Live data from Hacker News

FaceID Security [pdf]

images.apple.com

161–170 of 314 posts

Re: FaceID Security [pdf]

#161

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

> And I don't see people complaining about the state of home security... Home security is a really poor analogy. * Attacking everybody's house at once is not scalable, unlike attacking many people's electronic devices at once. Furthermore, defending against a SWAT team armed with a search warrant is nigh impossible, no matter what lock you put on your front door. * The contents of most people's houses is far more wei…

The analogy is one of defense in depth: if you're serious about security, you can use memorized & typed secondary passwords on secure apps, such as secure notes in 1Password, or an app like https://guardianproject.info/apps/pixelknot/ that would steganographically encode secure notes into otherwise normal photos, potentially with independent passwords for complete deniability.

A locked door and a face-locked iPhone are only the first line of defense, and are largely for convenience's sake in both daily use/as a deterrent and in the case of physically being distant from your property. The "guns" are entirely independent.

Re: FaceID Security [pdf]

#162

Earlier quoted context omitted.

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

You turn it off until it's been confirmed secure again. This is not much different from any security issue in software -- you disable the functionality until it's secure again. The only risk is if somebody cracks the entire FaceID model and Apple cannot fix it in software. But even then, you would still disable FaceID and either return your phone or wait for a recall.

You can't replace your face. Are you suggesting that people turn it off until it's secure again meaning, like, plastic surgery?

Re: FaceID Security [pdf]

#163

Earlier quoted context omitted.

> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.

The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court.

In the phone case, they don't need a warrant if your authentication method is literally your face.

Re: FaceID Security [pdf]

#164

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.

I keep hoping that FaceID will also get FacePassword, where you have to show one or more expressions in order. Then it becomes a password, and the police can't force you to change your expression.

Re: FaceID Security [pdf]

#165
post #127
post #55

I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…

One common scenario where I often have problems with TouchID and FaceID should solve them: wet hands.

I just train my wet and dry prints separately, as separate fingers. If you promise no to tell any would be thief/gov about the backdoor into my phone, I’ve done the same for my capacitive glove finger.

Re: FaceID Security [pdf]

#166

Earlier quoted context omitted.

Not to mention incredibly difficult to pull off. It isn't like having two passwords, one distress password and one normal. An algorithm that needs to identify your face in any situation AND detect subtle characteristics? I don't see that being a reality with our current technology. Or at least without significant false positives. Though a two password feature would be nice and easy to implement.

It could be something as simple as having one eye closed when under duress(sorry, monoculars!). It only takes one unlock attempt to then lock it down. Bonus with this is that LE couldn't hold the phone up to your face while you are sleeping to unlock it.

I see two problems with that. 1) Everyone now knows that the duress signal is one eye 2) people with one eye (or at least as far as the algorithm is concerned) cannot use the service. Which say, you got beat up and one eye was swelling you might accidentally set it into duress mode, when you need the full mode and you bypass the password override.

I just think that a duress mode with facial recognition (that also has to account for eye-wear, makeup, and various environmental changes) is going to have a difficult time creating a duress mode. Whereas a dual password system is easy to implement.

Re: FaceID Security [pdf]

#167

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

Tell apple they can only recognize your face if it shows a certain expression

Re: FaceID Security [pdf]

#168
post #50

Earlier quoted context omitted.

This is woefully insufficient for a feature I have been begging for forever... I would prefer it to be a double-tap on the power button, or at the very absolute worse, a triple tap. Two buttons simultaneously five times? Impossible to do under any sort of external pressure/duress.

Not sure where you got two buttons from. It's only the power button.

On this year's hardware, they have added a new option to temporarily disable biometrics.

You press either one of the volume buttons on one side of the phone while also pressing the sleep/wake button on the opposite side.

http://www.techrepublic.com/article/how-to-disable-face-id-o...

Re: FaceID Security [pdf]

#169

Earlier quoted context omitted.

It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.

I keep hoping that FaceID will also get FacePassword, where you have to show one or more expressions in order. Then it becomes a password, and the police can't force you to change your expression.

To the extent the police can legally compel you to provide access to a device, the means by which that access is protected does not impede their legal capability to do it and impose consequences for non-compliance.

Re: FaceID Security [pdf]

#170

Earlier quoted context omitted.

You turn it off until it's been confirmed secure again. This is not much different from any security issue in software -- you disable the functionality until it's secure again. The only risk is if somebody cracks the entire FaceID model and Apple cannot fix it in software. But even then, you would still disable FaceID and either return your phone or wait for a recall.

You can't replace your face. Are you suggesting that people turn it off until it's secure again meaning, like, plastic surgery?

You can't!? Wow, thanks for teaching me that.

Did you even read what I wrote? You would turn off FaceID and revert back to a passcode/passphrase until it is fixed in software.

Post reply on HN