Live data from Hacker News

FaceID Security [pdf]

images.apple.com

231–240 of 314 posts

Re: FaceID Security [pdf]

#231

Earlier quoted context omitted.

Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode. Either way, let's say this attack you're talking about is possible. What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "…

>Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode. You don't need to shut off the phone to get into the hardware. >What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "tri…

> You don't need to shut off the phone to get into the hardware.

Do you mean row hammer [1] or cold boot attack [2]?

[1] https://en.wikipedia.org/wiki/Row_hammer

[2] https://en.wikipedia.org/wiki/Cold_boot_attack

Re: FaceID Security [pdf]

#232
post #118

Earlier quoted context omitted.

It mentions infrared picture. Masks probably have a different infrared signature. But so does your face if it's been wearing a balaclava in the cold (some parts will be cold and some will be warm...

I seriously doubt they’re using actual infrared emissions (as in heat measurements), I imagine it’s just used as a simple B&W camera so they don’t need visible light.

Since I’ve been downvoted and I can no longer edit, let me try to explain my theory:

I’m guessing they only use the camera to read the positions of the dots projected onto the face. I don’t think they care about the ‘color’ of the face or how hot it is thermally.

They’ve said they’re projecting the infrared dots? Have they said they’re doing any other kind of infrared illumination like the kind that can show blood vessels?

I’m curious to see if face paint (assuming it reflects IR to a reasonable degree) interferes with FaceID. If it does they’re using more than just the dots for geometry. On the other hand if it doesn’t then the can’t be paying attention to things like IR emissions from the skin since it would be covered and thus heavily dampened.

Right?

Re: FaceID Security [pdf]

#233

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

Its more nuanced than you put it with physical keys.

Consider for a moment the baklava [1]. A baklava increases anonymity of an attacker (ie. burglar in our discussion), but also increases suspiciousness of victims and 3rd parties (ie. innocent bystanders, witnesses).

Physical burglary has many of these nuances, trade-offs.

A key on a front door is meant to keep an attacker out for as long as they get caught and/or identified, or become afraid they get caught and/or identified. It isn't meant to stop an attacker to enter a house. If an attacker wants to enter your house, they can just break in via a window. Various techniques exist for that, some are noisy, others are more sophisticated and aren't noisy.

Someone who's trying to enter via a window by night though is suspicious which means the attacker might be noticed and get caught. Most normal house keys [at least here in NL] are very cheap and have a lot of vulnerabilities, they have weak entropy (e.g. 6 entries with 6 options each), or are vulnerable via lock bumping (takes max 10 sec to enter and doesn't look very suspicious).

With electronic devices, its more binary, but it depends a lot on whom you're defending against. Petty criminals, technical criminals, or state actors.

> This is in contrast to passwords and pincodes, which can be stolen by eyeballs, cameras, audio recording devices, etc.

Yes, passwords can be stolen by eyeballs and cameras and Van Eck phreaking (TEMPEST). However if combined with TOTP it becomes something you have and something you know. Facial recognition is just a form of something you have, and the key cannot be changed.

They key can be put off, but that is not more secure than having TOTP on your watch (with yes/no button) and being able to disable the authentication method on your phone by pressing the power button 5 times.

Liveness is just obscurity. Its gonna be insecure at some point, and you'll be begging Apple for a newer, more secure solution at that point. Pray they still support your advice by then.

[1] Yes, thank you, balaclava (bivakmuts in my primary language). I have difficulty pronouncing and remembering the word. I'll keep it as-is for readability of the discussion, and for admitting my mistake.

Re: FaceID Security [pdf]

#234

Earlier quoted context omitted.

It mentions infrared picture. Masks probably have a different infrared signature. But so does your face if it's been wearing a balaclava in the cold (some parts will be cold and some will be warm...

Just guessing here, but veins and blood flow are visible in infra red [1]. A color camera can also measure pulse using small color variations. [1] https://software.intel.com/en-us/articles/pulse-detection-wi...

Apple wants this to work in total darkness. So color wouldn’t work. Do we know if they’re projecting IR light (besides the dot pattern) that they could use to look for blood vessels?

