Live data from Hacker News

FaceID Security [pdf]

images.apple.com

301–310 of 314 posts

Re: FaceID Security [pdf]

#301

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

The problem with biometrics is not username vs password, biometrics are password. The problem is that these are client-side protections, and there's no data sent to a server that can verify the identity. And you can't build a remote identity verification with this data, because there's no way for the user to change it and revoke it (let alone it's very privacy sensitive). The biometric access control systems (the one…

> biometrics are password

Tell that to virtually all the governments around the world, who are now building databases of everyone's fingerprints, from "needing them" for passports to national IDs.

Also that is the problem, because those biometric signatures can be hacked. It's way harder to hack into 1 billion devices to steal everyone's biometric signature. That is a feature not a problem.

Re: FaceID Security [pdf]

#302
post #163

Earlier quoted context omitted.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.

Searching through your phone seems like an action that would require a warrant.

Requiring a warrant seems like an action many cops could not care less about nevertheless.

For one, there are tons of loopholes, from border searches to "evidence of criminal activity" (dead easy to "prove" for a black/latino/poor person and have the court agree), and unless you can afford a good lawyer, good luck trying to prove your rights were violated:

https://en.wikipedia.org/wiki/Warrantless_searches_in_the_Un...

http://www.npr.org/2011/05/16/136368744/in-warrantless-searc...

Not to mention that warrants are not that difficult to obtain either -- except in the movies.

Re: FaceID Security [pdf]

#303
post #246

Earlier quoted context omitted.

I believe solatic means that once a method to crack Face ID is found, all devices are suddenly at risk.

Like the dissemination of knowledge about bump keys fifteen years ago, which put a large number of homes suddenly at risk.

Indeed. However it seems likely to me that an attack could be resolved with a software update as the decision to unlock is performed entirely by software (as far as I can tell).

It's a bit harder to upgrade your front door lock in this way.

Re: FaceID Security [pdf]

#304
post #231

Earlier quoted context omitted.

>Actually, no. When you first power on an iPhone, you need the passphrase, not the FaceID. So swapping hardware does you no good unless you also have the passphrase/passcode. You don't need to shut off the phone to get into the hardware. >What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "tri…

> You don't need to shut off the phone to get into the hardware. Do you mean row hammer [1] or cold boot attack [2]? [1] https://en.wikipedia.org/wiki/Row_hammer [2] https://en.wikipedia.org/wiki/Cold_boot_attack

Uh, neither? I don't think you understand the problem.

Re: FaceID Security [pdf]

#305
post #259

Earlier quoted context omitted.

> On top of that, FaceID disables itself and requires a passcode after 4 hours of no detection or 48 hours of continuous time that the phone hasn't been unlocked. You know how and where Ross Anderson was busted? This is peanuts to beat. You bust the target whilst they're on a dinner having a drink, or right after they went asleep. The government knows your current position, and knows when you're asleep. Once this has…

With any sort of password or authentication, you can just wait for the person to take out their phone and start using it, and then grab it from them. Not exactly difficult. If you are so concerned about security that you think there is a good chance someone is going to physically attack you to get into your phone, you should just assume someone will get into your phone eventually, and don't keep any sensitive data on…

The problem with phone security nowadays isn't merely the data people have on the phones, its the data people have in the cloud as well with passwords being saved on the device.

> If you are so concerned about security that you think there is a good chance someone is going to physically attack you to get into your phone, you should just assume someone will get into your phone eventually, and don't keep any sensitive data on it. For the other 99.9999% of the population, face id is good enough.

I don't understand this statistic. Are you arguing 99.9999% of all phones aren't a potential target of being stolen? Are you arguing 99.9999% of all people's data isn't interesting to authorities? You're being overly optimistic about FaceID.

Re: FaceID Security [pdf]

#306
post #285

Earlier quoted context omitted.

It could be something as simple as having one eye closed when under duress(sorry, monoculars!). It only takes one unlock attempt to then lock it down. Bonus with this is that LE couldn't hold the phone up to your face while you are sleeping to unlock it.

Why wouldn't you just make it via a separate password... simply force your device into password unlock mode (no faceID/touchID). enter the duress password.

I thought the point of a duress password was to be covert. Plus, someone can still force the real unlock just by holding the phone to your face. I'm still under the impression that you'd need the face to be a username and two passwords.

Re: FaceID Security [pdf]

#307
post #281

Earlier quoted context omitted.

Warrants aren’t always required. Also, lack of a warrant just means the direct evidence they gather won’t be admissible, but it might lead them to new evidence. Also, it’s not just the police one needs worry about.

Even if an illegal search of your phone led to new evidence, in the US that new evidence would fall under a legal doctrine known as "fruit of a poisonous tree". Fruit of the poisonous tree is a legal metaphor in the United States used to describe evidence that is obtained illegally. For example, if a police officer conducted an unconstitutional search of a home and obtained a key to a train station locker, and eviden…

“Parallel construction”

Re: FaceID Security [pdf]

#309
post #161

Earlier quoted context omitted.

> And I don't see people complaining about the state of home security... Home security is a really poor analogy. * Attacking everybody's house at once is not scalable, unlike attacking many people's electronic devices at once. Furthermore, defending against a SWAT team armed with a search warrant is nigh impossible, no matter what lock you put on your front door. * The contents of most people's houses is far more wei…

The analogy is one of defense in depth: if you're serious about security, you can use memorized & typed secondary passwords on secure apps, such as secure notes in 1Password, or an app like https://guardianproject.info/apps/pixelknot/ that would steganographically encode secure notes into otherwise normal photos, potentially with independent passwords for complete deniability. A locked door and a face-locked iPhone a…

I am not a huge fan of Steganography in images. There are far too many services out there which take the liberty of modifying or re-encoding your images to a different format for various reasons.

Is there a lossless medium which can be used for steganography?

Re: FaceID Security [pdf]

#310
post #161

Earlier quoted context omitted.

The analogy is one of defense in depth: if you're serious about security, you can use memorized & typed secondary passwords on secure apps, such as secure notes in 1Password, or an app like https://guardianproject.info/apps/pixelknot/ that would steganographically encode secure notes into otherwise normal photos, potentially with independent passwords for complete deniability. A locked door and a face-locked iPhone a…

I am not a huge fan of Steganography in images. There are far too many services out there which take the liberty of modifying or re-encoding your images to a different format for various reasons. Is there a lossless medium which can be used for steganography?

If it's lossless, then where do you hide the message? In "comment" sections? Not very well hidden.

How many formats are there where you can intentionally encode something with meaningless characters?

Post reply on HN