Live data from Hacker News

FaceID Security [pdf]

images.apple.com

261–270 of 314 posts

Re: FaceID Security [pdf]

#261
post #190

Earlier quoted context omitted.

The problem with biometrics is not username vs password, biometrics are password. The problem is that these are client-side protections, and there's no data sent to a server that can verify the identity. And you can't build a remote identity verification with this data, because there's no way for the user to change it and revoke it (let alone it's very privacy sensitive). The biometric access control systems (the one…

> The problem with biometrics is not username vs password, biometrics are password. Yes, that is the problem. No, biometrics are not password. Please stop spouting this nonsense? Biometrics are akin to username; they suggest your identity, but don't authenticate you. They should not be used as password because they cannot be changed, and cannot be kept secret. A password (or better, TOTP authentication) can be change…

You only read the first sentence and not the rest it seems. I said exactly that, that you can't use biometrics for an identification protocol.

I still disagree on the username. You know my username here and on twitter, you don't know my fingerprint. And no, you can't repro my fingerprint so easily as you think because "fingerprint reader" is a short for a sophisticated piece of hardware that measures other things, e.g. blood pressure.

On the research, I didn't say biometrics can be revoked. I said you can build a function of biometrics info, whose result can be revoked [1]. No one is disagreeing with your premises, but this doesn't mean that the problem has no solutions.

[1] https://scholar.google.com/scholar?hl=en&as_sdt=0,5&q=revoca...

Re: FaceID Security [pdf]

#262

Earlier quoted context omitted.

It's a competitive move; it gives Apple and their users a bragging point, causing competition an expensive countermove. Competition has to move to depth sensor cameras and more on their phones, while Apple is reducing the expense and improving the quality of theirs. The Face ID tech is immature today, but a quarter or three? The quarter after that once support issues have had a few cycles, and the Face ID team has it…

Pardon my ignorance. FR industry? Foreign Relations? First Responder? Flame Resistant? Google was no help. Edit: Oh, do you mean facial recognition?

FR = Farseical Reality :-)

Re: FaceID Security [pdf]

#263

Earlier quoted context omitted.

What about an IR transparent burqa?

FaceID uses a combination of IR and visible light. So, theoretically, if you had a perfectly EMR-transparent burqa, it would not interfere with FaceID. Although an EMR-transparent burqa might not even qualify as a burqa anymore.

Does it use visible light? If it’s supposed to work in total darkness that seems like a problem.

Re: FaceID Security [pdf]

#264
post #251

I'm pretty late to this and I'm sure this will get buried... > Face ID data doesn’t leave your device, and is never backed up to iCloud or anywhere else. Only in the case that you wish to provide Face ID diagnostic data to AppleCare for support will this information be transferred from your device. Enabling Face ID Diagnostics requires a digitally signed authorization from Apple that’s similar to the one used in the…

You have to authenticate this and it wipes your faceid data. It doesn’t allow upload of the current data.

Re: FaceID Security [pdf]

#265
post #258

Earlier quoted context omitted.

In the United States, the Supreme Court does not allow warrantless cell phone searches. https://en.wikipedia.org/wiki/Riley_v._California

The police holds up the phone, pointing towards the suspect: Detective: "Is this yours?" _Suspect glances in the direction indicated, phone unlocks._ Detective: "Nevermind, I got it from here." ----- At least TouchID required physical assault to get you to unlock the phone. FaceID on the other hand can be defeated with perfectly legal attention grabbing techniques.

This doesn't seem to be a valid argument when discussing the police in the United States.

Without a warrant: No information taken from your phone by the police is admissible.

With a warrant: A judge can compel you to unlock any device with a biometric lock, regardless of what sort of biometric lock we are discussing. Fingerprint, iris scan, or face, it simply does not matter.

Re: FaceID Security [pdf]

#266
post #259

Earlier quoted context omitted.

