5 ms·
I'm not saying 1 in 1,000,000 is great, but I don't see how the birthday paradox applies. Assume that I want to analyse whether face unlock is secure enough for
by codeflo 9y ago
I'm not saying 1 in 1,000,000 is great, but I don't see how the birthday paradox applies. Assume that I want to analyse whether face unlock is secure enough for me -- why is the chance that anyone else's phone gets unlocked by someone else's face even relevant?
- arkades 9y agoBecause if you're an actor with a lot of faces (eg, state level actor with a face db) to feed it, and you're sweeping large numbers of phones rather than trying to hit one in particular, this suggests they'd have an easier time than it sounds like when you're considering it in the private use context.
- LeifCarrotson 9y agoI think it can be assumed that the facial recognition is rate-limited, just like PIN entries. Even if you had a million phones and a million faces in your database, you could only try perhaps 30 faces on each phone.
- linuxps2 9y agoIf you know generally what the owner looks like, I imagine you could cut down your data set significantly before using it to bruteforce a phone
- ubernostrum 9y agoIf you have the kind of surveillance tech people are postulating here, you already have a high-res-enough scan of the actual face of the person you target in order to produce something to unlock their phone.
- djrogers 9y agoNot likely - they used professional hollywood mask makers to test against... Remember, this is infrared with a 30k dot projector - the most accurate 3d visual record you could make would appear to be insufficient.
- DonHopkins 9y agoYou mean like Peter Sellers? http://cinetropolis.net/the-many-faces-of-peter-sellers-part-1/ http://cinetropolis.net/the-many-faces-of-peter-sellers-part...
- DigitalJack 9y agoThey'd have to be 3d faces. Not impossible. Maybe flexible displays will finally take off to facilitate hacking these things.