11 ms·
Face ID beaten by mask
- jgrahamc 9y agoVideo of this working: https://www.youtube.com/watch?v=i4YQRLQVixM https://www.youtube.com/watch?v=i4YQRLQVixM
- deleted 9y ago[deleted]
- gabrielgoh 9y agoi enjoyed the presentation, he has a flair for the dramatic.
- WA 9y agoThe 1st point is, everything went much more easily than you expect. You can try it out with your own iPhone X, the phone shall recognize you even when you cover a half of your face. It means the recognition mechanism is not as strict as you think, Apple seems to rely too much on Face ID's AI. We just need a half face to create the mask. It was even simpler than we ourselves had thought. Interesting. I expected this to be some quite obscure technique.
- cdubzzz 9y ago> We used a popular 3D printer. Nose was made by a handmade artist. We use 2D printing for other parts (similar to how we tricked Face Recognition 9 years ago). The skin was also hand-made to trick Apple's AI. That seems reasonably obscure (:
- mtgx 9y agoThere was also a rumor that Apple was having trouble with FaceID recognizing people (it even happened to Craig Federighi on stage!), and they made the security less strict so it recognizes people more easily. For all we know, FaceID doens't have that "1 in a million" False Acceptance Rate" anymore, but only 100,000 which would be a lot closer to a fingerprint.
- mikeash 9y agoWhat happened to Craig was that he tried to unlock a freshly rebooted phone. iOS requires the user’s passcode after booting, and won’t allow a biometric unlock until after that.
- macintux 9y agoNo, it was actually the people setting up the stage accidentally triggered Face ID often enough that it fell back to passcode. Could find a link to Apple's explanation if needed.
- mikeash 9y agoThanks, you're right. It looks like it was initially reported as having been rebooted like I said, but Apple later on explained it as you say, and I must have missed the update. Here's a link: https://9to5mac.com/2017/09/13/face-id-demo-fail-details/ https://9to5mac.com/2017/09/13/face-id-demo-fail-details/ Anyway, the key point here is that Face ID didn't fail to recognize Craig, it refused to recognize him because it had already been locked.
- baxtr 9y ago> A: We used a popular 3D printer. Nose was made by a handmade artist. We use 2D printing for other parts (similar to how we tricked Face Recognition 9 years ago). The skin was also hand-made to trick Apple's AI. > Q: What's the approximate cost of the mask? > A: ~ 150 USD Taken together, the second answer cannot be true. Only if the cost stated is related to material cost only, which is is only one input factor to assess the total cost of this approach
- geoah 9y agoI assume this was done in Singapore where prices should be a bit cheaper, if you don't have a 3D printer you can always get a service for the 50 USD, and probably give the rest to an art student to make you the nose? :D Not sure about the "hand-made" skin, but it might just be some white and glossy paint?
- staz 9y agoThis seems to be a Vietnamese firm actually
- x0x0 9y agoNitpicking the cost of the labor to build this mask misses the point of the article: face id is much less secure than Apple claims.
- delinka 9y agoWhat claims have they made? That it can’t be fooled by masks? No. That one in a million other faces can open your phone. That’s still fewer people than could open you phone with Touch ID. At no time that I’m aware have Apple claimed resilience against masks or gelatin fingers.
- Tepix 9y agoYes, Apple claimed that it can't be fooled by masks. The article even has the picture from the slide of the presentation. Did you read it?
- syshum 9y agoBiometrics are usernames not passwords. Biometrics should never be used on the sole authentication method they should only be used in conjunction with something else.
- nobodyshere 9y agoThey realize that at Apple too. Face/Touch ID can be forcefully disabled for enterprise. However for an average Joe this is not a threat.
- tormeh 9y agoCan you require both face and password?
- nobodyshere 9y agoNo. As far as I know, there is no such device on the market. You can disable Face ID, but can't force it in combination with passcode, for example. Android allows you basically the same approach: any of the currently enabled methods. It is awkward though that there is no option to have that sort of 2FA for mobile devices, where at least two methods would be required, or strictly specified ones.
- valuearb 9y agoThat would be an extremely bad idea. In that scenario, imagine FaceID fails to recognize you, now you can't get into your device. Currently if FaceID fails, you have passcode as an alternative way into the device.
