Earlier quoted context omitted.
Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…
Reading the linked PDF: > To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern. and > An additional neural network that’s trained to spot and resist spoofing defends against attempts to unlock your phone with photos or masks. It's effectiveness is yet to be seen, but the implementation details count…
FaceID Security [pdf]
211–220 of 314 posts
Re: FaceID Security [pdf]
#212Earlier quoted context omitted.
Not sure where you got two buttons from. It's only the power button.
On this year's hardware, they have added a new option to temporarily disable biometrics. You press either one of the volume buttons on one side of the phone while also pressing the sleep/wake button on the opposite side. http://www.techrepublic.com/article/how-to-disable-face-id-o...
Re: FaceID Security [pdf]
#213I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
Re: FaceID Security [pdf]
#214Recently I posted this theoretical spoofing attack in a comment. I'm glad to know they've put in the appropriate measure to detect it - randomly blinking the IR dot pattern, requiring any spoofed videos to react to the blinking with very near zero lag (likely sub-microsecond). Specifically, the last step in this process could be detected because the generated IR video would have a static dot pattern. How to (not) hac…
Theoretical countermeasure: I get an IR visible tattoo that you can't see in my Facebook pictures but FaceID can. I think the level of equipment needed to pull your attack off couldn't be done off-the-shelf. It seems reasonable that IR camera would scan in detail greater than that of a typical display (say, 500ppi) and it needs 100,000dpi resolution. Then you need bigger displays, advanced optics to reduce it to the…
I suspect the ir camera is a few mega pixels at most.
Re: FaceID Security [pdf]
#215Earlier quoted context omitted.
To the extent the police can legally compel you to provide access to a device, the means by which that access is protected does not impede their legal capability to do it and impose consequences for non-compliance.
That's the thing -- the police can't legally compel you to provide them access to your device, but if they can get it without you having to give them anything, by, say, pointing the phone at your face, it's fair game. I don't have time to look up the court precedents about this, but that's my understanding of the current state of the law.
Your understanding of the current state of the law is very wrong.
There's a person in the US [0] who has been in jail for multiple years now without being tried / convicted due to refusing to provide access to their devices.
There's another case with a warrant[1] allowing an officer to force someone to unlock their phone protected by TouchID.
I have also heard multiple US states have enacted laws specifically addressing device unlock, but I don't have links to them at the moment.
[0] https://arstechnica.com/tech-policy/2017/08/man-in-jail-2-ye...
[1] http://files.cloudprivacy.net/la-iphone-fingerprint-warrant....
Re: FaceID Security [pdf]
#216Earlier quoted context omitted.
But your argument makes no sense. The attack isn't "someone stole the processed image ("stick figure") of my fingerprint", the attack is someone copied my fingerprint .
That’s TouchID. Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you? The fingerprint argument isn’t an argument against FaceID. And it’s still kind of pointless because Apple put out figures a few years ago that TouchID lead to a ~50% INCREASE in locked phones. You seem to be arguing that a secure passcode without biometrics is…
Re: FaceID Security [pdf]
#217The problem I have is with the lack of TouchID. FaceID is fine. But, I don't always want to have to stop what I'm doing, loooook at the phone and then proceed. Sometimes I even unlock my phone in my pocket to sneak a look. How do you do that with FaceID when the sensor's been removed?
By “removed” do you mean “occluded”? If you have access to the screen but not to the sensor array, you can use a passcode. This is obviously very difficult to do when the phone’s in your pocket, so that’s a very small regression in usability there, but that seems like an extreme edge case.
>> extreme edge case
OK, maybe. Though I think TouchID has become so quick and natural that we forget it's even happening. For me it's almost automatic as I pull it from my pocket. Maybe FaceID will get to that point also.
But I think I'm safe in predicting, at least in the beginning, memes of people looking with zombie like stares at their phones trying to get them to unlock.
Re: FaceID Security [pdf]
#218I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
> your biometrics can't be easily stolen, and you can't lose them. Fingerprints are very different from face. Someone has to actually follow you around and clone your fingerprint from something you touched. With facial unlock, as virtually all previous systems have demonstrated, you usually only need someone's online photo, or a close variation of that to unlock a device/system that uses face unlock. With everyone pl…
I believe it was doing infrared detection.
Re: FaceID Security [pdf]
#219Earlier quoted context omitted.
On this year's hardware, they have added a new option to temporarily disable biometrics. You press either one of the volume buttons on one side of the phone while also pressing the sleep/wake button on the opposite side. http://www.techrepublic.com/article/how-to-disable-face-id-o...
Didn't realise the X model did it differently than all others. Weird.
If history is a guide, this will be a new normal that will carry through to future hardware as well.
Re: FaceID Security [pdf]
#220Earlier quoted context omitted.
That’s TouchID. Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you? The fingerprint argument isn’t an argument against FaceID. And it’s still kind of pointless because Apple put out figures a few years ago that TouchID lead to a ~50% INCREASE in locked phones. You seem to be arguing that a secure passcode without biometrics is…
Oh, no, I absolutely agree that biometrics overall increase security for everyone. My argument is entirely a pedantic one. FaceID is clearly an improvement precisely because it makes stealing your "original" biometrics much more difficult.
“Biometrics are evil because you can’t change them.” Or “They’re usernames/passwords/whatever.” Or “FaceID can be subverted by a nation state with 3 years and $75 trillion”. Or “You can just unlock it with a single picture from Twitter.”
And of course “If only they added an esoteric and complex method of unlocking a fake environment under duress by winking the word tomato backward in French Morse code...”
None of it seems helpful. Using a FaceID discussion to argue TouchID is insecure... seems pointless. The arguments about how it can be bypassed (supposedly) with JUST a 3D printer and thousands of high resolution photos and a video of you looking into a camera and........ come on. This stuff would be unbelievable in an Oceans 11 sequel.
And people argue as if FaceID has to be perfect when it replaces a fingerprint (which is easier to fake) or basically nothing. We’re not securing the Crown Jewels here. We’re trying to keep the guy next to you at the bar from tweeting as you.
So in the end there is no useful on top discussion. It’s just a irrelevant story that people can use to tell about their pet biometric issues even when they don’t fit.
People are still arguing about things Apple said during the initial keynote. The only one I don’t see from before is the ‘will it work in the dark’ question which Apple explicitly mentioned in the keynote.
I want to know more about FaceID from people who know more about security. Instead we’re discussing how the technology it replaced is bad and fringe internet conspiracy theory level nonsense.
Edit to add one more thing: maybe this is rose colored glasses but I don’t remember the threads around TouchID being anywhere near this bad. People argued over how easy it was to get a fingerprint, sure. That’s fair. But the rest of the discussion seemed much more relevant.