Live data from Hacker News

Face ID beaten by mask

bkav.com

191–200 of 244 posts

Re: Face ID beaten by mask

#191
post #149

Troy Hunt already posted about this [1]. I think this quote is fitting: "More than anything though, we need to remember that Face ID introduces another security model with its own upsides and downsides on both security and usability. It's not "less secure than a PIN", it's differently secure and the trick now is in individuals choosing the auth model that's right for them." [1] https://www.troyhunt.com/face-id-touch-…

From Troy Hunt's article:

> given the processing power to actually observe and interpret eye movements in the split second within which you expect this to work, this would be a really neat failsafe. Apple highlights this as "attention awareness"

Yes, it would be a great failsafe.

However, if the PoC demonstrated by Bkav is legit, it would seem that Face ID doesn't look for eye movement; it just checks if the eyes are oriented toward the device.

That said, I agree that regular people probably don't need to worry about any of this.

Re: Face ID beaten by mask

#192
post #186

Isn’t it strange that a room-temperature face can unlock the phone when Apple has made it clear that the iPhone X uses the temperature of the face to detect masks etc.? From the perspective of the IR camera, the mask and that guy’s face should look completely different. This attack makes it look like it’s not using this information at all.

well.. if you have already advanced to the point where you're making a mask, I imagine it wouldn't be too hard to heat it up a bit.

Re: Face ID beaten by mask

#193
post #41

Earlier quoted context omitted.

In the video, he shows the iPhone being unlocked with his own face at 1:06: https://m.youtube.com/watch?v=i4YQRLQVixM

So it does. It seems that the iPhone is better at recognising faces than me at least.

On the bright side, this seems to confirm that one would be able to use FaceID if mugged and beaten black and blue.

Re: Face ID beaten by mask

#194
Most of these answers basically say nothing. e.g.

"""Q: How did Bkav develop the mask (for example why you use silicone for the nose, why 3D printing for some areas while special processing for others, etc.)?

A: You are right. Many people in the world have tried different kinds of masks but all failed. It is because we understand how AI of Face ID works and how to bypass it. As stated above, we were the first in the world to show that face recognition was not an effective security measure for laptops."""

is a really nice way to dodge the question of why they used silicone for some parts of the mask.

Re: Face ID beaten by mask

#195
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

>> For spies, spooks, government agents etc. I suspect that Face ID would always be a no-no You are correct. Face recognition, like any other biometric, is a bit of a farce. The face doesn't unlock the phone. The face is read by software which then generates some string of numbers, essentially a hash of the face/print, than then unlocks the phone. That hashing process can be hacked/intercepted/replicated just as with…

Very important note: Be sure to provide the old man behind glass with food and water. I had an old man behind glass in my house for security and didn't think to give him food and water and he died within a week.

Re: Face ID beaten by mask

#196
post #186

Isn’t it strange that a room-temperature face can unlock the phone when Apple has made it clear that the iPhone X uses the temperature of the face to detect masks etc.? From the perspective of the IR camera, the mask and that guy’s face should look completely different. This attack makes it look like it’s not using this information at all.

The IR camera is near-infrared, it measures more or less light that your eyes can't see, and no heat frequencies. The IR camera is used to recover 3D information: https://en.wikipedia.org/wiki/Structured-light_3D_scanner

Re: Face ID beaten by mask

#198

Earlier quoted context omitted.

> but stuff like this makes it hard to take them seriously What about that part makes it hard to "take them seriously"? Their claims to be "the leading security firm" etc might be, but this is a perfectly rational and plausible claim (and the part that the technology was rushed is true as told by Apple). > Before Touch ID, my passcode was 0000 with a four-hour lock timeout. Then probably you're not the target market…

It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur. There's no such thing as "a secure device." There are devices which offer various levels and types of security. If you're a CIA officer carrying classified secrets on your device,…

It's hard to take Apple seriously about Face ID when it's now obvious that security wasn't the goal at all.

Face ID is a gimmick to keep attention on the iPhone.

Re: Face ID beaten by mask

#199
post #158
post #15

Earlier quoted context omitted.

Nitpicking the cost of the labor to build this mask misses the point of the article: face id is much less secure than Apple claims.

Cost do matter for their claim, because given an indefinite budget every security measure can be broken.

On the surface though, these guys look to be a small company in Vietnam, so I doubt they have an infinite budget, much less a "large" budget for this demonstration.

Re: Face ID beaten by mask

#200

Earlier quoted context omitted.

Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?

Doesn't sound like they took that approach: > However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.

How did they accomplish this though? Is there a timeout where, after enough FaceID failures cause a fallback to passcode, FaceID is accepted again without entering a passcode in the interim?
Post reply on HN