- nobodyshere 9y agoAlthough fingerprint AND face/iris scan would probably add more confidence, with passcode as a reserve option.
- adamlett 9y agoBiometrics are usernames not passwords That such a meaningless slogan. Passwords and biometrics have different pros and cons, but they are the same in that they increase security. Biometrics should never be used on the sole authentication method * Biometrics is always better than no security. * Biometrics done well is certainly better than a 4-digit PIN. * Biometrics on an iDevice is in fact always used with something else, which is device itself: Touch/FaceID on an iPhone can only be used to access that particular iPhone. Ie. if you manage to steal my fingerprint, you can only use it to access the devices that I have set up to use my fingerprint. This means that my fingerprint alone is not of any value, unless you can also gain physical access to my phone. Compare this with a password which, if stolen, allows attackers on the other side of the globe to access to my accounts.
- thoughtsimple 9y agoNevermind. Should have read the article. I thought it was the same as the one I saw over the weekend.
- steve19 9y agoEdit: the op asked if this could be done with the user knowing (I don't know why the question was removed). "We might use smartphones with 3D scanning capabilities (like Sony XZ1); or set up a room with a 3D scanner, a few seconds is enough for the scanning (here's an example of a 3D scanning booth). An easier way is photograph-based, artists craft a thing from its photos. Take the nose of our mask for example, its creation is not complicated at all. "
- thoughtsimple 9y agoI tried to delete it but you were too quick to answer so deletion was blocked. The question was clearly answered in the article.
- vultour 9y agoWonder if this would work have Apple not relaxed their FaceID sensor requirements to ship the phones more quickly.
- sambeau 9y agoWhile I recall this rumour I thought it was widely discredited. Was there any actual evidence of this?
- valuearb 9y agoApple denies they ever relaxed any sensor requirements. Attacks will always be possible because FaceID can never be infinitely precise. Your face changes over time, even during the day. People wear glasses or sunglasses sometimes, and take them off sometimes. They grow facial hair, and shave it off. They wear makeup, and take it off. They pick up black eyes in jui-jitsu class. There is a balance between maximum precision and maximum usability. Apple's task was to find that balance. This hacked up "exploit" does nothing but show they found the proper balance.
- sambeau 9y agoAs a consumer this doesn't worry me as to be able to crack my phone it looks like they would already have to have access to my face to make the mask (and an expert sculpture to make a nose). If they could demonstrate it working from a 3D printed mask taken from a surreptitious scan at distance in the outdoors then I think we'd have reason to be worried. For spies, spooks, government agents etc. I suspect that Face ID would always be a no-no as it is much harder to control the ability of others to eavesdrop.
- jonwinstanley 9y agoExactly. This is definitely not a reason not to buy an iPhone X.
- nvr219 9y agoyeah this is mostly like, multinational CEOs, etc who would be targeted
- azinman2 9y agoAnd they shouldn’t rely on consumer-level security protection.
- Spivak 9y agoYou say that like they don't all use commodity phones and laptops. The idea that people are buying super secure hardware for CEOs is firmly in the realm of screenplays.
- azinman2 9y agoI didn’t say they shouldn’t use an iPhone, I said they shouldn’t use consumer level security features. All leading smartphones have enterprise features that change the security profile — for example to use long alphanumeric passwords instead of a PIN or FaceID.
- Arnt 9y ago
- KeitIG 9y agoSo, fingerprints are not "secure", face recognition is not "secure"... Are passwords/double authentication the only way to keep things private and secure these days? Are there any serious alternative?
- jbg_ 9y agoA fingerprint is just a really complex password that you leave on everything you touch. Your face is just a really complex password that is written on the front of your head. It should be self-evident that neither of these is "secure" for some level of "security", but they might be perfectly fine for the level of threat that you face, which is not likely to be particularly high. But I don't know you, so maybe you face a higher-than-average level of threat, in which case, yes, a sufficiently long password/passphrase that you memorise is probably the best option for your mobile device.
- contras1970 9y agofingerprints and faces are just really complex usernames: they're not secret at all.
- valuearb 9y agoYour biometric measurements are essentially secrets. They work today because it's far too difficult for a thief to steal your device AND copy your biometrics at the same time. This makes them the most secure tokens we have in real world use, given the number of people with 0000 passcodes. Eventually they may become easy to copy, then their utility as secrets will be gone.
