Live data from Hacker News

Face ID beaten by mask

bkav.com

231–240 of 244 posts

Re: Face ID beaten by mask

#231

Earlier quoted context omitted.

There are a lot of holes in your equation there. Apple never said they rushed the phone. They said they were able to get it out early. These are not the same thing; "rushed" implies that quality suffered, while merely getting it out early could just be due to work going faster than anticipated. Even if the phone as a whole was "rushed," that doesn't mean Face ID was. Maybe it was naturally ready by now. Even if Face…

> It's like if you show up early to a meeting and so I accuse you of speeding. Is that sensible? No, but it is sensible to consider that if they've estimated 2018 themselves as the initial release date and then put it out in 2017, they didn't "made it naturally" but rather rushed it. I don't say that's 100% proven or anything. But it's very sensible to consider -- in other words plausible. It might be "rushing to con…

> I don't say that's 100% proven or anything.

You previously said it was "to the point of being a tautology."

Re: Face ID beaten by mask

#232
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

I have discovered to my surprise, since shattering my iPhone 6 screen last week, that Touch ID works perfectly well through multiple layers of Saran Wrap. So you could keep your thumb wrapped up if you’re concerned about leaving prints. ;-) In the meantime, my iPhone X arrives on Thursday, and I’m looking forward to training Face ID. All I got from this article was “these are the lengths you have to go to to defeat i…

Funny idea. My takeaway from the article was similar. Touch ID was already Good Enough for me, and it sounds like Face ID is quite a bit better. Which is, oddly enough, exactly what I expected.

One thing I'd really be interested in learning about is how much time and how many attempts it took them before they could successfully unlock the phone. And more pertinently, what those values might look like once they get some more experience with it. In a real-world scenario, they only get 48 hours and 5 attempts, so any technique which takes more than that is still nonviable.

It will also be interesting to see if Apple is able to improve their defenses against this. I get the sense that they couldn't improve Touch ID much because a good fake fingerprint looks just like a real one to the sensor. This mask definitely does not look much like the person's actual face, so they may be able to tweak things to be more resistant to this attack.

Which is not to say that this attack is pointless or these guys are dumb or anything. I'm impressed with their work! It's just not a game over situation the way they make it sound in certain parts of their writeup.

Re: Face ID beaten by mask

#233

Earlier quoted context omitted.

Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?

No, Face ID takes another snapshot after the passcode has been entered. Source: "Face ID takes another capture and augments its enrolled Face ID data" https://images.apple.com/business/docs/FaceID_Security_Guide...

This only happens if the face is deemed similar enough to the original face data, which is unlikely if it's a completely different person.

Here's the entire quote:

"…if Face ID fails to recognize you, but the match quality is higher than a certain threshold and you immediately follow the failure by entering your passcode, Face ID takes another capture and augments its enrolled Face ID data with the newly calculated mathematical representation"

Re: Face ID beaten by mask

#234
post #27

Earlier quoted context omitted.

Remember: Attacks always grow better, not worse. The bluetooth distance records grew quite quickly.

Apple could add eye movement to it's algorithm tomorrow and this attack would fail forever.

Oh sure. Unreleased vapourware beats all attacks.

Re: Face ID beaten by mask

#235
post #66

Earlier quoted context omitted.

Fingerprint or face or retina is not a "password", it is a "login". And we should have a proper password in addition to the login, not as a substitute.

No, we should not have a "proper password" in addition to a login. People use their phones without passscodes or set them to 0000 all the time. Edit: The worse problem is if biometrics fail in that scenario, you can't access your device ever again. In the real world, effective biometrics are the most secure login tokens we have.

So what is the problem then - they will just have face/fingerprint protection (as they have now) plus useless 0000 pin. And all this optional in settings. No inconvenience at all. Other will have proper bio + password protection that can't abused in most cases.

Re: Face ID beaten by mask

#236
post #66

Earlier quoted context omitted.

Fingerprint or face or retina is not a "password", it is a "login". And we should have a proper password in addition to the login, not as a substitute.

Then what's the point of the added complexity? It's a single user device, so just have a password.

Appliances like telephones will never have secure passwords (e.g. 32 random symbols), they will have at most short and insecure pins/passwords, 6-10 numbers or letters. But adding on top of that fingerprint/face with 1/10000-1000000 security will make it acceptably secure and still convenient.

Re: Face ID beaten by mask

#237
post #58

Earlier quoted context omitted.

Can you require both face and password?

That would be an extremely bad idea. In that scenario, imagine FaceID fails to recognize you, now you can't get into your device. Currently if FaceID fails, you have passcode as an alternative way into the device.

Although fingerprint AND face/iris scan would probably add more confidence, with passcode as a reserve option.

Re: Face ID beaten by mask

#238
post #66

Earlier quoted context omitted.

Fingerprint or face or retina is not a "password", it is a "login". And we should have a proper password in addition to the login, not as a substitute.

I wonder if Apple experimented with using eye movements as a passcode? I imagine they have the technology available to do such a thing. That would make it so your face is your username and a specific movement you made with your eyes the password.

There are conditions that may make an average person unable to perform the movement, like getting a severe cold or an eye infection that makes an eye water. They may still want to use their phones with minimum inconvenience, instead of resorting to entering a passcode. It may not be possible for some people to configure it well either, and may probably result in eye movements that others may consider weird (imagine rolling your eyes in front of your boss because you wanted to unlock your phone).

Re: Face ID beaten by mask

#239
post #235

Earlier quoted context omitted.

No, we should not have a "proper password" in addition to a login. People use their phones without passscodes or set them to 0000 all the time. Edit: The worse problem is if biometrics fail in that scenario, you can't access your device ever again. In the real world, effective biometrics are the most secure login tokens we have.

So what is the problem then - they will just have face/fingerprint protection (as they have now) plus useless 0000 pin. And all this optional in settings. No inconvenience at all. Other will have proper bio + password protection that can't abused in most cases.

The problem is you are locked out forever if your biometrics fail. Requiring biometrics AND passcode means both have to succeed, Apple wisely chose to let you use biometrics OR passcode, so you can still get in when biometrics don't or can't work.

Re: Face ID beaten by mask

#240
post #234

Earlier quoted context omitted.

Apple could add eye movement to it's algorithm tomorrow and this attack would fail forever.

Oh sure. Unreleased vapourware beats all attacks.

Isn't this attack "unreleased vaporware"?

For example, you have to use FaceID every 4 hours or it requires a passcode. Do you think they were able to hand make an acceptable mask within 4 hours?

Post reply on HN