That doesn't really make sense. If they take your phone while you're gone or asleep, FaceID is worthless to the attacker anyways because they'd either not be attentive or they wouldn't have your face at all . On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked. Either way, you'd be covered. The only situation w…

> On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked. You know how and where Ross Anderson was busted? This is peanuts to beat. You bust the target whilst they're on a dinner having a drink, or right after they went asleep. The government knows your current position, and knows when you're asleep. Once this has…

If you have anything on your phone that's valuable / incendiary enough that the government is willing to SWAT you to get at it... don't use goddamn biometrics.

In encryption terms, logging in with biometrics is "vs. kid sister" security, not "vs. major government" security.

Re: FaceID Security [pdf]

#267
post #197
post #117

Earlier quoted context omitted.

But your argument makes no sense. The attack isn't "someone stole the processed image ("stick figure") of my fingerprint", the attack is someone copied my fingerprint .

That’s TouchID. Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you? The fingerprint argument isn’t an argument against FaceID. And it’s still kind of pointless because Apple put out figures a few years ago that TouchID lead to a ~50% INCREASE in locked phones. You seem to be arguing that a secure passcode without biometrics is…

"Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you?"

Plenty of phones and cameras have 3D capability. That kind of tech is already being used in cosmetology courses to 3D print a model of your own face and hair for hairstyling practice. It wouldn't be that difficult to make a warm 3D mask to fool the infrared camera and sensors.

Re: FaceID Security [pdf]

#268
post #63
post #34

Earlier quoted context omitted.

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

How did you arrive at the "0.0001%" figure? Of what population is that a percentage? I strongly dislike this kind of waving away an important feature request. These days anybody crossing the border of the USA could be asked to unlock their phone. I'd say that's at least a larger percentage of the "population" (whatever population you meant) than "0.0001%".

The 0.0001% was obviously a facetious figure. Meant to convey the fact that a duress feature whereby you cross your eyes while using FaceID to "alert the mothership" as OP said, is an extreme corner case.

As another commentor said, you can't expect Apple (or any manufacturer) to build all these extreme corner cases. If you don't want to unlock your phone at the border, put it in your checked luggage or ship it to your hotel/destination.

If you still think that Apple should build something like this because it's important and serves a non zero % of the population... I'd also like Apple to build...

1. FaceID that will tell me when I have something in my teeth

2. FaceID that will tell me when my hair is messy

3. an iPhone that listens to my voice and detect when I might be sick and orders cough syrup

4. an iPhone accelerometer that detects when I am limping and books a physio appointment

5. an iPhone camera that can detect when someone is watching me in the distance

6. an iPhone that will passively listen for gunfire and tell me to seek cover.

See how feature requests can get out of control.

Re: FaceID Security [pdf]

#269
post #246

Earlier quoted context omitted.

How do you attack everyone’s physical camera at once? Sure you could attack other implementation details of the device remotely and “at once” — but how is that relevant to the faceid use case?

I believe solatic means that once a method to crack Face ID is found, all devices are suddenly at risk.

Like the dissemination of knowledge about bump keys fifteen years ago, which put a large number of homes suddenly at risk.

Re: FaceID Security [pdf]

#270
post #234

Earlier quoted context omitted.

Just guessing here, but veins and blood flow are visible in infra red [1]. A color camera can also measure pulse using small color variations. [1] https://software.intel.com/en-us/articles/pulse-detection-wi...

Apple wants this to work in total darkness. So color wouldn’t work. Do we know if they’re projecting IR light (besides the dot pattern) that they could use to look for blood vessels?

Yes. The iPhone X has something literally called the "Flood illuminator" which projects IR light. This is one of the many reasons FaceID is not reactively available to previous iPhones via a software update.

> The flood illuminator produces infrared (IR) light, part of the electromagnetic spectrum that's invisible to the naked eye, to illuminate your face;

https://www.forbes.com/sites/jvchamary/2017/09/16/how-face-i...

Post reply on HN