Live data from Hacker News

FaceID Security [pdf]

images.apple.com

201–210 of 314 posts

Re: FaceID Security [pdf]

#201

Earlier quoted context omitted.

Two questions: How often do you get arrested where that edge case is a legitimate concern? If being arrested were a legitimate concern, why would you keep data on your phone that would implicate you in a crime? If you were in a higher risk group (i.e. a drug dealer,) why not disable Face ID? Use a six digit pin and be done with it. I am not particularly worried about cops, I am worried about losing my phone and havin…

I and others I know have faced this problem often enough that it is a primary concern for me. Political dissidents are the group I'm concerned about. Police are very interested in extracting contact lists from activists' phones in order to build a model of their social networks and infiltrate/disrupt them. This is a pervasive problem. Yes, the answer is to get people to turn off FaceID if they're at risk, but educati…

Apple’s studies/metrics showed that basically no one (5-10%?) used passwords or pins before TouchID.

You already have to educate them to use a password, is it that hard to say ‘and don’t use biometrics either’?

Re: FaceID Security [pdf]

#202

Earlier quoted context omitted.

You are implying that there is a "secret" based on that face mapping that can be copied out of the device and then used to either 1) gain access to a non-Apple system that has some kind of biometric face detection system or 2) can be used to reproduce a face like yours to unlock your phone without you present From the PDF: "Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads ov…

Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…

Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode.

Either way, let's say this attack you're talking about is possible. What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "trivial." If you're Edward Snowden, don't use this feature. Simple as that. But I wouldn't use TouchID if I was Snowden either.

Judging by your last paragraph, though, I'm guessing you're trolling. Have a nice day.

Re: FaceID Security [pdf]

#203

Earlier quoted context omitted.

You are implying that there is a "secret" based on that face mapping that can be copied out of the device and then used to either 1) gain access to a non-Apple system that has some kind of biometric face detection system or 2) can be used to reproduce a face like yours to unlock your phone without you present From the PDF: "Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads ov…

Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…

Reading the linked PDF:

> To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern.

and

> An additional neural network that’s trained to spot and resist spoofing defends against attempts to unlock your phone with photos or masks.

It's effectiveness is yet to be seen, but the implementation details counter all the points you made.

Re: FaceID Security [pdf]

#204
post #201

Earlier quoted context omitted.

I and others I know have faced this problem often enough that it is a primary concern for me. Political dissidents are the group I'm concerned about. Police are very interested in extracting contact lists from activists' phones in order to build a model of their social networks and infiltrate/disrupt them. This is a pervasive problem. Yes, the answer is to get people to turn off FaceID if they're at risk, but educati…

Apple’s studies/metrics showed that basically no one (5-10%?) used passwords or pins before TouchID. You already have to educate them to use a password, is it that hard to say ‘and don’t use biometrics either’?

No, now you have an additional problem, because they might ignore the advice to use a password now that they think their device is secure by default

Re: FaceID Security [pdf]

#205

Earlier quoted context omitted.

Here's the sequence of events: 1. You're walking, with your phone in your pocket. 2. Suddenly, a cop accosts you. You don't have time to react. 3. They detain and restrain you (with handcuffs or otherwise) 4. They pat you down and find your phone 5. They hold up your phone to your face to unlock it I know that people who've never been detained or interacted much with cops think that this is a completely unlikely situ…

As someone who has been stopped/questioned/detained before domestically and internationally (as well as at border checkpoints) as well as mugged, I can assure you that touch vs look is pretty much the same (definitively not light years in difference). The solution is to be proactive. If you are going to walk down the street in an at risk area, you hit the power button five times. If you are about to go through a CBP…

> The solution is to be proactive. If you are going to walk down the street in an at risk area, you hit the power button five times. If you are about to go through a CBP checkpoint, then do the same.

You and I have incredibly different experiences of policing and detention if, for you, "be proactive when you're at-risk" is appreciably different from saying "don't use FaceID ever".