- tzahola 9y agoThe solution is obvious: genital scanners! https://www.youtube.com/watch?v=0zu4XlM_89s https://www.youtube.com/watch?v=0zu4XlM_89s
- timthelion 9y agoAdvanced fingerprint recognition devices recognize things that are not left on things that you touch. They look under the skin at blood vessel and measure body capacitance and other statistics. That's why there is the weird light on the "biometrics" device in the airport, to be able to see through the outer layers of skin. https://en.wikipedia.org/wiki/Finger_vein_recognition https://en.wikipedia.org/wiki/Finger_vein_recognition
- thisisit 9y agoI re-read the whole thing but cannot find what special processing is all about. Is it molding using clay or something?
- draugadrotten 9y agoThe special processing is done to large areas of skin, so I would say that it is makeup powder to make the plastic have IR reflective properties of real skin.
- nezza-_- 9y agoI feel like this demo is not really good. A video where a (real) face is learned in and then the mask is used to unlock would be good, this could just show that the mask is learned into FaceID.
- davweb 9y agoIt's conspicuous that the real face of the user of the iPhone isn't shown in the video or in photos on the site.
- Reason077 9y agoIn the video, he shows the iPhone being unlocked with his own face at 1:06: https://m.youtube.com/watch?v=i4YQRLQVixM https://m.youtube.com/watch?v=i4YQRLQVixM
- deleted 9y ago[deleted]
- schappim 9y agoThey're an "Interesting" company... I'm not sure the authenticity of this story. The authors of the hack claim to be: "the leading firm in network security, software, smartphone manufacturing (Bkav.com/Bphone) and smarthome"[sic] and one of their products is a "gold plated SmartHome for super luxury villas". I wonder if it will work is ordinary luxury villas...
- tuananh 9y agotheir bphone is just an overpriced android phone. they even goes as far as re-branded chrome to be bchrome. probably without google's permission as well as installing market and google default apps.
- Udik 9y agoWould it be possible to just capture the IR beams with a camera, and use a projector to send to the phone's sensor a new set of IR points as they would appear if they were projected on an actual 3D model? This would allow to use only a digital model of a face, without the need for printing it.
- nobodyshere 9y agoYou'd need a very precise IR projector. That's likely very far away from a DIY home made solution in terms of costs.
- zionic 9y agoFaceID resists this by using a random dot pattern. If the pattern it gets back doesn't match what it sends you get a lockout.
- valparaiso 9y ago<here was a misleading comment>
- x3ro 9y agoHe does no such thing. The passcode is never entered in front of the mask. They also explicitly state in their Q&A that the passcode was never entered in front of the mask.
- timthelion 9y agoI don't see any suggestion that this is what they did in the demonstration. In fact, quite the opposite is suggested: "Q: Were you able to use the mask to unlock the iPhone immediately after freshly enrolling the real face? The reason I ask is that, according to Apple's whitepaper, Face ID will take additional captures over time and augment its enrolled Face ID data with the newly calculated mathematical representation. Can you describe precisely how you went about conducting this experiment? A: It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask."
- discordance 9y agoI hope this does not result in me getting 3D face scanned as I pass through border control
- y7 9y agoI think the "self-service" passport gates in the EU already do this.
- threeseed 9y agoActually quite a few countries already do this e.g. Australia. Although I am not sure if it's based on your head or just scanning your iris.
- Cthulhu_ 9y agoWell that was already the case for fingerprints, so, nothing new there. Matter of time before a 3D representation of your face becomes mandatory in biometric IDs / passports too.
- positivecomment 9y ago> Because... we are the leading cyber security firm ;) But you don't even use HTTPS. Why?
- amelius 9y agoBecause the information was meant to be public anyway?
- kbart 9y agoTheir "download" page is also HTTP which is a bit more concerning. Pretty sloppy for a company that provides security tools imho.
- positivecomment 9y agoThis is the infamous "nothing to hide" argument in a different form.
- borplk 9y agoThere are countless other benefits to having HTTPS (such as ensuring the end-to-end integrity of the communication so stuff can't be injected in the document). It's not meant only for private information.
