Live data from Hacker News

FaceID Security [pdf]

images.apple.com

311–314 of 314 posts

Re: FaceID Security [pdf]

#311
post #272

Earlier quoted context omitted.

"Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you?" Plenty of phones and cameras have 3D capability. That kind of tech is already being used in cosmetology courses to 3D print a model of your own face and hair for hairstyling practice. It wouldn't be that difficult to make a warm 3D mask to fool the infrared camera and sensor…

But how close do you have to get to use that 3D capability? And is its resolution as good or better than what Apple is using? I mean sure you can knock someone out and use a handheld 3D scanner to get a whole bunch of good shots of them but that’s hardly someone walking down the street and you getting a quick grab of their face. My point isn’t that it’s impossible it’s that it’s not feasible for any normal person or…

"But how close do you have to get to use that 3D capability?"

With a Lytro camera you could do it from just about any distance.

"but that’s hardly someone walking down the street and you getting a quick grab of their face."

All you have to do is even look remotely interested in your phone and pretend you're not taking a picture - boom info gotten surreptitiously. That's assuming the other person you're copying biometrics from is even paying attention - odds are they're probably too focused on their own phone to notice.

Re: FaceID Security [pdf]

#312

Earlier quoted context omitted.

"Can they reasonably steal a full perfect 3D map of your face that can pass the attention checks and whatever FaceID uses to determine its you?" Plenty of phones and cameras have 3D capability. That kind of tech is already being used in cosmetology courses to 3D print a model of your own face and hair for hairstyling practice. It wouldn't be that difficult to make a warm 3D mask to fool the infrared camera and sensor…

I think you are oversimplifying. The IR camera isn’t detecting “warm” (it’s not a FLIR camera), it’s detecting color in the IR range, which is going to be extremely characteristic of a face. In addition, a mask may copy appearance, but it’s not going to copy physical shape in detail. Finally, the channel between the sensor and secure enclave is likely encrypted and/or authenticated, so you can’t just inject any depth…

"it’s detecting color in the IR range,"

A very narrow bandwidth of IR thanks to what we term the "Infrared Window," which is trivially easy to duplicate or fool, as it's one of the same IR bands used for surface mineralogy done via satellite.

I'm really not oversimplifying at all; I am applying knowledge in fields in which I am competent to say "You think it can't be that easy, here's how easy it can really be."

Re: FaceID Security [pdf]

#313
post #305

Earlier quoted context omitted.

With any sort of password or authentication, you can just wait for the person to take out their phone and start using it, and then grab it from them. Not exactly difficult. If you are so concerned about security that you think there is a good chance someone is going to physically attack you to get into your phone, you should just assume someone will get into your phone eventually, and don't keep any sensitive data on…

The problem with phone security nowadays isn't merely the data people have on the phones, its the data people have in the cloud as well with passwords being saved on the device. > If you are so concerned about security that you think there is a good chance someone is going to physically attack you to get into your phone, you should just assume someone will get into your phone eventually, and don't keep any sensitive…

> I don't understand this statistic. Are you arguing 99.9999% of all phones aren't a potential target of being stolen? Are you arguing 99.9999% of all people's data isn't interesting to authorities? You're being overly optimistic about FaceID.

No, I'm saying that, for effectively everyone, there are way easier ways to get into their phone than through FaceID, for example by just taking their phone while they are using it. So for effectively everyone, FaceID will not change their security risk, because there is no motivation for anyone to try and bypass their FaceID when there are easier attack vectors - especially when you are able to disable FaceID the second you feel you are being threatened.

Re: FaceID Security [pdf]

#314

Earlier quoted context omitted.

5-clicks-in-quick-succession primarily activates the "Emergency SOS mode", as well as temporarily disabling TouchID. I think you should edit your post to reflect this.

It’s disabled until you enter your passcode again, correct, which is what you want. I am not sure what you thought I was saying? If you want to disable it permanently, you can do that in Settings, but doing that requires you to unlock the phone, at which point the adversary may take it and have free reign.

What I'm saying is, if someone wants to simply disable TouchID, without also automatically calling the police by whom they are presently being held then the 5 click method is overkill.
Post reply on HN