Live data from Hacker News

Apple is sharing your facial wireframe with apps

washingtonpost.com

11–20 of 152 posts

Re: Apple is sharing your facial wireframe with apps

#11

So instead of asking Apple API to authenticate a user via FaceID, apps are going to obtain this data themselves and record it forever? I remember Steve talking on stage about how Apple would always make the operating system retain control of sensitive sensors and only give the result to user-approved apps(asking for permission every time). That's all thrown out of the window now?

This is not FaceID data, nor is it a replacement for it - the data available to apps is less granular than that used by FaceID, and is designed to give app developers the ability to create things like Animoji or any other creative uses of the 3D sensor data.

>I remember Steve talking on stage about how Apple would always make the operating system retain control of sensitive sensors and only give the result to user-approved apps(asking for permission every time). That's all thrown out of the window now?

Why would you think that? Apps do request permission for this, and it can be revoked.

Re: Apple is sharing your facial wireframe with apps

#12
post #7

I'm honestly less worried about Apple than others. They've at least made some measures to prove that they are willing to go some distance to protect privacy, even losing ground to competitors in voice recognition. Now thinking about co's like Facebook that not only has access to far more imagery of faces tied to sentiments and moments but have shown time and time again that privacy is a secondary concern AND that the…

> I'm honestly less worried about Apple than others.

That's a pretty low bar. Yes, Apple at least gives lip service to security which other companies don't even bother to do, but Apple has had some pretty major security screwups lately (three in the last few weeks). You might be less worried about Apple than the competition, but you'd do well to be somewhat worried about them nonetheless.

Re: Apple is sharing your facial wireframe with apps

#13
I've been playing with the TrueDepth Camera APIs on the iPhone X. Some things I've noticed:

1) The ARKit "Face Mesh" seems to be a standard model that is scaled and skewed to fit your face (for example, it ignores glasses, still works if you put your hand in front of your face, etc). It is _not_ a 3D scan.

2) The "TrueDepth" data is not really all that granular. It seems similar to the depth map you get from the rear-facing cameras on the "plus" sized models. Here's what the sensor data spits out: https://twitter.com/braddwyer/status/930682879977361408

3) Apple is really good at marketing. It's been shown that, even if you cover the TrueDepth camera, features that "require" it still work fine (including Animoji and the apps that I've been developing using the front-facing ARKit APIs).

3.1) The lack of Animoji and front-facing ARKit seems to be a software limitation made for business reasons rather than a hardware limitation. See: Google's Pixel 2 portrait mode photos done using a single front-facing camera that have stacked up well against the ones from the iPhone X.

4) The scary part, which is vast dystopian databases of facial fingerprints is already being done with normal photographs. The depth data is not needed.

I agree with the author that the privacy implications of all-encompassing databases could be scary. But I disagree that this has anything to do with the iPhone X or its TrueDepth camera.

Re: Apple is sharing your facial wireframe with apps

#14

What’s interesting is that on the previous security method - fingerprint - no data was shared with apps. If your face is now a security feature and the data is being shared with apps, that sounds like a security leak. If an app collects your face data, can that data be subpoenaed by a court to attempt to unlock your phone? If a court could work with an outside party to use subpoenaed face data to 3D print your face,…

The thing is, I don’t think the 3D scanner really introduces that much functionality beyond what could be done with any normal front-facing camera and software. I’d bet that a few seconds of normal movement would provide enough parallax to build a decent 3D model. In fact, the Apple APIs may not even use the 3D scanner, given that Animojis apparently work with the scanner covered up (and don’t work in the dark).

Re: Apple is sharing your facial wireframe with apps

#15
post #8

Notice the deafening silence.

As I understand it, apps will have access to emotions and other abstracted info about the user, but not the "face" as a reproducible element. This will be interesting for engagement analysis.

> This will be interesting for engagement analysis.

