Live data from Hacker News

Face ID beaten by mask

bkav.com

201–210 of 244 posts

Re: Face ID beaten by mask

#201
So Ive been thinking about biometrics and phone security a bit, and it seems to me there is a pretty easy way to tell how secure your phone needs to be on an X/Y chart where Y= Security needed and X = Data sensitivity/Personal-ness.

Id say the ideal plot would follow an exponential curve, and seems that if you didn't keep a lot of personal data on your phone and all your social, financial and mail accounts can be reset quickly via the web, you don't need much security provided you maintain custody of your device. That said, Im glad that any claims as to the security of biometrics are not just taken at apple's/samsung's/google's word.

I remember the iPhoneX event stated that there was a exponentially smaller chance that someone else's face could unlock your phone, and that masks "wont work". I could also be mis-remembering, but there is a way to tell the iPhoneX to not allow your face if you find yourself compromised in some way. So unless someone has access to make a 3d rendering of your face, the means to make a mask and the opportunity to take your phone before you can signal that you want to authenticate with a password it seems pretty secure...

Re: Face ID beaten by mask

#202
post #120

Earlier quoted context omitted.

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

> One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred. Well, that's hardly a criterion for most people. I'd rather give the password than die.

[deleted]

Re: Face ID beaten by mask

#203
post #120
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.

When you start to think about attacks from adversaries with lots of resources (like governments), are passwords safe from fMRI-assisted interrogations?

Re: Face ID beaten by mask

#204

Earlier quoted context omitted.

Apple specifically recommends to law enforcement using a deceased suspect’s fingerprint while the device will still accept it to bypass encryption.

Legally in the US you can't be forced to testify a password under the fourth amendment, but you can be forced to use your fingerprint to unlock a device. That's why repeatedly pressing the power button on an iPhone prevents any biometric unlocking.

I'm not sure that's firmly established. Last time I looked into it, there were rulings in just about every direction, but the trend seemed to be what you suggest.

Re: Face ID beaten by mask

#205
post #191
post #149

Troy Hunt already posted about this [1]. I think this quote is fitting: "More than anything though, we need to remember that Face ID introduces another security model with its own upsides and downsides on both security and usability. It's not "less secure than a PIN", it's differently secure and the trick now is in individuals choosing the auth model that's right for them." [1] https://www.troyhunt.com/face-id-touch-…

From Troy Hunt's article: > given the processing power to actually observe and interpret eye movements in the split second within which you expect this to work, this would be a really neat failsafe. Apple highlights this as "attention awareness" Yes, it would be a great failsafe. However, if the PoC demonstrated by Bkav is legit, it would seem that Face ID doesn't look for eye movement; it just checks if the eyes are…

You can also turn attention awareness off. They didn’t specifically mention whether they turned it off or left it on.

Re: Face ID beaten by mask

#206
post #27
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

Remember: Attacks always grow better, not worse. The bluetooth distance records grew quite quickly.

Apple could add eye movement to it's algorithm tomorrow and this attack would fail forever.

Re: Face ID beaten by mask

#207
post #191
post #149

Troy Hunt already posted about this [1]. I think this quote is fitting: "More than anything though, we need to remember that Face ID introduces another security model with its own upsides and downsides on both security and usability. It's not "less secure than a PIN", it's differently secure and the trick now is in individuals choosing the auth model that's right for them." [1] https://www.troyhunt.com/face-id-touch-…

From Troy Hunt's article: > given the processing power to actually observe and interpret eye movements in the split second within which you expect this to work, this would be a really neat failsafe. Apple highlights this as "attention awareness" Yes, it would be a great failsafe. However, if the PoC demonstrated by Bkav is legit, it would seem that Face ID doesn't look for eye movement; it just checks if the eyes are…

Or maybe it does check, but the mask puts it in some kind of error recovery mode.

Re: Face ID beaten by mask

#208

Earlier quoted context omitted.

It's hard to take seriously because they take a story about Apple getting the phone out a year early as somehow demonstrating that Apple hadn't properly studied how the security of Face ID compares with Touch ID. It's a total non sequitur. There's no such thing as "a secure device." There are devices which offer various levels and types of security. If you're a CIA officer carrying classified secrets on your device,…

It's hard to take Apple seriously about Face ID when it's now obvious that security wasn't the goal at all. Face ID is a gimmick to keep attention on the iPhone.

In what way is that "obvious"?

Re: Face ID beaten by mask

#209
post #22

Earlier quoted context omitted.

A fingerprint is just a really complex password that you leave on everything you touch. Your face is just a really complex password that is written on the front of your head. It should be self-evident that neither of these is "secure" for some level of "security", but they might be perfectly fine for the level of threat that you face, which is not likely to be particularly high. But I don't know you, so maybe you fac…

fingerprints and faces are just really complex usernames : they're not secret at all.

Your biometric measurements are essentially secrets. They work today because it's far too difficult for a thief to steal your device AND copy your biometrics at the same time. This makes them the most secure tokens we have in real world use, given the number of people with 0000 passcodes.

Eventually they may become easy to copy, then their utility as secrets will be gone.

Re: Face ID beaten by mask

#210
post #66
post #13

So, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?

Fingerprint or face or retina is not a "password", it is a "login". And we should have a proper password in addition to the login, not as a substitute.

No, we should not have a "proper password" in addition to a login. People use their phones without passscodes or set them to 0000 all the time. Edit: The worse problem is if biometrics fail in that scenario, you can't access your device ever again.

In the real world, effective biometrics are the most secure login tokens we have.

Post reply on HN