Sometimes I even unlock my phone in my pocket to sneak a look.
How do you do that with FaceID when the sensor's been removed?
121–130 of 314 posts
Sometimes I even unlock my phone in my pocket to sneak a look.
How do you do that with FaceID when the sensor's been removed?
I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
I have a house with a standard lock. A couple years ago someone decided to kick the front door in while I was at work. We have shitty house locks because the entire system is terribly insecure and strengthening one link in the chain is pointless.
Also, OP says you can't lose your biometrics. You can, it's just painful and you'll not be the least bit happy about it.
Earlier quoted context omitted.
Twins and siblings that look like you are not random people.
Now I'm imagining the FBI using its facial-recognition databases and tracking down people who look like the phone owner to wave an iPhone in front of their face.
Sounds like a movie plot to me (I made a guess at one if you dig through my comment history).
Recently I posted this theoretical spoofing attack in a comment. I'm glad to know they've put in the appropriate measure to detect it - randomly blinking the IR dot pattern, requiring any spoofed videos to react to the blinking with very near zero lag (likely sub-microsecond). Specifically, the last step in this process could be detected because the generated IR video would have a static dot pattern. How to (not) hac…
Theoretical countermeasure: I get an IR visible tattoo that you can't see in my Facebook pictures but FaceID can. I think the level of equipment needed to pull your attack off couldn't be done off-the-shelf. It seems reasonable that IR camera would scan in detail greater than that of a typical display (say, 500ppi) and it needs 100,000dpi resolution. Then you need bigger displays, advanced optics to reduce it to the…
Earlier quoted context omitted.
If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?
It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption. My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.
You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.
I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…
Earlier quoted context omitted.
No, because they (and we) don’t want to be able to store face information server-side.
They wouldn't have to until the phone is reported stolen and the user enables it.
Earlier quoted context omitted.
- More secure (Face ID uses more data points) - Less user-interaction to authenticate (though as you point out this is also a negative) - Allows for other UX improvements, e.g., maintaining screen lighting while phone is being observed but not manipulated - My speculation: capacity to add additional faces will be added with SW (or next HW) update __ I don't understand your point #3. How do you think someone would unl…
For their Point #3 I'm guessing they are saying if they are sleeping or a mugger points their phone at their face. Fortunately, Face ID has focus detection, so if you aren't looking at it then it won't unlock. Which makes point #3 moot as well.
It requires your face + your attention.
I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
Home security is a really poor analogy.
* Attacking everybody's house at once is not scalable, unlike attacking many people's electronic devices at once. Furthermore, defending against a SWAT team armed with a search warrant is nigh impossible, no matter what lock you put on your front door.
* The contents of most people's houses is far more weighted to "things which would be a hassle to file with insurance to replace" and less "it would ruin my life if this got into the wrong hands", and their strategy for home defense is weighted as such.
* Many people whose strategy for home defense (well, in the US) is more serious, will weigh more towards weapons / guns and less to the actual locks on the doors. What would a digital equivalent be? A prick of poison for anybody who picks up a phone which doesn't belong to them? The analogy totally breaks down in context.