Live data from Hacker News

Face ID beaten by mask

bkav.com

131–140 of 244 posts

Re: Face ID beaten by mask

#131
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

>As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask

So like what they can gather from 100s of one's photos in social media and other places?

Re: Face ID beaten by mask

#132
post #117

What stops someone from taking the phone and "flash" it to your face, having the phone unlocked before you understand what's going on. Or do you have to hold the phone to the face while typing the password ?

The same thing that stops someone from jumping you and forcing you to unlock with Touch ID.

Re: Face ID beaten by mask

#133
post #53
post #36

Earlier quoted context omitted.

It seems much more secure than fingerprints, since that was defeated much more quickly (within a couple days?), with easily lifted prints and a more cost effective (though still somewhat lengthy) method. This, in comparison, seems much harder and consequently further reduces the realistic attack scenarios where people have to be worried. For most people this is a non-issue. (It mostly already was a non-issue with fin…

TouchID was spoofed in 2 days and FaceID in 7 days. Still, I feel like the difference in time is not that relevant. I think the biggest difference in time was given by the "attacker" trying to understand what the FaceID system is looking for exactly, as an algorithm. But once they know that, future attacks should be much faster. Like if they try to bypass someone else's phone, it shouldn't take another 7 days. It cou…

>I think the biggest difference in time was given by the "attacker" trying to understand what the FaceID system is looking for exactly, as an algorithm. But once they know that, future attacks should be much faster

Not necessarily, as the algorithm is a NN (IIRC), so it looks for different things on different people too.

Re: Face ID beaten by mask

#134

Earlier quoted context omitted.

Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?

Doesn't sound like they took that approach: > However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.

Then again, if they wanted to make a name for their selves with BS, they would say that even if they have done the opposite.

Re: Face ID beaten by mask

#135
post #79

Earlier quoted context omitted.

Presumably all you would need is another iPhone X to do the scanning.

The data from one iPhone isn’t supposed to be useful to another since the infrared emitters are in a random pattern.

It doesn't need to be usable to another iPhone for what we're discussing in this subthread.

Just to be usable to map the face in 3D space and make a mask.

Re: Face ID beaten by mask

#136
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

For a consumer, it's fine -- way better than the bullshit passwords that people use.

Once you start getting into higher security areas, you still need multiple identity factors to authenticate people. I'd guess that a bigger potential risk factor for systems like FaceID is intent -- entry of a passcode or fingerprint being placed on a button is a more explicit expression of intent as opposed to glancing at a device.

Re: Face ID beaten by mask

#137
post #120

Earlier quoted context omitted.

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

Apple specifically recommends to law enforcement using a deceased suspect’s fingerprint while the device will still accept it to bypass encryption.

Legally in the US you can't be forced to testify a password under the fourth amendment, but you can be forced to use your fingerprint to unlock a device. That's why repeatedly pressing the power button on an iPhone prevents any biometric unlocking.

Re: Face ID beaten by mask

#138
post #29
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

Also, it took them a whole week to achieve this. So this is definitely not something someone could realistically do to you unless you are a some sorts of high-profile target.

Or you know, have access to a $300 3D printer, a $200 real one, is idle (e.g. unemployed), and can expect to make $2000 or more from stealing your phone/identity details etc.

Re: Face ID beaten by mask

#139

Once someone is at the stage where they're going to 3D scan you, create a replica of your face and steal your phone to get into it...why wouldn't they just coerce you into unlocking your phone with force? See https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Because they depend on you not knowing it.

Also because the former carries a much smaller jail sentence if caught.

Re: Face ID beaten by mask

#140
post #13

So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?

This is why you can't meaningfully talk about security without talking about a threat model. People don't talk about safes being broken because advanced tools will eventually open anything because the model assumes the police will show up and so the safe just needs to delay an attacker or require them to bring conspicuous or slow equipment.

If your goal is not having the punk who grabs your phone be able to get access to your banking info or personal data, any competent biometric system is a huge win if it means that the average person keeps their device locked rather than unlocked because it's too much trouble.

If you're worried about mass surveillance-style attacks, a fingerprint sensor or advanced face scanner is likely better than a password because it's significantly harder to harvest using a camera in a public place.

If you're being targeted, all of those trade-offs change, almost completely if state-level resources are involved.

Post reply on HN