Live data from Hacker News

Face ID beaten by mask

bkav.com

141–150 of 244 posts

Re: Face ID beaten by mask

#141
post #120
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

[deleted]

Re: Face ID beaten by mask

#142
post #66
post #13

So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?

Fingerprint or face or retina is not a "password", it is a "login". And we should have a proper password in addition to the login, not as a substitute.

I wonder if Apple experimented with using eye movements as a passcode? I imagine they have the technology available to do such a thing. That would make it so your face is your username and a specific movement you made with your eyes the password.

Re: Face ID beaten by mask

#143
post #53

Earlier quoted context omitted.

TouchID was spoofed in 2 days and FaceID in 7 days. Still, I feel like the difference in time is not that relevant. I think the biggest difference in time was given by the "attacker" trying to understand what the FaceID system is looking for exactly, as an algorithm. But once they know that, future attacks should be much faster. Like if they try to bypass someone else's phone, it shouldn't take another 7 days. It cou…

> I think the biggest difference in time was given by the "attacker" trying to understand what the FaceID system is looking for exactly, as an algorithm. But once they know that, future attacks should be much faster Not necessarily, as the algorithm is a NN (IIRC), so it looks for different things on different people too.

Even easier perhaps, with all the news about adversarial networks lately!

Re: Face ID beaten by mask

#144

They're an "Interesting" company... I'm not sure the authenticity of this story. The authors of the hack claim to be: "the leading firm in network security, software, smartphone manufacturing (Bkav.com/Bphone) and smarthome"[sic] and one of their products is a "gold plated SmartHome for super luxury villas". I wonder if it will work is ordinary luxury villas...

their bphone is just an overpriced android phone. they even goes as far as re-branded chrome to be bchrome. probably without google's permission as well as installing market and google default apps.

Re: Face ID beaten by mask

#145
post #95

Can sombebody explain this: "A: It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask." Does it mean passcode was completely off and the phone would n…

It most definitely matters. I have read Face ID tries to learn more about your face if you unlock it with the passcode after having issues unlocking with your face. What are the chances it learned the mask?

Re: Face ID beaten by mask

#146
post #13

So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?

It's pointless even thinking about IMHO. Someone could just hold a gun to your head or to your partner/child and then it's irrelevant what the security mechanism is. You are going to hand over the credential since your privacy is not more important than your life.

it’s not equivalent because there’s very different penalties in hacking someone vs torturing or coercing. So it requires different levels of motivation.

Re: Face ID beaten by mask

#147

Earlier quoted context omitted.

Apple specifically recommends to law enforcement using a deceased suspect’s fingerprint while the device will still accept it to bypass encryption.

Legally in the US you can't be forced to testify a password under the fourth amendment, but you can be forced to use your fingerprint to unlock a device. That's why repeatedly pressing the power button on an iPhone prevents any biometric unlocking.

I'm curious if using that feature could lead to other charges.

Re: Face ID beaten by mask

#148
post #66
post #13

So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?

Fingerprint or face or retina is not a "password", it is a "login". And we should have a proper password in addition to the login, not as a substitute.

Then what's the point of the added complexity? It's a single user device, so just have a password.

Re: Face ID beaten by mask

#149
Troy Hunt already posted about this [1].

I think this quote is fitting:

"More than anything though, we need to remember that Face ID introduces another security model with its own upsides and downsides on both security and usability. It's not "less secure than a PIN", it's differently secure and the trick now is in individuals choosing the auth model that's right for them."

[1] https://www.troyhunt.com/face-id-touch-id-pins-no-id-and-pra...

Re: Face ID beaten by mask

#150
post #95

Can sombebody explain this: "A: It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask." Does it mean passcode was completely off and the phone would n…

It most definitely matters. I have read Face ID tries to learn more about your face if you unlock it with the passcode after having issues unlocking with your face. What are the chances it learned the mask?

That's a super interesting thought. Face ID is a bit of a black box. Though I'm not trying to defend it to death, I can imagine it's better than all of the face scanners before it but far from super secure.
Post reply on HN