Of course it will, which is why this is another very troubling development in phone software. It's bad enough that most (all?) interactions are logged and data mined in a modern app. Soon emotional data will be too.

Re: Apple is sharing your facial wireframe with apps

#16
post #13

I've been playing with the TrueDepth Camera APIs on the iPhone X. Some things I've noticed: 1) The ARKit "Face Mesh" seems to be a standard model that is scaled and skewed to fit your face (for example, it ignores glasses, still works if you put your hand in front of your face, etc). It is _not_ a 3D scan. 2) The "TrueDepth" data is not really all that granular. It seems similar to the depth map you get from the rear…

#3 is mistaken.

https://www.imore.com/yes-animoji-uses-truedepth-camera-syst...

Re: Apple is sharing your facial wireframe with apps

#17

Earlier quoted context omitted.

Give it a moment, everyone is in scrum.

Back from my scrum. It will take a lot to move myself away from Apple products, but the continuation of issues from last week isn't helping at all. I don't own the iPhone X, but now it's not even a thought. The entire pitch of face id was that it was x times more secure. You can't just give away that data.

I'll certainly have to give this more thought, but I do agree that last week's issues, and well, iOS and MacOS in general, are not up to the quality that Apple users (myself included) expect nor that Apple themselves portray.

Re: Apple is sharing your facial wireframe with apps

#18
Tell me again how FaceID will be "so much more secure" than TouchID - when Apple itself is sharing those 3D facial profiles with third-party vendors (and governments).

In practice, fingerprint readers should still remain significantly more secure than any facial recognition technology.

Re: Apple is sharing your facial wireframe with apps

#19
post #13

I've been playing with the TrueDepth Camera APIs on the iPhone X. Some things I've noticed: 1) The ARKit "Face Mesh" seems to be a standard model that is scaled and skewed to fit your face (for example, it ignores glasses, still works if you put your hand in front of your face, etc). It is _not_ a 3D scan. 2) The "TrueDepth" data is not really all that granular. It seems similar to the depth map you get from the rear…

> 2) The "TrueDepth" data is not really all that granular. It seems similar to the depth map you get from the rear-facing cameras on the "plus" sized models. Here's what the sensor data spits out: https://twitter.com/braddwyer/status/930682879977361408

As @braddwyer himself notes, you can probably get a much better mesh integrating over time. It depends how long it takes to capture a single frame, but I imagine that's not long, so getting an order of magnitude improvement is probably quite easy.

> 4) The scary part, which is vast dystopian databases of facial fingerprints is already being done with normal photographs. The depth data is not needed.

And yes ... after all, humans are quite capable of identifying people with high accuracy from 2D photographs. Depth maps are not required for there to be serious privacy issues with such databases.

Re: Apple is sharing your facial wireframe with apps

#20
post #14

What’s interesting is that on the previous security method - fingerprint - no data was shared with apps. If your face is now a security feature and the data is being shared with apps, that sounds like a security leak. If an app collects your face data, can that data be subpoenaed by a court to attempt to unlock your phone? If a court could work with an outside party to use subpoenaed face data to 3D print your face,…

The thing is, I don’t think the 3D scanner really introduces that much functionality beyond what could be done with any normal front-facing camera and software. I’d bet that a few seconds of normal movement would provide enough parallax to build a decent 3D model. In fact, the Apple APIs may not even use the 3D scanner, given that Animojis apparently work with the scanner covered up (and don’t work in the dark).

>the Apple APIs may not even use the 3D scanner, given that Animojis apparently work with the scanner covered up (and don’t work in the dark).

Animoji uses all of the front sensors - RGB and TrueDepth.

From https://www.imore.com/yes-animoji-uses-truedepth-camera-syst...:

> the TrueDepth camera system captures a crude depth mask with the IR system and then, in part using the Neural Engine Block on the A11 Bionic processor, persistently tracks and matches facial movement and expressions with the RGB camera.

Post reply on HN