- syncsynchalt 9y agoNot using https means that your ISP, your mobile carrier, or your airport network provider can modify the information being presented to you. This is not a hypothetical, it happens all the time (though usually just to inject ads). It's not about whether the provider wants the information to be public, it's about whether the provider wants the information to arrive intact.
- LoSboccacc 9y agowell, we only need a process to rotate faces now every month and a minimum complexity check because faces with only one nose are clearly not secure enough
- return0 9y agofinally a useful application for 3d printers
- Yizahi 9y agoI wish both companies would allow us to have both PIN/PASS + biometric together and not strictly separately as it is now. At least as an option.
- Cthulhu_ 9y agoIt would make a lot of sense for the new iphone actually, since with the PIN you're usually already looking at the screen.
- ploggingdev 9y agoI was hoping they released more details about the process. One possible method is that they trained the iphone's Face ID on the mask by repeatedly failing to unlock it with the mask and then entering the passcode which trains the iphone's neural net on the new face (mask in this case). There was a video a few days ago where the iphone X was unlocked by a man's brother by doing this : https://9to5mac.com/2017/11/04/face-id-siblings-fail/ https://9to5mac.com/2017/11/04/face-id-siblings-fail/ . This was posted 2 days ago, any statement from apple on this story?
- JosephRedfern 9y agoThey address this in their second point: > It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.
- jclardy 9y agoYes, they addressed it, but why not demonstrate it if it was actually true? As in register on camera then point it at the mask. My guess would be because it doesn't actually work.
- b3lvedere 9y ago"the phone shall recognize you even when you cover a half of your face". I wonder what half and why this works.
- yoz-y 9y agoProbably because of clothes such as hats and scarves.
- m_st 9y agoI would really appreciate an option for 2FA: Require both a PIN and Touch ID / Face ID to unlock the phone. With long passphrase to disable this again.
- dmitriid 9y agoI’d love to see more details. When TouchID was hacked, it caused a minor sensation. When details of the hack emerged, it turned out to be not a sensation at all, but a process that can hardly be replicated by real criminals.
- dolguldur 9y agoOne thing that’s usually missed is that passcodes aren’t that secure if you unlock your phone with strangers around or if there are surveillance cameras filming you.
- mikeash 9y agoI wish they’d tone it down a little. This is really interesting, but stuff like this makes it hard to take them seriously: “Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven't carried out scientific and serious estimation before deciding to replace Touch ID with Face ID.” I’m amy case, this doesn’t worry me personally too much. I don’t expect biometrics to be more secure than a password, just reasonably secure and more convenient. Before Touch ID, my passcode was 0000 with a four-hour lock timeout. I only had it set because some apps reduced functionality if no passcode was set. Real world security for me increased a lot with biometrics. As for fingerprints versus facial recognition, the article claims fingerprints are better, but I’m skeptical. For one thing, my phone is covered in my own fingerprints, so getting something to copy is a lot easier.
- gilleain 9y ago> As for fingerprints versus facial recognition, the article claims fingerprints are better, but I’m skeptical. For one thing, my phone is covered in my own fingerprints, so getting something to copy is a lot easier. Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? I'm only half-serious, but it might make lifting the real prints harder... (maybe it is trivial to distinguish prints made on a surface from those in the structure of the surface)
- coldtea 9y ago>Would it be possible to have a really secure phone that had fake fingerprints added to the material of the surface of the phone? Because we don't touch 20000 other objects every day from where someone can pick our fingertips from?
- GrinningFool 9y ago_>Because we don't touch 20000 other objects every day from where someone can pick our fingertips from?_ We're less likely to lose one of those objects at the same place and time we leave our phone somewhere. It's comparable to leaving your keys in your car. Sure, someone could find those keys where you lost them and then find your car - but is sure is easier for them when they're both in the same place.
- dep_b 9y agoCan sombebody explain this: "A: It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask." Does it mean passcode was completely off and the phone would not lock itself after a few failed attempts? Because there's a difference between trying until it works and getting a mask within 24 hours that does not fail three times.
- ComodoHacker 9y agoThey don't answer directly and clearly to almost every question, or simply evade them like this first one. Weird, especially considering they've written both questions and answers.
- noitsnot 9y agoIt most definitely matters. I have read Face ID tries to learn more about your face if you unlock it with the passcode after having issues unlocking with your face. What are the chances it learned the mask?