Re: FaceID Security [pdf]

#235
post #135

Earlier quoted context omitted.

> I still wish it had an "unlock under duress" mode The practical applications of this are close to nil. The government will not be fooled for one second because they can cross reference enough sources to know if you are lying. All this will do is get you slapped with a felony: https://www.popehat.com/2011/03/18/just-a-friendly-reminder-... If it is a criminal instead, well, they don't have to tiptoe around moral, et…

In addition to this, don't keep private (and certainly not illegal) data on a compute device that you walk around with. Maybe, just maybe, treat that device as compromised from the start and treat it accordingly. The idea of using them as secure devices should probably stop, at least until they are actually secure. Moreover, if you're committing crimes, maybe don't record them in a way that is recoverable. Not that y…

Why carry a smartphone then? Current tech doesn't allow for regular users to secure their data in this fashion. I mean you'd have to completely log out of something like Dropbox even if you managed to keep your data remote.

Re: FaceID Security [pdf]

#236
post #113
post #63

Earlier quoted context omitted.

How did you arrive at the "0.0001%" figure? Of what population is that a percentage? I strongly dislike this kind of waving away an important feature request. These days anybody crossing the border of the USA could be asked to unlock their phone. I'd say that's at least a larger percentage of the "population" (whatever population you meant) than "0.0001%".

> I strongly dislike this kind of waiving away an important feature request I could easily say I dislike people making up rediculous corner cases and demanding new technology be designed for it and being deployed. Are there any authorization methods on any kind of mainstream devices that provide that capability? I tend to agree that it’s not actually useful and would be incredible hard to implement, all for a case wh…

Are you saying that I shouldn't be able to snap my fingers three times to call 911? What if I'm handcuffed?

Re: FaceID Security [pdf]

#237

Earlier quoted context omitted.

That's the thing -- the police can't legally compel you to provide them access to your device, but if they can get it without you having to give them anything, by, say, pointing the phone at your face, it's fair game. I don't have time to look up the court precedents about this, but that's my understanding of the current state of the law.

> the police can't legally compel you to provide them access to your device Your understanding of the current state of the law is very wrong. There's a person in the US [0] who has been in jail for multiple years now without being tried / convicted due to refusing to provide access to their devices. There's another case with a warrant[1] allowing an officer to force someone to unlock their phone protected by TouchID.…

I don't think "very wrong" is a fair assesment. Here's a summary of current law (as of 2016) concerning cell phone passwords: https://consumerist.com/2016/05/03/can-law-enforcement-force...

Re: FaceID Security [pdf]

#238
post #233

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

Its more nuanced than you put it with physical keys. Consider for a moment the baklava [1]. A baklava increases anonymity of an attacker (ie. burglar in our discussion), but also increases suspiciousness of victims and 3rd parties (ie. innocent bystanders, witnesses). Physical burglary has many of these nuances, trade-offs. A key on a front door is meant to keep an attacker out for as long as they get caught and/or i…

Note - I think you mean balaclava. Baklava is a delicious Greek dessert.

Re: FaceID Security [pdf]

#240
post #206

Earlier quoted context omitted.

Point a similar device at someone's face. Now you have their facial structure. You can open up their iPhone, desolder the FaceID hardware, and feed the leads captured inputs. Boom, phone unlocked. Even if they have some defense against that, you can just 3D print the person's face in a few hours and be done. Easy to write the data down in a less secure database somewhere, too. This is trivial to do if the person is i…

TouchID can be easily tricked. From december of 2014 at CCC: [1] Its not merely secret service who can do this. Criminals can do it as well. The easy part of it? Your fingerprint is left all over your device. Including likely the one you authenticate with. If its your index finger of your primary hand, its bingo. A fake 2G cell tower costs 250 EUR on the black market. That's also a bad way to use TOTP. However, 15 ye…

> TouchID can be easily tricked. From december of 2014 at CCC: [1]

While I am sure it is not impossible, nobody has been able to provably "trick" the current-generation Touch ID sensor. Only demonstrated on the first revision (found in the iPhone 5s, and possibly the iPhone 6 too).

Post reply on HN