Earlier quoted context omitted.
The police holds up the phone, pointing towards the suspect: Detective: "Is this yours?" _Suspect glances in the direction indicated, phone unlocks._ Detective: "Nevermind, I got it from here." ----- At least TouchID required physical assault to get you to unlock the phone. FaceID on the other hand can be defeated with perfectly legal attention grabbing techniques.
This doesn't seem to be a valid argument when discussing the police in the United States. Without a warrant: No information taken from your phone by the police is admissible. With a warrant: A judge can compel you to unlock any device with a biometric lock, regardless of what sort of biometric lock we are discussing. Fingerprint, iris scan, or face, it simply does not matter.
FaceID Security [pdf]
281–290 of 314 posts
Re: FaceID Security [pdf]
#282Earlier quoted context omitted.
> the police can't legally compel you to provide them access to your device Your understanding of the current state of the law is very wrong. There's a person in the US [0] who has been in jail for multiple years now without being tried / convicted due to refusing to provide access to their devices. There's another case with a warrant[1] allowing an officer to force someone to unlock their phone protected by TouchID.…
I don't think "very wrong" is a fair assesment. Here's a summary of current law (as of 2016) concerning cell phone passwords: https://consumerist.com/2016/05/03/can-law-enforcement-force...
That is a very wrong statement. I don’t care if things changed a year or more ago, it doesn’t make it any less wrong now. I of course meant no offense to you, but legal statements which are wrong could easily mislead someone and the emphasis is necessary. Apologies if offense was taken!
Re: FaceID Security [pdf]
#283Earlier quoted context omitted.
Technically I could see FaceID being marginally more secure in one very specific edge case... If you are asleep. With TouchID, all that is needed is to push their finger to the phone. With FaceID, your eyes would need to be open (theoretically, let's see in practice).
Sure, for some people. I'd be surprised if you could unlock my phone with my hand without waking me up (light stomach sleeper). Honestly, the easiest attack would just be to ask me about my dogs. 99.99% chance I'll unlock my phone, pull up pictures and show them to you (easy grab) or just hand you the phone and let you browse through them.
Re: FaceID Security [pdf]
#284I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
> And I don't see people complaining about the state of home security... Home security is a really poor analogy. * Attacking everybody's house at once is not scalable, unlike attacking many people's electronic devices at once. Furthermore, defending against a SWAT team armed with a search warrant is nigh impossible, no matter what lock you put on your front door. * The contents of most people's houses is far more wei…
Except for, you know, family members.
Re: FaceID Security [pdf]
#285Earlier quoted context omitted.
Not to mention incredibly difficult to pull off. It isn't like having two passwords, one distress password and one normal. An algorithm that needs to identify your face in any situation AND detect subtle characteristics? I don't see that being a reality with our current technology. Or at least without significant false positives. Though a two password feature would be nice and easy to implement.
It could be something as simple as having one eye closed when under duress(sorry, monoculars!). It only takes one unlock attempt to then lock it down. Bonus with this is that LE couldn't hold the phone up to your face while you are sleeping to unlock it.
Re: FaceID Security [pdf]
#286Questions: * Does one explicitly set up their FaceID with the option to skip, like how TouchID works currently? I see (when...enabled) verbiage, which is a good sign. * "The probability that a random person in the population could look at your iPhone X and unlock it using Face ID is approximately 1 in 1,000,000 (versus 1 in 50,000 for Touch ID)" If you have a face that causes most people you meet to say "oh, you look…
Re: FaceID Security [pdf]
#287Earlier quoted context omitted.
This doesn't seem to be a valid argument when discussing the police in the United States. Without a warrant: No information taken from your phone by the police is admissible. With a warrant: A judge can compel you to unlock any device with a biometric lock, regardless of what sort of biometric lock we are discussing. Fingerprint, iris scan, or face, it simply does not matter.
Warrants aren’t always required. Also, lack of a warrant just means the direct evidence they gather won’t be admissible, but it might lead them to new evidence. Also, it’s not just the police one needs worry about.
Fruit of the poisonous tree is a legal metaphor in the United States used to describe evidence that is obtained illegally.
For example, if a police officer conducted an unconstitutional search of a home and obtained a key to a train station locker, and evidence of a crime came from the locker, that evidence would most likely be excluded under the fruit of the poisonous tree legal doctrine.
https://en.wikipedia.org/wiki/Fruit_of_the_poisonous_tree
Border agents operate under a different set of rules and have been searching mobile devices without a warrant or even probable cause.
However the ACLU and EFF have filed a new lawsuit challenging this behavior, now that the Supreme Court has ruled that the police cannot conduct warrantless searches of cell phones inside the US.
Re: FaceID Security [pdf]
#288Earlier quoted context omitted.
I believe the probability for identical twins is 1 in 1; they mentioned in the keynote that some people will have to stick with passcodes, including those with "evil twins". (Presumably if you trust your identical twin to not be evil, you don't care if they're able to unlock your phone.)
Identical twins aren't identical down to every last detail. What I'm curious about is if Face ID can pick up on any details that are different that humans wouldn't notice. Also regarding the "evil twin" thing, evil twins came from another dimension so, aside from the goatee, they really were literally identical down to every last detail. It's unclear to me if that joke was meant as "your identical twin will be able t…
Re: FaceID Security [pdf]
#289Earlier quoted context omitted.
The police holds up the phone, pointing towards the suspect: Detective: "Is this yours?" _Suspect glances in the direction indicated, phone unlocks._ Detective: "Nevermind, I got it from here." ----- At least TouchID required physical assault to get you to unlock the phone. FaceID on the other hand can be defeated with perfectly legal attention grabbing techniques.
This doesn't seem to be a valid argument when discussing the police in the United States. Without a warrant: No information taken from your phone by the police is admissible. With a warrant: A judge can compel you to unlock any device with a biometric lock, regardless of what sort of biometric lock we are discussing. Fingerprint, iris scan, or face, it simply does not matter.
Doesn't (or can't) law enforcement also use parallel construction (based on information obtained without a warrant)? I believe the point about what's admissible is not as clear cut as you state in a single sentence.
Re: FaceID Security [pdf]
#290> Many (most?) people have more private information on their phones than they do in their house
But I can‘t think of any in my situation. Regarding data, almost all is available on my PC and tablet as well, both staying at home most of the time and with security features that can be bypassed with enough time/effort. Moreover, photos, handwritten notes, purchase receipts, bills, love letters and so on are all at my home or accessible through my home, but not necessarily stored on my phone. Digital traces about my communications and travel are available through numerous service providers (mail, cell, isp) ... no need to break into my phone, either.
So, what is the private data only available on everyone’s phones but not in their homes? Unsynced, not backuped private notes and photos never shared with anyone else? Am I missing something (honest question)?