Live data from Hacker News

Face ID beaten by mask

bkav.com

121–130 of 244 posts

Re: Face ID beaten by mask

#121
post #120
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

Apple specifically recommends to law enforcement using a deceased suspect’s fingerprint while the device will still accept it to bypass encryption.

Re: Face ID beaten by mask

#122
post #45
post #21

Earlier quoted context omitted.

> We used a popular 3D printer. Nose was made by a handmade artist. We use 2D printing for other parts (similar to how we tricked Face Recognition 9 years ago). The skin was also hand-made to trick Apple's AI. That seems reasonably obscure (:

This is the first step, it's only going to get easier from now on.

Sure, but Face ID will also evolve.

Re: Face ID beaten by mask

#123
I’d really like to see more details about how this was done, and less of the over-the-top rhetoric.

Claims such as “we are the leading cyber security firm” and “we understand apple’s AI and how to beat it” do not make you look more competent, just more boastful.

Re: Face ID beaten by mask

#124
post #105

Earlier quoted context omitted.

This isn't true, touchID requires a living person/something that simulates a living person to unlock.

Interesting. Can you point to any official white-paper from Apple claiming this? I'm reading this: https://www.apple.com/business/docs/iOS_Security_Guide.pdf but I cannot find any such information about a living person.

Don't have any paper from Apple about this, but first finger-print scanners started to check temperature to avoid reading old fingerprints left on the reader when someone did breath on it to trigger a new reading. So to attack the temperature check you had to place a plastic-bag with body temperature water on the reader, making it read the old fingerprint if enough of it was left on the reader. Then they started to check for pulse, so the easiest attack is to put a false fingerprint on a finger.

Fingerprints are easy to copy and you cannot change them, so fingerprints might be more secure than use the pin 1234. But it isn't more secure than a strong password, but so much more convenient to use...

Re: Face ID beaten by mask

#125
post #89

> Because... we are the leading cyber security firm ;) But you don't even use HTTPS. Why?

Because the information was meant to be public anyway?

There are countless other benefits to having HTTPS (such as ensuring the end-to-end integrity of the communication so stuff can't be injected in the document). It's not meant only for private information.

Re: Face ID beaten by mask

#126
post #77
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

>If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. I would be astonished if state actors are not already well on their way to figuring out how to do this.

That's true but it's outside the threat model for most devices: that same state-level actor can no doubt use cameras to collect passwords and some combination of imaging and subterfuge to get fingerprints, too.

Re: Face ID beaten by mask

#127
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

>but stuff like this makes it hard to take them seriously

What about that part makes it hard to "take them seriously"?

Their claims to be "the leading security firm" etc might be, but this is a perfectly rational and plausible claim (and the part that the technology was rushed is true as told by Apple).

>Before Touch ID, my passcode was 0000 with a four-hour lock timeout.

Then probably you're not the target market for a secure device.

Re: Face ID beaten by mask

#128
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

> As for fingerprints versus facial recognition, the article claims fingerprints are better, but I’m skeptical. For one thing, my phone is covered in my own fingerprints, so getting something to copy is a lot easier. Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? I'm only half-serious, but it might make lifting the real prints harder...…

>Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone?

Because we don't touch 20000 other objects every day from where someone can pick our fingertips from?

Re: Face ID beaten by mask

#129
post #120
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

>One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

Well, that's hardly a criterion for most people. I'd rather give the password than die.

Re: Face ID beaten by mask

#130
post #23

Earlier quoted context omitted.

Human labor is expensive. Not accounting for that is a bit disingenuous.

Artists aren't particularly well paid.

… for pure art, maybe. For commercial artists, especially ones capable of precise results on a deadline and, in this case, also not asking too many questions?
Post reply on HN