Live data from Hacker News

FaceID Security [pdf]

images.apple.com

181–190 of 314 posts

Re: FaceID Security [pdf]

#181

Earlier quoted context omitted.

I keep hoping that FaceID will also get FacePassword, where you have to show one or more expressions in order. Then it becomes a password, and the police can't force you to change your expression.

To the extent the police can legally compel you to provide access to a device, the means by which that access is protected does not impede their legal capability to do it and impose consequences for non-compliance.

That's the thing -- the police can't legally compel you to provide them access to your device, but if they can get it without you having to give them anything, by, say, pointing the phone at your face, it's fair game. I don't have time to look up the court precedents about this, but that's my understanding of the current state of the law.

Re: FaceID Security [pdf]

#182

Earlier quoted context omitted.

It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.

Two questions: How often do you get arrested where that edge case is a legitimate concern? If being arrested were a legitimate concern, why would you keep data on your phone that would implicate you in a crime? If you were in a higher risk group (i.e. a drug dealer,) why not disable Face ID? Use a six digit pin and be done with it. I am not particularly worried about cops, I am worried about losing my phone and havin…

I and others I know have faced this problem often enough that it is a primary concern for me.

Political dissidents are the group I'm concerned about. Police are very interested in extracting contact lists from activists' phones in order to build a model of their social networks and infiltrate/disrupt them. This is a pervasive problem.

Yes, the answer is to get people to turn off FaceID if they're at risk, but educating large groups of at-risk people is hard, and it would be better if this feature were not turned on by default.

Re: FaceID Security [pdf]

#183

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

Very important point (re: house key analogy). Houses and cars are 1000% not secure, you can always break a window and get access. That's why they have ARMORED cars and bank VAULTS or safes. However, if you break a window, or drill a hole in a safe, there is "visible sign of forced entry". https://en.wikipedia.org/wiki/Forcible_entry When you see a broken window by your front door, when you see a broken window on your…

You raise very good points, but it's not like there aren't ways to break into a house without signs of forced entry.

To my mind, privacy is often the most important difference. There are a lot more private things on my phone than in my house, honestly -- a phone these days is often almost an extension of the mind. Which is why we should hold it to a higher standard.

I personally have no problems with TouchID/FaceID, I think the secure enclave is great, but I still think there's a lot of room for improvement, better sandboxing of data, better tripwires for when data is accessed/transferred, etc.

Re: FaceID Security [pdf]

#184

Earlier quoted context omitted.

> The same holds true for physical keys. Nobody's saying that home security is good. The point the parent was making is that, even with a "liveness test", compared to other biometric identification, this is a regression from fingerprint-based authentication for the iPhone.

How is it a regression? What kind of scenario exists where the cops can force you to FaceID unlock your phone, but not TouchID unlock it? You think they can force you to look at it ("engage" with it) but not touch the phone?

Technically I could see FaceID being marginally more secure in one very specific edge case... If you are asleep. With TouchID, all that is needed is to push their finger to the phone. With FaceID, your eyes would need to be open (theoretically, let's see in practice).

Re: FaceID Security [pdf]

#185

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

> your biometrics can't be easily stolen, and you can't lose them.

Fingerprints are very different from face. Someone has to actually follow you around and clone your fingerprint from something you touched.

With facial unlock, as virtually all previous systems have demonstrated, you usually only need someone's online photo, or a close variation of that to unlock a device/system that uses face unlock.

With everyone plastering their photos in high resolution all over the web these days, and with machine learning advancing so fast these days, how long until a system like this is defeated?

Do you really think "3D photos" of you can't be created? Or even ones that test for "liveness". What exactly do you think that "liveness test" is? It's just an algorithm that Apple uses. That algorithm can be reverse-engineered.

Also, Apple's Face ID has a False Acceptance Rate of 1 million versus TouchID "only" 50,000, is very misleading. That metric only works when you think of an attacker throwing completely random faces at the system. Do you think an attacker that wants your phone is going to throw random faces at the device? Or do you think it's far more likely that it will start building that 3D profile out of your high-resolution online photos?

