As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
yeah this is mostly like, multinational CEOs, etc who would be targeted
Face ID beaten by mask
211–220 of 244 posts
Re: Face ID beaten by mask
#212> A: We used a popular 3D printer. Nose was made by a handmade artist. We use 2D printing for other parts (similar to how we tricked Face Recognition 9 years ago). The skin was also hand-made to trick Apple's AI. > Q: What's the approximate cost of the mask? > A: ~ 150 USD Taken together, the second answer cannot be true. Only if the cost stated is related to material cost only, which is is only one input factor to a…
What other cost are you referring to? The 3D printer? You can send your design to a studio and they'll print it for you and send it, or you can rent time in some places to get access to a printer, without needing to buy one. In any case, if it needed only a paper print, you wouldn't count the cost of the printer, since you can print it anywhere.
Then "hand made" skin, which they don't reference cost or time spent creating.
Then "hand made" nose, which they don't reference cost or time spent creating.
Also makeup, which they don't reference cost or time spent applying.
This is a security firm serving up info with HTTP, not HTTPS, ducking every serious question to the point it seems likely they are hiding something. Even if everything they claim is true, their attack vector is so difficult chances of success would seem to be effectively nil.
Re: Face ID beaten by mask
#213> A: We used a popular 3D printer. Nose was made by a handmade artist. We use 2D printing for other parts (similar to how we tricked Face Recognition 9 years ago). The skin was also hand-made to trick Apple's AI. > Q: What's the approximate cost of the mask? > A: ~ 150 USD Taken together, the second answer cannot be true. Only if the cost stated is related to material cost only, which is is only one input factor to a…
Nitpicking the cost of the labor to build this mask misses the point of the article: face id is much less secure than Apple claims.
In the end, they've shown is FaceID is just as secure as Apple claimed. Apple never claimed impervious to any attacks, they claimed it would work well an quickly, and be more resistant to attack than TouchID. Requiring a Mission Impossible level team to create a mask that duplicates your face is not a level of attack most customers are concerned with.
TouchID can be defeated simply by stealing the device, lifting the owners fingerprints from said device, and 3d printing duplicate prints to use. FaceID is far more secure than that.
Re: Face ID beaten by mask
#214Earlier quoted context omitted.
Biometrics are weaker than anything that relies on knowledge, for the simple fact that a physical attack IRL cannot be resisted. One could die without revealing a pin or password, but a biometric device would reveal his secrets very quickly through simple coercion and even after death has occurred.
When you start to think about attacks from adversaries with lots of resources (like governments), are passwords safe from fMRI-assisted interrogations?
Re: Face ID beaten by mask
#215Earlier quoted context omitted.
They realize that at Apple too. Face/Touch ID can be forcefully disabled for enterprise. However for an average Joe this is not a threat.
Can you require both face and password?
Re: Face ID beaten by mask
#216Biometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.
Re: Face ID beaten by mask
#217Wonder if this would work have Apple not relaxed their FaceID sensor requirements to ship the phones more quickly.
Attacks will always be possible because FaceID can never be infinitely precise. Your face changes over time, even during the day. People wear glasses or sunglasses sometimes, and take them off sometimes. They grow facial hair, and shave it off. They wear makeup, and take it off. They pick up black eyes in jui-jitsu class.
There is a balance between maximum precision and maximum usability. Apple's task was to find that balance. This hacked up "exploit" does nothing but show they found the proper balance.
Re: Face ID beaten by mask
#218Earlier quoted context omitted.
It's hard to take Apple seriously about Face ID when it's now obvious that security wasn't the goal at all. Face ID is a gimmick to keep attention on the iPhone.
In what way is that "obvious"?
The second thing is their claims and their focus on marketing around security. This was easily beaten in its first week in the real world! So it's not really that secure is it?
The third thing is that Apple has a long history of choosing gimmicks over actual functionality. The OS X dock is just one example of this.
Re: Face ID beaten by mask
#219Earlier quoted context omitted.
yeah this is mostly like, multinational CEOs, etc who would be targeted
And they shouldn’t rely on consumer-level security protection.
Re: Face ID beaten by mask
#220As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…
These scans were made from photographs: http://2.bp.blogspot.com/-c_lP5_5u1Dk/VmM5aDNFHzI/AAAAAAAABz...