Live data from Hacker News

Face ID beaten by mask

bkav.com

241–244 of 244 posts

Re: Face ID beaten by mask

#241
post #234

Earlier quoted context omitted.

Oh sure. Unreleased vapourware beats all attacks.

Isn't this attack "unreleased vaporware"? For example, you have to use FaceID every 4 hours or it requires a passcode. Do you think they were able to hand make an acceptable mask within 4 hours?

Do they have to start making the mask after obtaining the phone?

Re: Face ID beaten by mask

#243
post #234

Earlier quoted context omitted.

Oh sure. Unreleased vapourware beats all attacks.

Isn't this attack "unreleased vaporware"? For example, you have to use FaceID every 4 hours or it requires a passcode. Do you think they were able to hand make an acceptable mask within 4 hours?

It's not vapourware: It may be a lie, but it's not a promise of greatness in some future version. They're saying "we have carried out an attack", not "we will attack oh-so-well".

Regarding the four-hour limit, the attacker have to either cheat and start making the mask in advance, or practise making masks quickly. Neither seems impossible. But of course, Apple could (and IMO would) improve the defense. I'm sure Apple would think of ways to counter any publicly known attack.

Re: Face ID beaten by mask

#244
post #235

Earlier quoted context omitted.

So what is the problem then - they will just have face/fingerprint protection (as they have now) plus useless 0000 pin. And all this optional in settings. No inconvenience at all. Other will have proper bio + password protection that can't abused in most cases.

The problem is you are locked out forever if your biometrics fail. Requiring biometrics AND passcode means both have to succeed, Apple wisely chose to let you use biometrics OR passcode, so you can still get in when biometrics don't or can't work.

I do realize that some scenarios where bio fails exist. But I don't want simultaneous security all the time, I want an option to enable it and disable it when I want. E.g. I'm traveling through customs and I enable this mode - now the phone can't be opened by e.g. restraining me (or tricking me) and using only bio, they won't know the password to match. And if they will request to unlock my phone for inspection, well ok - but they can only look into it beside me, the minute it autolocks they won't be able to open it knowing only password that I provided because my bio is inseparable from me. Some other valid scenarios can also exist.

PS: I read that some community firmware images allow this mode, the only thing that stops me from using them is lack of camera drivers for unofficial firmware.

Post reply on HN