Suddenly that 1 million FAR becomes much smaller, as the difference in profile from what the attacker has already gathered on you from public websites is much smaller than how you look like in real life.

This is what may actually make the Face ID system less secure overall than TouchID. It's just way way easier to get someone's pictures than it is to get their fingerprints.

Re: FaceID Security [pdf]

#186
post #163

Earlier quoted context omitted.

The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.

>Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissible in court.

Depends on the country. Not everywhere, including western Europe, is this true.

Re: FaceID Security [pdf]

#187
post #116

Earlier quoted context omitted.

If I lose my house key I can change the locks and make the old key worthless. How do you change biometric keys once they're compromised?

It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption. My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.

"Liveness tests" will be beaten in the same way Apple created them: with machine learning.

Re: FaceID Security [pdf]

#188

Earlier quoted context omitted.

You can't!? Wow, thanks for teaching me that. Did you even read what I wrote? You would turn off FaceID and revert back to a passcode/passphrase until it is fixed in software.

Until what's fixed in software? Your face being compromised? You can't fix a leaked secret in software.

You are implying that there is a "secret" based on that face mapping that can be copied out of the device and then used to either 1) gain access to a non-Apple system that has some kind of biometric face detection system or 2) can be used to reproduce a face like yours to unlock your phone without you present

From the PDF:

"Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads over 30,000 infrared dots to form a depth map of the face, along with a 2D infrared image. This data is used to create a sequence of 2D images and depth maps, which are digitally signed and sent to the Secure Enclave. To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern. A portion of the A11 Bionic chip’s neural engine—protected within the Secure Enclave—transforms this data into a mathematical representation and compares that representation to the enrolled facial data. This enrolled facial data is itself a mathematical representation of your face captured across a variety of poses. "

So, it's more like a hash of your face, which is very similar to how TouchID works. So, again, even if someone were able to break into the secure enclave and get that data, what could they do with it? It's a representation of yourself that is used for Apple devices.

Also, this is an OPTIONAL feature. If it doesn't fit your security model, don't use it. For the same reason a lot of people don't use TouchID -- they want the security of a passphrase. But for 90%+ of people that will buy that phone and are not at risk of the government or police pursuing them, the security it offers is more than adequate and it achieves this by not annoying the user and requiring them to have a 50 character passphrase.

Re: FaceID Security [pdf]

#189

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.

There is a way to quickly disable face id, presumably you would do so in most situations when facing police.

Re: FaceID Security [pdf]

#190

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

The problem with biometrics is not username vs password, biometrics are password. The problem is that these are client-side protections, and there's no data sent to a server that can verify the identity. And you can't build a remote identity verification with this data, because there's no way for the user to change it and revoke it (let alone it's very privacy sensitive). The biometric access control systems (the one…

> The problem with biometrics is not username vs password, biometrics are password.

Yes, that is the problem. No, biometrics are not password. Please stop spouting this nonsense? Biometrics are akin to username; they suggest your identity, but don't authenticate you. They should not be used as password because they cannot be changed, and cannot be kept secret. A password (or better, TOTP authentication) can be changed, and can be kept secret; a hardware fingerprint scanner (or face or iris scanner) cannot be changed, and can be faked by any semi-intelligent person or organization. Fingerprint can already be stolen and used in identity theft. We saw this various years ago in CCC when a German minister got his/her fingerprints stolen as a way to prove the insecurity. It is only a matter of time when the common people learn about how to trick face recognition and iris recognition. In the meantime, strong passwords and (preferably) TOTP is secure. Use that instead.

> Research in biometric security aims at finding functions of your biometric data that can be revoked and it's not privacy sensitive.

Cat and mouse game, and wrong premise: biometrics cannot be revoked. They're permanent.

Post reply on HN