So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?
A fingerprint is just a really complex password that you leave on everything you touch. Your face is just a really complex password that is written on the front of your head. It should be self-evident that neither of these is "secure" for some level of "security", but they might be perfectly fine for the level of threat that you face, which is not likely to be particularly high. But I don't know you, so maybe you fac…
Face ID beaten by mask
81–90 of 244 posts
Re: Face ID beaten by mask
#82Re: Face ID beaten by mask
#83Earlier quoted context omitted.
Two words: incremental improvement. 3d printing is getting better and cheaper all the time. Cameras and software are getting better all the time. If someone cares enough to invest the R&D it should be pretty easy to automate everything between getting photos someone and printing the mask. The point is that using biometric authentication as an all-in-one isn't secure.
Photos are not enough, they would need a high resolution 3D scan on the person’s face as well. Also they didn’t just use 3D printing, they had to use different fabrication methods and materials for different parts of the face part of which was ‘simply’ hand sculpted. This is not at all trivial to automate. But then we already know it’s not as secure as two factor authentication and a random passcode. Touch ID could b…
My guess on how those attacks will develop in the future are:
1. Exploit occlusions. As far as I know the FaceID System does work with occluded faces (glasses, maybe scarfs in the winter, ...). Once you know what the minimum required visible area is, you can focus on partial faces. If the algorithm has less features to identify, it probably makes more mistakes and is easier to fool.
2. Create a low-dimensional (in terms of parameters, not vertices) representation of a face that can be tuned to mimic a wide variety of target faces and still is correctly identified by Face ID. Once you have that you can take a few photos of your target person and tune the parameters in your generic model to fit the person in the photos, and probably be even able to reconstruct a mask from far away.
3. Try to create a real mask with a flexible surface that can be tuned to fit a wide range of faces. If at all possible try to span the same feature space as in 2.) as it would allow you to create a real face mask from only the few parameters that directly come from your fitting process.
If all of the above works an attacker can create an Iphone stealing pipeline:
Have several cameras set up in a crowded tourist spot. Match persons in different views and try to reconstruct their faces. Once the system has found a person that has been viewed from enough angles, "retrieve" his phone unlock it with the mask and reset it.
I know that does sound pessimistic, but your face is a "security token" but one which you can not realistically protect from theft. Unless you want it to have serious negative impact on your daily routine.
And if someone wants to hide his face while in public (i.e. with a surgical mask), he can no longer travel to certain countries. I live in Austria and there just recently came a law into effect that bars everyone from occluding their face while in public.
Re: Face ID beaten by mask
#84Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.
Biometrics are biometrics. They're distinct from username and passwords.
They can be used for low effort access control, the same way that most locks are easy to pick or bypass but are still useful to block crimes of opportunity.
Re: Face ID beaten by mask
#85So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?
Someone could just hold a gun to your head or to your partner/child and then it's irrelevant what the security mechanism is. You are going to hand over the credential since your privacy is not more important than your life.
Re: Face ID beaten by mask
#86Earlier quoted context omitted.
> If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance A scanner could be placed e.g. behind or on top of a mirror in a restroom.
Presumably all you would need is another iPhone X to do the scanning.
Re: Face ID beaten by mask
#87I hope this does not result in me getting 3D face scanned as I pass through border control
I think the "self-service" passport gates in the EU already do this.
Although I am not sure if it's based on your head or just scanning your iris.
Re: Face ID beaten by mask
#88As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
Two words: incremental improvement. 3d printing is getting better and cheaper all the time. Cameras and software are getting better all the time. If someone cares enough to invest the R&D it should be pretty easy to automate everything between getting photos someone and printing the mask. The point is that using biometric authentication as an all-in-one isn't secure.
Well, the same applies to the iPhoneX and its software, I suppose.
Re: Face ID beaten by mask
#89> Because... we are the leading cyber security firm ;) But you don't even use HTTPS. Why?
Re: Face ID beaten by mask
#90The 1st point is, everything went much more easily than you expect. You can try it out with your own iPhone X, the phone shall recognize you even when you cover a half of your face. It means the recognition mechanism is not as strict as you think, Apple seems to rely too much on Face ID's AI. We just need a half face to create the mask. It was even simpler than we ourselves had thought. Interesting. I expected this t…
There was also a rumor that Apple was having trouble with FaceID recognizing people (it even happened to Craig Federighi on stage!), and they made the security less strict so it recognizes people more easily. For all we know, FaceID doens't have that "1 in a million" False Acceptance Rate" anymore, but only 100,000 which would be a lot closer to a fingerprint.