Earlier quoted context omitted.
Oh sure. Unreleased vapourware beats all attacks.
Isn't this attack "unreleased vaporware"? For example, you have to use FaceID every 4 hours or it requires a passcode. Do you think they were able to hand make an acceptable mask within 4 hours?
Face ID beaten by mask
241–244 of 244 posts
Re: Face ID beaten by mask
#242Re: Face ID beaten by mask
#243Earlier quoted context omitted.
Oh sure. Unreleased vapourware beats all attacks.
Isn't this attack "unreleased vaporware"? For example, you have to use FaceID every 4 hours or it requires a passcode. Do you think they were able to hand make an acceptable mask within 4 hours?
Regarding the four-hour limit, the attacker have to either cheat and start making the mask in advance, or practise making masks quickly. Neither seems impossible. But of course, Apple could (and IMO would) improve the defense. I'm sure Apple would think of ways to counter any publicly known attack.
Re: Face ID beaten by mask
#244Earlier quoted context omitted.
So what is the problem then - they will just have face/fingerprint protection (as they have now) plus useless 0000 pin. And all this optional in settings. No inconvenience at all. Other will have proper bio + password protection that can't abused in most cases.
The problem is you are locked out forever if your biometrics fail. Requiring biometrics AND passcode means both have to succeed, Apple wisely chose to let you use biometrics OR passcode, so you can still get in when biometrics don't or can't work.
PS: I read that some community firmware images allow this mode, the only thing that stops me from using them is lack of camera drivers for unofficial firmware.