Live data from Hacker News

FaceID Security [pdf]

images.apple.com

241–250 of 314 posts

Re: FaceID Security [pdf]

#241
post #209

Earlier quoted context omitted.

It would seem to be extremely difficult for them to compel you to aim them at a fixed point in space.

The police can forcefully draw your blood with a warrant. Maybe they can also forcefully sedate you or fix your head/eyes with some medical device.

I wonder if it works on a dead person in a morgue.

Re: FaceID Security [pdf]

#242
post #163

Earlier quoted context omitted.

The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.

Keys and faces don't really matter. It's a 3-part test. 1. You are a government agent 2. You are on a quest for evidence 3. You are searching in a place where there exists a reasonable expectation of privacy

If all 3 of these are true, you need a warrant (at least in the US). Doesn't matter if the keys, or in this case your face, are right there. The fact that you locked your phone with something the cop doesn't normally have is enough to require a warrant.

Re: FaceID Security [pdf]

#243
post #163

Earlier quoted context omitted.

The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.

In the United States, the Supreme Court does not allow warrantless cell phone searches.

https://en.wikipedia.org/wiki/Riley_v._California

Re: FaceID Security [pdf]

#244
post #135

Earlier quoted context omitted.

In addition to this, don't keep private (and certainly not illegal) data on a compute device that you walk around with. Maybe, just maybe, treat that device as compromised from the start and treat it accordingly. The idea of using them as secure devices should probably stop, at least until they are actually secure. Moreover, if you're committing crimes, maybe don't record them in a way that is recoverable. Not that y…

Why carry a smartphone then? Current tech doesn't allow for regular users to secure their data in this fashion. I mean you'd have to completely log out of something like Dropbox even if you managed to keep your data remote.

There are plenty of uses that don't require you to give them as much trust as people do. I'd never suggest banking on a smartphone, but people do. I'd use a separate email, just for the smartphone. I'd not store medical data on there. I'd not put private data on there.

That doesn't mean they are useless, just that I consider them compromised right out of the box. I treat it accordingly and will recommend others do the same until they are much more secure.

They are great for lots of things. Privacy and security are not among those things.

Re: FaceID Security [pdf]

#245

Earlier quoted context omitted.

https://www.theverge.com/2017/8/17/16161758/ios-11-touch-id-... is how you work around that issue. Keep in mind, you don't need to refuse to TouchID/FaceID forever, just for the timeout (which I do wish was configurable -- I think one hour is reasonable).

Here's the sequence of events: 1. You're walking, with your phone in your pocket. 2. Suddenly, a cop accosts you. You don't have time to react. 3. They detain and restrain you (with handcuffs or otherwise) 4. They pat you down and find your phone 5. They hold up your phone to your face to unlock it I know that people who've never been detained or interacted much with cops think that this is a completely unlikely situ…

Here's the sequence of events:

1. You're walking, with your phone in your pocket.

2. Suddenly, a cop accosts you. You don't have time to react.

3. They detain and restrain you (with handcuffs or otherwise)

4. They pat you down and find your phone

5. They take your hand and place it on the fingerprint sensor.

Ignoring #2 (and the terrible language you used), I don't see how my scenario is significantly more or less likely than yours.

Re: FaceID Security [pdf]

#246

Earlier quoted context omitted.

> And I don't see people complaining about the state of home security... Home security is a really poor analogy. * Attacking everybody's house at once is not scalable, unlike attacking many people's electronic devices at once. Furthermore, defending against a SWAT team armed with a search warrant is nigh impossible, no matter what lock you put on your front door. * The contents of most people's houses is far more wei…

How do you attack everyone’s physical camera at once? Sure you could attack other implementation details of the device remotely and “at once” — but how is that relevant to the faceid use case?

I believe solatic means that once a method to crack Face ID is found, all devices are suddenly at risk.

Re: FaceID Security [pdf]

#247

Earlier quoted context omitted.

How is it a regression? What kind of scenario exists where the cops can force you to FaceID unlock your phone, but not TouchID unlock it? You think they can force you to look at it ("engage" with it) but not touch the phone?

Technically I could see FaceID being marginally more secure in one very specific edge case... If you are asleep. With TouchID, all that is needed is to push their finger to the phone. With FaceID, your eyes would need to be open (theoretically, let's see in practice).

Sure, for some people. I'd be surprised if you could unlock my phone with my hand without waking me up (light stomach sleeper).

Honestly, the easiest attack would just be to ask me about my dogs. 99.99% chance I'll unlock my phone, pull up pictures and show them to you (easy grab) or just hand you the phone and let you browse through them.

Re: FaceID Security [pdf]

#248

Earlier quoted context omitted.

> The solution is to be proactive. If you are going to walk down the street in an at risk area, you hit the power button five times. If you are about to go through a CBP checkpoint, then do the same. You and I have incredibly different experiences of policing and detention if, for you, "be proactive when you're at-risk" is appreciably different from saying "don't use FaceID ever".

Or I guess our detection of risk differs. I have never been detained when I didn't have a "hair on my neck raise" with enough time to disable my phone. If you are in such high risk situations continuously that "be proactive when you're at-risk" is appreciably the same as "don't use FaceID ever", then I say you are doing something very wrong and not just incidentally being stopped for a suspicion of possibly doing som…

Even for long alphanumeric passcodes, a pipe wrench has a 99.99% effectiveness in passcode discovery, given sufficiently bad actors. https://xkcd.com/538/

Re: FaceID Security [pdf]

#249
post #3

>You can always use your passcode instead of Face ID, and it’s still required under the following circumstances: >The device has received a remote lock command. I haven't had an iPhone since the 3Gs - how are these sent? Via cellular data I assume, but is there some app you have to have on your computer?

As others have mentioned, this can be done via iCloud/Find my iPhone, but it can also be done via MDM for enterprise controlled devices as well.

Re: FaceID Security [pdf]

#250
post #193

Earlier quoted context omitted.

There is a way to quickly disable face id, presumably you would do so in most situations when facing police.

There's also a way to break in your house whilst you're gone or asleep. In the former case, if the device is in your house, would you've disabled FaceID? In the latter case, would you've disabled FaceID? Would you've disabled FaceID when you were going outside (with your device) and you'd be busted then? Answer in all these cases: Of course not. So a PIN alone would've been more secure. It'd have cost the government…

That doesn't really make sense. If they take your phone while you're gone or asleep, FaceID is worthless to the attacker anyways because they'd either not be attentive or they wouldn't have your face at all. On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked. Either way, you'd be covered. The only situation where this is actually an issue is where you're being compelled, on the spot, to unlock your phone and you haven't had the time to click the side buttons (which would be very rare since it would just require you to squeeze both sides and you'd have the chance to do that while performing the action of handing your phone over).
Post reply on HN