- dep_b 9y agoThat's a super interesting thought. Face ID is a bit of a black box. Though I'm not trying to defend it to death, I can imagine it's better than all of the face scanners before it but far from super secure.
- sangnoir 9y ago> It does not matter whether Apple Face ID "learns" new images of the face, since it will not affect the truth that Apple Face ID is not an effective security measure. They are saying the question is moot. > However, we knew about this "learning" but they are going to answer the question regardless > thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask. They ensured that the mask didn't get integrated into Apple's learning data by never entering the pin. The understanding is that whenever a failed face scan is followed by a correct pin, the face scan is added to learning data (since the assumption is it belongs to the legit user).
- yoz-y 9y agoThe one answer that is missing from this QA is how many tries they had before it worked. Did they configure Face Id, made the mask and then it worked immediately? Did they tinker with the mask until it worked? From the way this is written I suppose the latter. Nevertheless, I thought Apple was detecting small movements in eyes to ensure that the subject in front is actually a living human. I don't know where I got this from, but now I am disappointed.
- Anechoic 9y ago*I thought Apple was detecting small movements in eyes to ensure that the subject in front is actually a living human Face ID does track eye movement ("require attention"), but you can turn off that setting. I haven't found any information as to whether the firm disabled the eye tracking for this crack.
- oliwarner 9y agoWhy not layer on more data? Like a facial gesture (smile, wink, tongue out, etc) and a fingerprint? Both using thermal readings as "proof". Given you're almost always using your face and hands, this isn't much of an inconvenience but it's powers more secure. All for pennies (in comparison to a $1k device). It's infuriating that each time a mass-produced biometric scanner comes out, it's hogtied by the fact this cheap technology isn't quite good enough yet.
- iamsaul 9y agoThis type of 'layering' could be done with other devices in the eco-system, too. The Apple Watch for (a crude) example: > Does this person have an Apple Watch? Is the device in range? Is it unlocked? Do the wearer's biometrics match? Most individuals have (for better or worse) bought into the (relatively) closed system of Apple products – why not continue leveraging that to their advantage?
- seanwilson 9y agoOnce someone is at the stage where they're going to 3D scan you, create a replica of your face and steal your phone to get into it...why wouldn't they just coerce you into unlocking your phone with force? See https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
- z3t4 9y agoWhat stops someone from taking the phone and "flash" it to your face, having the phone unlocked before you understand what's going on. Or do you have to hold the phone to the face while typing the password ?
- hamandcheese 9y agoThe same thing that stops someone from jumping you and forcing you to unlock with Touch ID.
- ataturk 9y agoWhen I saw the headline I said: "Of course wearing a mask would defeat it!" But I was thinking of facial recognition as the invasive technology being used by governments to further destroy what's left of our privacy in public (an oxymoron, I guess). I think about all those '80s sci fi movies where the urchins and street hackers all had makeup lines on their faces which I thought was just the costume makers being "edgy" but it turns out it had a backstory--people were attempting to disrupt face scanners. How did they know this in the 1980s?
- djrogers 9y agoI’d really like to see more details about how this was done, and less of the over-the-top rhetoric. Claims such as “we are the leading cyber security firm” and “we understand apple’s AI and how to beat it” do not make you look more competent, just more boastful.
- eric_h 9y agoYes, the whole tone (and lack of specificity) of the article does not add to its credibility.
- pasta 9y agoTroy Hunt already posted about this [1]. I think this quote is fitting: "More than anything though, we need to remember that Face ID introduces another security model with its own upsides and downsides on both security and usability. It's not "less secure than a PIN", it's differently secure and the trick now is in individuals choosing the auth model that's right for them." [1] https://www.troyhunt.com/face-id-touch-id-pins-no-id-and-pragmatic-security/ https://www.troyhunt.com/face-id-touch-id-pins-no-id-and-pra...
- scribu 9y agoFrom Troy Hunt's article: > given the processing power to actually observe and interpret eye movements in the split second within which you expect this to work, this would be a really neat failsafe. Apple highlights this as "attention awareness" Yes, it would be a great failsafe. However, if the PoC demonstrated by Bkav is legit, it would seem that Face ID doesn't look for eye movement; it just checks if the eyes are oriented toward the device. That said, I agree that regular people probably don't need to worry about any of this.
