Live data from Hacker News

Face ID beaten by mask

bkav.com

181–190 of 244 posts

Re: Face ID beaten by mask

#181
Cool that they took the time to explore the limits of it, but FaceID is about convenience with security, not maximum security. Having physical access to the phone is still required, which is a pretty big obstacle for this kind of attack.

There is also a quick button squeeze you can do that requires passcode for the next unlock, so you can do that before you go to bed if you're really afraid someone is going to gain physical access to your device.

Re: Face ID beaten by mask

#182
post #130

Earlier quoted context omitted.

… for pure art, maybe. For commercial artists, especially ones capable of precise results on a deadline and, in this case, also not asking too many questions?

not true either, read up on past stories of skilled forgers of paper currency: their labor was surprisingly inexpensive.

Do you have any citations?

Re: Face ID beaten by mask

#183
post #115

Earlier quoted context omitted.

Biometrics are usernames not passwords That such a meaningless slogan. Passwords and biometrics have different pros and cons, but they are the same in that they increase security. Biometrics should never be used on the sole authentication method * Biometrics is always better than no security. * Biometrics done well is certainly better than a 4-digit PIN. * Biometrics on an iDevice is in fact always used with somethin…

>That such a meaningless slogan. Passwords and biometrics have different pros and cons, but they are the same in that they increase security. It is not a meaningless slogan, if Biometrics give the wider public a FALSE sense of security in that companies like Apple pitch them in unrealistic and inaccurate ways in their marketing that gives the average Joe the false idea that bio metrics are more secure than they reall…

Biometrics give the wider public a FALSE sense of security

Oh, please! There is an abundance of evidence to show that the wider public is completely uninterested in security to the degree that a majority will disable security features altogether if they are inconvenient to use in the slightest. People don’t use biometric authentication because they are misled to believe that it’s more secure than other methods of security. They use it because it’s the most convenient method.

That not only a pointless statement, but a False Dilemma Fallacy as well

In principle perhaps, but not in practice. Before biometric authentication became widespread, it was completely normal not to protect your phone at all. And when it was protected, it was almost always with a 4-digit PIN that you only had to enter after some amount of time had passed since you last unlocked the phone.

often time I see people set VERY insecure passwords because they believe that thei biometrics protects their password

That’s a nice anecdote which may be a completely accurate account of what someone told you. Or not. I find it hard to believe with no evidence that such a specific misunderstanding should be widespread. I do find it very believable that people use bad passwords, because people have always used bad passwords. As long as we’re exchanging anecdotes, I can tell you that I personally changed from a 4-digit PIN to a longer password when I got Touch ID, because it wasn’t as inconvenient when I only had to type it in once in a while as opposed to every time I unlock my phone.

Re: Face ID beaten by mask

#184

Earlier quoted context omitted.

> but stuff like this makes it hard to take them seriously What about that part makes it hard to "take them seriously"? Their claims to be "the leading security firm" etc might be, but this is a perfectly rational and plausible claim (and the part that the technology was rushed is true as told by Apple). > Before Touch ID, my passcode was 0000 with a four-hour lock timeout. Then probably you're not the target market…

It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur. There's no such thing as "a secure device." There are devices which offer various levels and types of security. If you're a CIA officer carrying classified secrets on your device,…

>It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur.

Non sequitur? Sounds like a totally rational argument to me, to the point of being a tautology.

Rushed a feature to market by one year == they also rushed the testing.

Re: Face ID beaten by mask

#185

I was hoping they released more details about the process. One possible method is that they trained the iphone's Face ID on the mask by repeatedly failing to unlock it with the mask and then entering the passcode which trains the iphone's neural net on the new face (mask in this case). There was a video a few days ago where the iphone X was unlocked by a man's brother by doing this : https://9to5mac.com/2017/11/04/fa…

They address this in their second point: > It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.

Yes, they addressed it, but why not demonstrate it if it was actually true? As in register on camera then point it at the mask.

My guess would be because it doesn't actually work.

Re: Face ID beaten by mask

#186
Isn’t it strange that a room-temperature face can unlock the phone when Apple has made it clear that the iPhone X uses the temperature of the face to detect masks etc.? From the perspective of the IR camera, the mask and that guy’s face should look completely different. This attack makes it look like it’s not using this information at all.

Re: Face ID beaten by mask

#187

I’d really like to see more details about how this was done, and less of the over-the-top rhetoric. Claims such as “we are the leading cyber security firm” and “we understand apple’s AI and how to beat it” do not make you look more competent, just more boastful.

Yes, the whole tone (and lack of specificity) of the article does not add to its credibility.

Re: Face ID beaten by mask

#188

Earlier quoted context omitted.

It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur. There's no such thing as "a secure device." There are devices which offer various levels and types of security. If you're a CIA officer carrying classified secrets on your device,…

> It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur. Non sequitur? Sounds like a totally rational argument to me, to the point of being a tautology. Rushed a feature to market by one year == they also rushed the testing.

There are a lot of holes in your equation there.

Apple never said they rushed the phone. They said they were able to get it out early. These are not the same thing; "rushed" implies that quality suffered, while merely getting it out early could just be due to work going faster than anticipated.

Even if the phone as a whole was "rushed," that doesn't mean Face ID was. Maybe it was naturally ready by now.

Even if Face ID was rushed, that doesn't mean that the security aspects were rushed.

Even if Face ID's security aspects were rushed, that doesn't mean testing was rushed.

It's like if you show up early to a meeting and so I accuse you of speeding. Is that sensible?

Re: Face ID beaten by mask

#189

Earlier quoted context omitted.

It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur. There's no such thing as "a secure device." There are devices which offer various levels and types of security. If you're a CIA officer carrying classified secrets on your device,…

> It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur. Non sequitur? Sounds like a totally rational argument to me, to the point of being a tautology. Rushed a feature to market by one year == they also rushed the testing.

How do you know they rushed features to market instead of dropping other features which we don't even know about because they were dropped? Isn't this exactly how people want agile products delivered?

Re: Face ID beaten by mask

#190
post #108
post #51

Earlier quoted context omitted.

It's definitely a better situation than an attacker being able to steal your fingerprint off a glas or other everyday object. Copying a fingerprint requires very little skill.

> or other everyday object You mean like a phone or something?

... I feel stupid now.
Post reply on HN