stolen, allows attackers on the other side of the globe to access to my accounts.

Re: Face ID beaten by mask

#72
post #59

Earlier quoted context omitted.

Another thing is that an attacker only gets a few chances to use the face unlock before the phone requires a pin. How many tries did it take them while having to re-enable FaceId after locking the phone? IMO, it's only 'broken' if they can get the face right the first time without causing the phone to lock itself.

Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?

Doesn't sound like they took that approach:

> However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.

Re: Face ID beaten by mask

#73

Earlier quoted context omitted.

Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?

Doesn't sound like they took that approach: > However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.

I was confused by this at first. I thought one of the concerns was the the algorithm would be more discerning about the real face over time. It doesn't seem as though they've addressed this issue.

Re: Face ID beaten by mask

#75
post #51
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

It's definitely a better situation than an attacker being able to steal your fingerprint off a glas or other everyday object. Copying a fingerprint requires very little skill.

I thought you needed a 3D fingerprint to fool an iPhone—a holding from an impression in clay rather than a spear on a window.

Re: Face ID beaten by mask

#76
post #59

Earlier quoted context omitted.

Another thing is that an attacker only gets a few chances to use the face unlock before the phone requires a pin. How many tries did it take them while having to re-enable FaceId after locking the phone? IMO, it's only 'broken' if they can get the face right the first time without causing the phone to lock itself.

Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?

That's not what I'm saying. They made a face that managed to trick the FaceId, but how many times did they have to test it? In a real world situation, the face would have to work in 3 tries or the phone locks itself with a passcode. Given the elaborate process they went through to make the face, it would be very hard to make a face that basically works the first time (I've noticed FaceId will try multiple times and lock pretty quickly).

Re: Face ID beaten by mask

#77
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

>If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried.

I would be astonished if state actors are not already well on their way to figuring out how to do this.

Re: Face ID beaten by mask

#78
I would really appreciate an option for 2FA: Require both a PIN and Touch ID / Face ID to unlock the phone. With long passphrase to disable this again.

Re: Face ID beaten by mask

#79
post #62
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

> If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance A scanner could be placed e.g. behind or on top of a mirror in a restroom.

Presumably all you would need is another iPhone X to do the scanning.

Re: Face ID beaten by mask

#80
post #59

Earlier quoted context omitted.

Another thing is that an attacker only gets a few chances to use the face unlock before the phone requires a pin. How many tries did it take them while having to re-enable FaceId after locking the phone? IMO, it's only 'broken' if they can get the face right the first time without causing the phone to lock itself.

Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?

No, Face ID takes another snapshot after the passcode has been entered.

Source: "Face ID takes another capture and augments its enrolled Face ID data" https://images.apple.com/business/docs/FaceID_Security_Guide...

Post reply on HN