- jkubicek 9y agoYou can also turn attention awareness off. They didn’t specifically mention whether they turned it off or left it on.
- dkonofalski 9y agoAccording to tweets from Wired, the attention features were disabled when they initially observed the test. There were also questions that they asked that the Bkav team refused to answer.
- azinman2 9y agoOr maybe it does check, but the mask puts it in some kind of error recovery mode.
- cletus 9y agoI'm actually going to be very interested to hear how FaceID works for the average user. False positive is one issue and one Apple lauded as being lower than TouchID. What about the false negative rate however? This is what will actually aggravate users. As a user I like touch unlock. I can do it without looking at the phone, having the phone gave me, in the dark, wearing sunglasses and so on. To me face recognition just seems like a huge step backwards. I'd love to be proven wrong.
- jrowley 9y agoI have a friend with an X who just bought a new pair of ray bands because her last pair wouldn’t work with FaceID. Pretty bizarre but understandable.
- abritinthebay 9y agoOnly negative results I’ve had were due to either proximity (it can’t see my face properly- too far away or too close) or obfuscation (lying on pillow which obscures too much of my face) Overall it’s much smoother and non-intrusive than TouchID I’ve never needed to unlock my phone in a situation where I’m not about to look at it so I’m not sure what use case you’re running into there. As for in the dark: it automatically scans when you swipe up, so no issue. Don’t think of it as “using Face ID” think of it as “swipe up to unlock phone”. The Face ID is just an implementation detail.
- magoon 9y agoIf somebody is going to try this hard to get through my Face ID, I’m enough of a high level target that I’m not relying on a shortcut unlock feature of a consumer cell phone. And I’ve likely got bigger problems.
- dabei 9y agoIf you are that high level then your family and close associates are all targets. Same goes their family and network...
- luxuryballs 9y agoCool that they took the time to explore the limits of it, but FaceID is about convenience with security, not maximum security. Having physical access to the phone is still required, which is a pretty big obstacle for this kind of attack. There is also a quick button squeeze you can do that requires passcode for the next unlock, so you can do that before you go to bed if you're really afraid someone is going to gain physical access to your device.
- runeks 9y agoIsn’t it strange that a room-temperature face can unlock the phone when Apple has made it clear that the iPhone X uses the temperature of the face to detect masks etc.? From the perspective of the IR camera, the mask and that guy’s face should look completely different. This attack makes it look like it’s not using this information at all.
- rsl7 9y agowell.. if you have already advanced to the point where you're making a mask, I imagine it wouldn't be too hard to heat it up a bit.
- mathgaron 9y agoThe IR camera is near-infrared, it measures more or less light that your eyes can't see, and no heat frequencies. The IR camera is used to recover 3D information: https://en.wikipedia.org/wiki/Structured-light_3D_scanner https://en.wikipedia.org/wiki/Structured-light_3D_scanner
- fao_ 9y agoMost of these answers basically say nothing. e.g. """Q: How did Bkav develop the mask (for example why you use silicone for the nose, why 3D printing for some areas while special processing for others, etc.)? A: You are right. Many people in the world have tried different kinds of masks but all failed. It is because we understand how AI of Face ID works and how to bypass it. As stated above, we were the first in the world to show that face recognition was not an effective security measure for laptops.""" is a really nice way to dodge the question of why they used silicone for some parts of the mask.
- S_A_P 9y agoSo Ive been thinking about biometrics and phone security a bit, and it seems to me there is a pretty easy way to tell how secure your phone needs to be on an X/Y chart where Y= Security needed and X = Data sensitivity/Personal-ness. Id say the ideal plot would follow an exponential curve, and seems that if you didn't keep a lot of personal data on your phone and all your social, financial and mail accounts can be reset quickly via the web, you don't need much security provided you maintain custody of your device. That said, Im glad that any claims as to the security of biometrics are not just taken at apple's/samsung's/google's word. I remember the iPhoneX event stated that there was a exponentially smaller chance that someone else's face could unlock your phone, and that masks "wont work". I could also be mis-remembering, but there is a way to tell the iPhoneX to not allow your face if you find yourself compromised in some way. So unless someone has access to make a 3d rendering of your face, the means to make a mask and the opportunity to take your phone before you can signal that you want to authenticate with a password it seems pretty secure...
- deleted 9y ago[deleted]