Re: FaceID Security [pdf]

#206

Earlier quoted context omitted.

You are implying that there is a "secret" based on that face mapping that can be copied out of the device and then used to either 1) gain access to a non-Apple system that has some kind of biometric face detection system or 2) can be used to reproduce a face like yours to unlock your phone without you present From the PDF: "Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads ov…

Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…

TouchID can be easily tricked. From december of 2014 at CCC: [1]

Its not merely secret service who can do this. Criminals can do it as well. The easy part of it? Your fingerprint is left all over your device. Including likely the one you authenticate with. If its your index finger of your primary hand, its bingo.

A fake 2G cell tower costs 250 EUR on the black market. That's also a bad way to use TOTP. However, 15 years ago those devices were either not sold or still very expensive. That's a different threat model.

FaceID is going to be hacked eventually (the question is when, not if), perhaps in the way you described. Until then it is reasonably good to keep criminals who steal your device at bay. Its also worth it to audit it (try to break it, e.g. in the way you described). State agencies, unlikely to keep those at bay with FaceID, given they can force you to authenticate. Criminals who mug you by force may also be able to force you to remove FaceID, but they may also compel you to give away your PIN. Government has already made devices to bruteforce PINs; we should've swapped to passwords ages ago.

[1] https://media.ccc.de/v/31c3_-_6450_-_de_-_saal_1_-_201412272...

Re: FaceID Security [pdf]

#207

Earlier quoted context omitted.

As someone who has been stopped/questioned/detained before domestically and internationally (as well as at border checkpoints) as well as mugged, I can assure you that touch vs look is pretty much the same (definitively not light years in difference). The solution is to be proactive. If you are going to walk down the street in an at risk area, you hit the power button five times. If you are about to go through a CBP…

> The solution is to be proactive. If you are going to walk down the street in an at risk area, you hit the power button five times. If you are about to go through a CBP checkpoint, then do the same. You and I have incredibly different experiences of policing and detention if, for you, "be proactive when you're at-risk" is appreciably different from saying "don't use FaceID ever".

Or I guess our detection of risk differs. I have never been detained when I didn't have a "hair on my neck raise" with enough time to disable my phone.

If you are in such high risk situations continuously that "be proactive when you're at-risk" is appreciably the same as "don't use FaceID ever", then I say you are doing something very wrong and not just incidentally being stopped for a suspicion of possibly doing something wrong.

Either way, your experience is definitely not in the 99.9999% of the population which FaceID would be sufficiently safe if it proves to be as secure as Apple implies. For you, let's hope you aren't using a numeric pin code either!

Re: FaceID Security [pdf]

#208

Questions: * Does one explicitly set up their FaceID with the option to skip, like how TouchID works currently? I see (when...enabled) verbiage, which is a good sign. * "The probability that a random person in the population could look at your iPhone X and unlock it using Face ID is approximately 1 in 1,000,000 (versus 1 in 50,000 for Touch ID)" If you have a face that causes most people you meet to say "oh, you look…

Like Touch ID, you don't have to enable Face ID if you prefer not to use it.

Re: FaceID Security [pdf]

#209
post #138

Earlier quoted context omitted.

i wonder if the feds can compel you to open your eyes

It would seem to be extremely difficult for them to compel you to aim them at a fixed point in space.

The police can forcefully draw your blood with a warrant.

Maybe they can also forcefully sedate you or fix your head/eyes with some medical device.

Re: FaceID Security [pdf]

#210

Earlier quoted context omitted.

Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…

Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode. Either way, let's say this attack you're talking about is possible. What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "…

>Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode.

You don't need to shut off the phone to get into the hardware.

>What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "trivial."

On the other hand, I bet a company could easily implement such an attack on the cheap and sell it to LE, who would just pass the costs on to the defendant.

>Judging by your last paragraph, though, I'm guessing you're trolling. Have a nice day.

I'm setting the stakes. If you're not up for the discussion that's up to you.

Post reply on HN