Live data from Hacker News

Face ID beaten by mask

bkav.com

111–120 of 244 posts

Re: Face ID beaten by mask

#111

Why not layer on more data? Like a facial gesture (smile, wink, tongue out, etc) and a fingerprint? Both using thermal readings as "proof". Given you're almost always using your face and hands, this isn't much of an inconvenience but it's powers more secure. All for pennies (in comparison to a $1k device). It's infuriating that each time a mass-produced biometric scanner comes out, it's hogtied by the fact this cheap…

This type of 'layering' could be done with other devices in the eco-system, too. The Apple Watch for (a crude) example:

> Does this person have an Apple Watch? Is the device in range? Is it unlocked? Do the wearer's biometrics match?

Most individuals have (for better or worse) bought into the (relatively) closed system of Apple products – why not continue leveraging that to their advantage?

Re: Face ID beaten by mask

#113
post #105
post #101

Earlier quoted context omitted.

No, you can put a thin printed 2d fingerprint onto your finger to fool it.

This isn't true, touchID requires a living person/something that simulates a living person to unlock.

Interesting. Can you point to any official white-paper from Apple claiming this? I'm reading this: https://www.apple.com/business/docs/iOS_Security_Guide.pdf but I cannot find any such information about a living person.

Re: Face ID beaten by mask

#114
post #79
post #62

Earlier quoted context omitted.

> If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance A scanner could be placed e.g. behind or on top of a mirror in a restroom.

Presumably all you would need is another iPhone X to do the scanning.

The data from one iPhone isn’t supposed to be useful to another since the infrared emitters are in a random pattern.

Re: Face ID beaten by mask

#115
post #6

Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.

Biometrics are usernames not passwords That such a meaningless slogan. Passwords and biometrics have different pros and cons, but they are the same in that they increase security. Biometrics should never be used on the sole authentication method * Biometrics is always better than no security. * Biometrics done well is certainly better than a 4-digit PIN. * Biometrics on an iDevice is in fact always used with somethin…

>That such a meaningless slogan. Passwords and biometrics have different pros and cons, but they are the same in that they increase security.

It is not a meaningless slogan, if Biometrics give the wider public a FALSE sense of security in that companies like Apple pitch them in unrealistic and inaccurate ways in their marketing that gives the average Joe the false idea that bio metrics are more secure than they really are, and secure more data that it really does.

>Biometrics is always better than no security.

That not only a pointless statement, but a False Dilemma Fallacy as well

>Biometrics done well is certainly better than a 4-digit PIN.

Done well is the key part, and again that is a False Dilemma Fallacy as you assume the choice is between a 4 digit pin and Biometrics, it is not

> if you manage to steal my fingerprint, you can only use it to access the devices that I have set up to use my fingerprint. This means that my fingerprint alone is not of any value, unless you can also gain physical access to my phone. Compare this with a password which, if stolen, allows attackers on the other side of the globe to access to my accounts.

it is funny you mention that because often time I see people set VERY insecure passwords because they believe that thei biometrics protects their password. So they set a insecure password "They will never use or need" because they relay biometrics and believe it provides all the security they need not just the security of the device, but since they only access their data from that device they are lulled in a false sense of security that the biometrics are protecting not only their device but ALL OF THEIR ACCOUNTS

Re: Face ID beaten by mask

#116
post #95

Can sombebody explain this: "A: It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask." Does it mean passcode was completely off and the phone would n…

They don't answer directly and clearly to almost every question, or simply evade them like this first one. Weird, especially considering they've written both questions and answers.

Re: Face ID beaten by mask

#117
What stops someone from taking the phone and "flash" it to your face, having the phone unlocked before you understand what's going on. Or do you have to hold the phone to the face while typing the password ?

Re: Face ID beaten by mask

#118
When I saw the headline I said: "Of course wearing a mask would defeat it!" But I was thinking of facial recognition as the invasive technology being used by governments to further destroy what's left of our privacy in public (an oxymoron, I guess). I think about all those '80s sci fi movies where the urchins and street hackers all had makeup lines on their faces which I thought was just the costume makers being "edgy" but it turns out it had a backstory--people were attempting to disrupt face scanners. How did they know this in the 1980s?

Re: Face ID beaten by mask

#119
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

> As for fingerprints versus facial recognition, the article claims fingerprints are better, but I’m skeptical. For one thing, my phone is covered in my own fingerprints, so getting something to copy is a lot easier.

Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone?

I'm only half-serious, but it might make lifting the real prints harder...

(maybe it is trivial to distinguish prints made on a surface from those in the structure of the surface)

Re: Face ID beaten by mask

#120
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.
Post reply on HN