Live data from Hacker News

Face ID beaten by mask

bkav.com

171–180 of 244 posts

Re: Face ID beaten by mask

#171
post #160

I'm actually going to be very interested to hear how FaceID works for the average user. False positive is one issue and one Apple lauded as being lower than TouchID. What about the false negative rate however? This is what will actually aggravate users. As a user I like touch unlock. I can do it without looking at the phone, having the phone gave me, in the dark, wearing sunglasses and so on. To me face recognition j…

Only negative results I’ve had were due to either proximity (it can’t see my face properly- too far away or too close) or obfuscation (lying on pillow which obscures too much of my face)

Overall it’s much smoother and non-intrusive than TouchID

I’ve never needed to unlock my phone in a situation where I’m not about to look at it so I’m not sure what use case you’re running into there.

As for in the dark: it automatically scans when you swipe up, so no issue. Don’t think of it as “using Face ID” think of it as “swipe up to unlock phone”. The Face ID is just an implementation detail.

Re: Face ID beaten by mask

#172
post #165

If somebody is going to try this hard to get through my Face ID, I’m enough of a high level target that I’m not relying on a shortcut unlock feature of a consumer cell phone. And I’ve likely got bigger problems.

If you are that high level then your family and close associates are all targets. Same goes their family and network...

Re: Face ID beaten by mask

#173

Earlier quoted context omitted.

This assumes a lot. As the OP said: demonstrate that from that data you can produce a sufficiently accurate model that works with this method. The article hasn’t. It may be possible (you only have to match the resolution of the IR depth map) but it is not currently demonstrated . Plus I imagine it’s quite easy to refine FaceID in the software as well so an attack like this may not be very long lasting.

Attacks only get better with time. Check back in a couple years and someone may have done just that.

Defenses only get better with time too. That isn’t a good argument. Based on that logic we should have no security ever on anything because it’s always pointless long term.

Re: Face ID beaten by mask

#174
post #89

> Because... we are the leading cyber security firm ;) But you don't even use HTTPS. Why?

Because the information was meant to be public anyway?

Not using https means that your ISP, your mobile carrier, or your airport network provider can modify the information being presented to you. This is not a hypothetical, it happens all the time (though usually just to inject ads).

It's not about whether the provider wants the information to be public, it's about whether the provider wants the information to arrive intact.

Re: Face ID beaten by mask

#175

Once someone is at the stage where they're going to 3D scan you, create a replica of your face and steal your phone to get into it...why wouldn't they just coerce you into unlocking your phone with force? See https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Obligatory https://www.xkcd.com/538/

Re: Face ID beaten by mask

#176
post #94

I wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before…

> As for fingerprints versus facial recognition, the article claims fingerprints are better, but I’m skeptical. For one thing, my phone is covered in my own fingerprints, so getting something to copy is a lot easier. Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? I'm only half-serious, but it might make lifting the real prints harder...…

> maybe it is trivial to distinguish prints made on a surface from those in the structure of the surface

I believe it is. Fingerprints left on a surface are made with oils from the skin and are "lifted" off by applying a substance that sticks to it and literally lifting the print off the surface.

Re: Face ID beaten by mask

#177
post #95

Can sombebody explain this: "A: It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask." Does it mean passcode was completely off and the phone would n…

> It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure.

They are saying the question is moot.

> However, we knew about this "learning"

but they are going to answer the question regardless

> thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.

They ensured that the mask didn't get integrated into Apple's learning data by never entering the pin. The understanding is that whenever a failed face scan is followed by a correct pin, the face scan is added to learning data (since the assumption is it belongs to the legit user).

Re: Face ID beaten by mask

#178
post #157

Earlier quoted context omitted.

Interesting. Can you point to any official white-paper from Apple claiming this? I'm reading this: https://www.apple.com/business/docs/iOS_Security_Guide.pdf but I cannot find any such information about a living person.

https://www.quora.com/Can-Apples-Touch-ID-tell-between-the-f...

While I'm pretty sure that Touch ID does have liveness sensing, that answer is nonsense. Nothing about capacitative touch requires liveness. You can manipulate a touchscreen with a hot dog.

Re: Face ID beaten by mask

#179
post #130

Earlier quoted context omitted.

Artists aren't particularly well paid.

… for pure art, maybe. For commercial artists, especially ones capable of precise results on a deadline and, in this case, also not asking too many questions?

not true either, read up on past stories of skilled forgers of paper currency: their labor was surprisingly inexpensive.

Re: Face ID beaten by mask

#180
post #9

As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID…

> As a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask So like what they can gather from 100s of one's photos in social media and other places?

they also have to gain physical access to your device, so if you're that worried about it, don't use FaceID or do the 'squeeze lock' to disable FaceID and require your passcode for the next unlock before you go to bed or something
Post reply on HN