Live data from Hacker News

FaceID Security [pdf]

images.apple.com

61–70 of 314 posts

Re: FaceID Security [pdf]

#61
post #46
post #12

> To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern. I await some interesting articles featuring IR imaging after the X ships.

How does that counter physical spoofs? If I have the 3D printing technology to pull off a Mission:Impossible quality mask of my target, what good does a random IR projection do?

There was a bit in the keynote where they mentioned those and said they’d done work to prevent them from logging in successfully. They did not elaborate though. Maybe the IR reflectivity of human skin and usual mask material is sufficiently different?

Re: FaceID Security [pdf]

#62

Biometrics are UID's - not passcodes.

Yes, we all know that.

The difference is that they are a user ID which is somewhat difficult to lose, forget, or have stolen. No, it’s not impossible to clone a fingerprint that will fool Touch ID, but it’s not easy either. If we assume that Face ID will be roughly as difficult to fool, then we’ve actually got pretty good security here.

It’s possinle that in some cases a secure passcode would be safer, and it’s great that you still have that option too. But security can only effective in the consumer market if it’s fairly frictionless; I’m unlikely to tolerate entering a long, complex passcode every time I want to use my phone, so I’d probably compromise on something shorter. If Touch/Face ID offers a more secure option, we all win!

Re: FaceID Security [pdf]

#63
post #34
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.

How did you arrive at the "0.0001%" figure? Of what population is that a percentage?

I strongly dislike this kind of waving away an important feature request. These days anybody crossing the border of the USA could be asked to unlock their phone. I'd say that's at least a larger percentage of the "population" (whatever population you meant) than "0.0001%".

Re: FaceID Security [pdf]

#64
post #55

I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…

I think FaceID won't be as good, either, but Apple has surprised me before (with TouchID, no less). The iPhone X definitely seems to be the experimental phone, which I'm glad to see.

I hope they continue the product lines they currently have for the phone: the experimental expensive one, the "normal" and Plus iterative ones, and the not-as-fancy-but-fits-in-my-small-hands one.

Re: FaceID Security [pdf]

#65
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

Huawei phones have this feature, alternate passcode or finger print will enter guest mode, but screen will not show any word Guest. When setting it up, mark folders, apps, things as private, and they will simply disappear from phone. Although the installation folders on SD card will not disappear.

Re: FaceID Security [pdf]

#66
post #55

I'm genuinely interested in knowing how apple can tell that FaceID is better than TouchID - TouchID is already very fast - I can give access to someone else with TouchID without giving my password - It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID - In case of coercion, I still have the possibility to give the wrong fingerprint 9 times before the good one - I have to…

> It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID

Do you really think it's likely that someone will steal your phone and then trick you into looking at your own phone without you realizing it? At that point you might as well be tricked into putting your finger on a TouchID sensor.

Re: FaceID Security [pdf]

#67
They should add some sort of integration for lost/stolen iphones that would allow them record face information of anyone who uses it after the phone has been reported stolen.

Re: FaceID Security [pdf]

#68
post #25

I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…

This sounds like a cool idea, but I don't think it would work in practice.

The would-be thief, assuming he knows about the "duress mode" (which isn't a bold assumption considering the large black market for stolen iPhones), would recognize that you've logged in to something strange, that doesn't show any useful data. They'd just pull back the hammer on their pistol and tell you to try again.

Re: FaceID Security [pdf]

#69
post #56
post #32

Earlier quoted context omitted.

They said in the keynote the chance a random person could unlock your phone with FaceID is 1 in a million.

Can someone help me understand why @gre got down-votes here? I don't get it. As far as I remember, in the big reveal, they did make a point of saying that faceid had a much lower chance of of colliding than the fingerprintid system.

He got downvoted because he said something that didn't match up with what OP said. In the presentation, Apple said

> The probability of a false match is different for twins and siblings that look like you

So that means the 1 in a 1,000,000 chance doesn't make sense here because Apple said the probability is different in regards to twins and siblings that look like you. So @gre just spouted off the statistic when OP was asking what the probability might be in regards to twins and siblings, because Apple says that it is different.

Re: FaceID Security [pdf]

#70
post #56
post #32

Earlier quoted context omitted.

They said in the keynote the chance a random person could unlock your phone with FaceID is 1 in a million.

Can someone help me understand why @gre got down-votes here? I don't get it. As far as I remember, in the big reveal, they did make a point of saying that faceid had a much lower chance of of colliding than the fingerprintid system.

They did, but the quote above was about confusion between twins or siblings. Those are explicitly not random people.
Post reply on HN