Apple is sharing your facial wireframe with apps
41–50 of 152 posts
Re: Apple is sharing your facial wireframe with apps
#42What’s interesting is that on the previous security method - fingerprint - no data was shared with apps. If your face is now a security feature and the data is being shared with apps, that sounds like a security leak. If an app collects your face data, can that data be subpoenaed by a court to attempt to unlock your phone? If a court could work with an outside party to use subpoenaed face data to 3D print your face,…
Access to the live face data stream is provided for features like silly Snapchat filters ("turn your face into a lion" type crap) which the user may opt in to.
Re: Apple is sharing your facial wireframe with apps
#43I've been playing with the TrueDepth Camera APIs on the iPhone X. Some things I've noticed: 1) The ARKit "Face Mesh" seems to be a standard model that is scaled and skewed to fit your face (for example, it ignores glasses, still works if you put your hand in front of your face, etc). It is _not_ a 3D scan. 2) The "TrueDepth" data is not really all that granular. It seems similar to the depth map you get from the rear…
> .. could be scary. But I disagree that this has anything to do with the iPhone X or its TrueDepth camera. Well, lets just say there's the kind of scary fact that nobody, trustworthy, has audited this thing. Like, should a company that didn't run a "doesn't let root login on first-try" test be allowed to be making such wide-ranging decisions as face-scanning? What if I don't want to have my face scanned, but neverth…
Well...yeah. If you're out in public and your face is visible, you don't have a reasonable expectation of privacy.
Re: Apple is sharing your facial wireframe with apps
#44I'm honestly less worried about Apple than others. They've at least made some measures to prove that they are willing to go some distance to protect privacy, even losing ground to competitors in voice recognition. Now thinking about co's like Facebook that not only has access to far more imagery of faces tied to sentiments and moments but have shown time and time again that privacy is a secondary concern AND that the…
> I'm honestly less worried about Apple than others. That's a pretty low bar. Yes, Apple at least gives lip service to security which other companies don't even bother to do, but Apple has had some pretty major security screwups lately (three in the last few weeks). You might be less worried about Apple than the competition, but you'd do well to be somewhat worried about them nonetheless.
- MAC address tracking (RTS packets thrwart MAC randomization[0], not immediately clear if WiFi is fully off[1])
- All-or-nothing access to photos on the phone (append-only for apps that request it)
Discord in particular is bad for the photo permission, as I don't trust China's Tencent with access to all the photos on my phone (which can include lots of frequent location information!), but pasting images doesn't work in the app.
I had assumed the "Photos" permission meant "permission to prompt this dialogue" and "permission to save to Camera Roll".
[0] https://arxiv.org/pdf/1703.02874v1.pdf [1] https://support.apple.com/en-us/HT208086
Re: Apple is sharing your facial wireframe with apps
#45Re: Apple is sharing your facial wireframe with apps
#46Earlier quoted context omitted.
> .. could be scary. But I disagree that this has anything to do with the iPhone X or its TrueDepth camera. Well, lets just say there's the kind of scary fact that nobody, trustworthy, has audited this thing. Like, should a company that didn't run a "doesn't let root login on first-try" test be allowed to be making such wide-ranging decisions as face-scanning? What if I don't want to have my face scanned, but neverth…
> What if I don't want to have my face scanned, but nevertheless need to pick up somebody's lost-phone/detonation-device? Shall I just wear a mask? Well...yeah. If you're out in public and your face is visible, you don't have a reasonable expectation of privacy.
Re: Apple is sharing your facial wireframe with apps
#47Earlier quoted context omitted.
> .. could be scary. But I disagree that this has anything to do with the iPhone X or its TrueDepth camera. Well, lets just say there's the kind of scary fact that nobody, trustworthy, has audited this thing. Like, should a company that didn't run a "doesn't let root login on first-try" test be allowed to be making such wide-ranging decisions as face-scanning? What if I don't want to have my face scanned, but neverth…
> What if I don't want to have my face scanned, but nevertheless need to pick up somebody's lost-phone/detonation-device? Shall I just wear a mask? Well...yeah. If you're out in public and your face is visible, you don't have a reasonable expectation of privacy.
Re: Apple is sharing your facial wireframe with apps
#48I'm honestly less worried about Apple than others. They've at least made some measures to prove that they are willing to go some distance to protect privacy, even losing ground to competitors in voice recognition. Now thinking about co's like Facebook that not only has access to far more imagery of faces tied to sentiments and moments but have shown time and time again that privacy is a secondary concern AND that the…
> I'm honestly less worried about Apple than others. That's a pretty low bar. Yes, Apple at least gives lip service to security which other companies don't even bother to do, but Apple has had some pretty major security screwups lately (three in the last few weeks). You might be less worried about Apple than the competition, but you'd do well to be somewhat worried about them nonetheless.
What I'm about to write does not invalidate your statement and concern, but to me there's a huge gulf between a bug and a willfully-designed feature that explicitly follows a security anti-pattern.
Re: Apple is sharing your facial wireframe with apps
#49Earlier quoted context omitted.
@braddwyer is me :) It gives you about 15 fps of depth data
Haha, cool! Hi :) Given the small size of the laser projector, I imagine natural movement from the phone being hand-held would result in significant displacement of the projected dots over a 1s interval? Have you tried integrating the 15 frames to see what it looks like?
Re: Apple is sharing your facial wireframe with apps
#50As it stands, you can start one of these ads and then turn your phone upside down, or look away. How long until an advertising provider makes use of the attention API and makes it so that you can't look away? Seems bleak.