I'm actually going to be very interested to hear how FaceID works for the average user. False positive is one issue and one Apple lauded as being lower than TouchID. What about the false negative rate however? This is what will actually aggravate users. As a user I like touch unlock. I can do it without looking at the phone, having the phone gave me, in the dark, wearing sunglasses and so on. To me face recognition j…
Face ID beaten by mask
161–170 of 244 posts
Re: Face ID beaten by mask
#162Earlier quoted context omitted.
They realize that at Apple too. Face/Touch ID can be forcefully disabled for enterprise. However for an average Joe this is not a threat.
Can you require both face and password?
Re: Face ID beaten by mask
#163As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
> As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask So like what they can gather from 100s of one's photos in social media and other places?
As the OP said: demonstrate that from that data you can produce a sufficiently accurate model that works with this method.
The article hasn’t.
It may be possible (you only have to match the resolution of the IR depth map) but it is not currently demonstrated.
Plus I imagine it’s quite easy to refine FaceID in the software as well so an attack like this may not be very long lasting.
Re: Face ID beaten by mask
#164Earlier quoted context omitted.
> Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? Because we don't touch 20000 other objects every day from where someone can pick our fingertips from?
_>Because we don't touch 20000 other objects every day from where someone can pick our fingertips from?_ We're less likely to lose one of those objects at the same place and time we leave our phone somewhere. It's comparable to leaving your keys in your car. Sure, someone could find those keys where you lost them and then find your car - but is sure is easier for them when they're both in the same place.
I think it's very likely that you touch something at the place where you left you phone, assuming that it wasn't dropped while you were moving.
Re: Face ID beaten by mask
#165Re: Face ID beaten by mask
#166I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…
> but stuff like this makes it hard to take them seriously What about that part makes it hard to "take them seriously"? Their claims to be "the leading security firm" etc might be, but this is a perfectly rational and plausible claim (and the part that the technology was rushed is true as told by Apple). > Before Touch ID, my passcode was 0000 with a four-hour lock timeout. Then probably you're not the target market…
Re: Face ID beaten by mask
#167I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…
> As for fingerprints versus facial recognition, the article claims fingerprints are better, but I’m skeptical. For one thing, my phone is covered in my own fingerprints, so getting something to copy is a lot easier. Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? I'm only half-serious, but it might make lifting the real prints harder...…
You might have a better shot at coming up with some material that just doesn't get fingerprints on it in the first place. Maybe a cloth-covered phone?
Re: Face ID beaten by mask
#168As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
Re: Face ID beaten by mask
#169The one answer that is missing from this QA is how many tries they had before it worked. Did they configure Face Id, made the mask and then it worked immediately? Did they tinker with the mask until it worked? From the way this is written I suppose the latter. Nevertheless, I thought Apple was detecting small movements in eyes to ensure that the subject in front is actually a living human. I don't know where I got th…
Face ID does track eye movement ("require attention"), but you can turn off that setting. I haven't found any information as to whether the firm disabled the eye tracking for this crack.
Re: Face ID beaten by mask
#170Earlier quoted context omitted.
> As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask So like what they can gather from 100s of one's photos in social media and other places?
This assumes a lot. As the OP said: demonstrate that from that data you can produce a sufficiently accurate model that works with this method. The article hasn’t. It may be possible (you only have to match the resolution of the IR depth map) but it is not currently demonstrated . Plus I imagine it’s quite easy to refine FaceID in the software as well so an attack like this may not be very long lasting.