Live data from Hacker News

Face ID beaten by mask

bkav.com

151–160 of 244 posts

Re: Face ID beaten by mask

#151

Earlier quoted context omitted.

It's pointless even thinking about IMHO. Someone could just hold a gun to your head or to your partner/child and then it's irrelevant what the security mechanism is. You are going to hand over the credential since your privacy is not more important than your life.

it’s not equivalent because there’s very different penalties in hacking someone vs torturing or coercing. So it requires different levels of motivation.

And you can scale hacking to millions of people via computer automation or hiring out of country workers. Scaling kidnapping and torture to millions will attract significantly more government attention.

Re: Face ID beaten by mask

#152

I was hoping they released more details about the process. One possible method is that they trained the iphone's Face ID on the mask by repeatedly failing to unlock it with the mask and then entering the passcode which trains the iphone's neural net on the new face (mask in this case). There was a video a few days ago where the iphone X was unlocked by a man's brother by doing this : https://9to5mac.com/2017/11/04/fa…

They address this in their second point:

> It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.

Re: Face ID beaten by mask

#153

Earlier quoted context omitted.

> As for fingerprints versus facial recognition, the article claims fingerprints are better, but I’m skeptical. For one thing, my phone is covered in my own fingerprints, so getting something to copy is a lot easier. Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? I'm only half-serious, but it might make lifting the real prints harder...…

> Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? Because we don't touch 20000 other objects every day from where someone can pick our fingertips from?

_>Because we don't touch 20000 other objects every day from where someone can pick our fingertips from?_

We're less likely to lose one of those objects at the same place and time we leave our phone somewhere. It's comparable to leaving your keys in your car. Sure, someone could find those keys where you lost them and then find your car - but is sure is easier for them when they're both in the same place.

Re: Face ID beaten by mask

#154
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

> but stuff like this makes it hard to take them seriously What about that part makes it hard to "take them seriously"? Their claims to be "the leading security firm" etc might be, but this is a perfectly rational and plausible claim (and the part that the technology was rushed is true as told by Apple). > Before Touch ID, my passcode was 0000 with a four-hour lock timeout. Then probably you're not the target market…

It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur.

There's no such thing as "a secure device." There are devices which offer various levels and types of security. If you're a CIA officer carrying classified secrets on your device, you probably don't want to use Face ID. For the average user, it's a nice increase in security.

Re: Face ID beaten by mask

#155
post #120
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

If you have cameras watching someone from many angles you could just watch them type in their PIN. It would be much easier than making this mask thing.

Re: Face ID beaten by mask

#156
post #90

Earlier quoted context omitted.

What happened to Craig was that he tried to unlock a freshly rebooted phone. iOS requires the user’s passcode after booting, and won’t allow a biometric unlock until after that.

No, it was actually the people setting up the stage accidentally triggered Face ID often enough that it fell back to passcode. Could find a link to Apple's explanation if needed.

Thanks, you're right. It looks like it was initially reported as having been rebooted like I said, but Apple later on explained it as you say, and I must have missed the update. Here's a link:

https://9to5mac.com/2017/09/13/face-id-demo-fail-details/

Anyway, the key point here is that Face ID didn't fail to recognize Craig, it refused to recognize him because it had already been locked.

Re: Face ID beaten by mask

#157
post #105

Earlier quoted context omitted.

This isn't true, touchID requires a living person/something that simulates a living person to unlock.

Interesting. Can you point to any official white-paper from Apple claiming this? I'm reading this: https://www.apple.com/business/docs/iOS_Security_Guide.pdf but I cannot find any such information about a living person.

https://www.quora.com/Can-Apples-Touch-ID-tell-between-the-f...

Re: Face ID beaten by mask

#158
post #15
post #5

> A: We used a popular 3D printer. Nose was made by a handmade artist. We use 2D printing for other parts (similar to how we tricked Face Recognition 9 years ago). The skin was also hand-made to trick Apple's AI. > Q: What's the approximate cost of the mask? > A: ~ 150 USD Taken together, the second answer cannot be true. Only if the cost stated is related to material cost only, which is is only one input factor to a…

Nitpicking the cost of the labor to build this mask misses the point of the article: face id is much less secure than Apple claims.

Cost do matter for their claim, because given an indefinite budget every security measure can be broken.

Re: Face ID beaten by mask

#159
post #13

So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?

I've read somewhere (probably in one of Troy Hunt's posts) that biometric data should not the be password , but rather the username . Maybe we're looking at this the wrong way. Biometric data seams to be equivalent (or at least similar) to a public key.

Public keys still (ought to) get rotated-out when they've been in-use long enough that they could have been factored in that time.

Re: Face ID beaten by mask

#160
I'm actually going to be very interested to hear how FaceID works for the average user. False positive is one issue and one Apple lauded as being lower than TouchID.

What about the false negative rate however? This is what will actually aggravate users.

As a user I like touch unlock. I can do it without looking at the phone, having the phone gave me, in the dark, wearing sunglasses and so on.

To me face recognition just seems like a huge step backwards. I'd love to be proven wrong.

Post reply on HN