7 ms·
Breaking Into Android Phones with a 3D-Printed Head
- goda90 8y agoBiometrics will never be a password. It's got to be a combo of something you have and something you know.
- zeta0134 8y agoAgreed. Biometrics doesn't even quality as something you have. It's something that you are. If your physical key gets compromised in some way, you can generally have a new one issued. But you can't just re-issue your face.
- wlesieutre 8y agoYou can, it’s just risky and expensive and probably not something you want to do.
- deleted 8y ago[deleted]
- matt4077 8y ago<something you have> + <something you know> = <something you are> Sounds ok to me, at least in the weird arithmetic of this tired talking point that invariable makes an appearance every time the subject is discussed, usually in a tone of letting us in on some great, newly discovered revelation.
- deleted 8y ago[deleted]
- kgwxd 8y agoIt's hard to resist stating "1+1=2" when everyone knows it's true but keep behaving like its not.
- mikeash 8y agoI don’t think people keep behaving like it’s not true. They just have different priorities. Yes, “something you have + something you know” is more secure, but security is not a binary thing, and people’s real world behaviors need to be accounted for. Before biometric authentication was available in cell phones, I had no passcode at all. My device’s security was just the physical security of the device itself. Constantly entering a passcode was just too much hassle, let alone a proper high-strength passcode. Moving to biometric authentication massively improved my security. Lots of people I know were in the same boat, or maybe had a four-digit passcode equal to their birthday and/or ATM PIN. It’s not foolproof but it’s good enough for almost everyone.
- PeterisP 8y agoOn the other hand, biometrics is a quite decent username, better for this purpose than some nickname or email address.
- dragonwriter 8y ago> On the other hand, biometrics is a quite decent username, better for this purpose than some nickname or email address. Well, biometrics may be better than an a third-party email address in some cases (harder to lose throguht third-party action), but often worse than a first-party email address (e.g., Gmail for a Google account) or a nickname, for the same consideration.
- biometrics 8y agoRight you are!
- PhasmaFelis 8y agoThe way it was explained to me is, a fingerprint (or whatever) is quite difficult to copy...but as soon as you scan it and send it over a network for verification, it's no longer a fingerprint but a datastream just like any other password, except that this is a password you can't change if it gets compromised. Therefore, biometrics can conceivably be useful if used cautiously on a single device or a well-secured local network. As soon as you start sending them over the public internet or anywhere else that it's possible for a hacker to intercept, all advantage is lost.
- bsenftner 8y agoWithin the security & digital forensics industry, it is best practices to require a minimum of 3 separate biometrics for anything requiring financial authentication capabilities. Apple is not respecting this best practice.
- Andre607 8y agoBiometrics is third-factor authentication (something you are). Its purpose is to supplement second-factor authentication (something you have), which is in turn meant to supplement first-factor authentication (something you know). You can also add a fourth factor (somewhere you are, or location) as an additional authentication factor as well. But it's this key point --that biometrics is meant to be one layer of multi-factor authentication -- which vendors seem to have ignored by conflating its function as supplement with its function as replacement, which it is decidedly not.
- edoo 8y agoIt seems similar to a personal challenge question like "What is the name of your High School". Your face is public information, just like that knowledge, but can be used in a security process to statistically decrease security breaches.
- ridgeguy 8y agoIt could be a combination of something you have (your face) and something you know (for example, that your right eyebrow has to be raised for face unlock to work).
- danlugo92 8y agonice idea
- dgzl 8y agoBiometrics is a difficult-to-guess user_id and not much more.
- kalleboo 8y agoStill works better as authentication than a 4-digit PIN or 4-point unlock pattern that you're entering right infront of strangers tens of times a day.
- ClassyJacket 8y agoI disagree. It's far easier to look over somebody's shoulder as they type in their password than it is to 3D print a copy of their head. I think most of the disdain for biometrics on phones is because Apple were the ones to popularise it, and tech people hate anything Apple does.
- fmj 8y ago>I think most of the disdain for biometrics on phones is because Apple were the ones to popularise it, and tech people hate anything Apple does. I've been hearing the exact same arguments against biometrics in every thread on the topic long before Apple even did biometrics.
- amelius 8y agoWhy didn't Apple consider to unlock phones using a smartwatch instead? That might have been a compelling reason to actually buy one.
- vivekseth 8y agoYou can use an Apple Watch to unlock a Macbook!
- MBCook 8y agoI really wish they didn’t have to be on the same iCloud account though. It would be nice to register my watch to unlock my work computer, but I can’t.
- hutattedonmyarm 8y agoAnd you can use your iPhone to unlock your Apple Watch! (But not the phone to unlock the Mac directly)
- rootusrootus 8y agoIt works the other way around. The presence of your paired, and unlocked iPhone will unlock the Apple Watch (provided it is on your wrist at the time). I have found many compelling reasons to buy the watch even though it can't unlock my phone. It can unlock my computer, but it's not much of a revelation, it's not that hard to type in my password quickly on a physical keyboard.
- tedunangst 8y agoIf it were that simple, wouldn't the police simply take your watch too?
- gpm 8y agoThe watch could delete the unlock code when removed from you wrist. You could further make it so that the phone would lock if unlocked by the watch, and it was removed from the immediate vicinity of the watch or the watch was removed from your wrist.
- shambolicfroli 8y agoHmm. When I had a skin cancer excised by a surgeon, in a followup visit a woman with no ID came in and made a point of taking closeup photos of full-face and profile. When I asked she said this was standard (for minor skin cancer removal). (Same place, where I walked into the room for the procedure, they had Carole King singing "it's too late" at loud volume on a portable stereo sitting on the ground.)
- scotty79 8y agoThis is like something from Black Mirror or Maniac.
- gumby 8y agoI was considering doing a startup addressing skin cancer and a number of Mohs surgeons were happy to have me come in and observe the entire process. To the patients they'd just say "he's observing today" and not even introduce me or ask the patient (or me) to sign anything. I have a friend whose startup cared was doing a surgical product; after I told him my story he called up a bunch of plastic surgeons and went and observed a bunch of them. Both of us were interested in workflow; the actual science we had done on animals of course, but our research was aimed at seeing if the product would be viable (could be medically wonderful but if the doctors don't care they won't use it on the patients, even if it improves outcome). I don't think we could have done this at a hospital, but given that it was surgery (surgeons have a lot of freedom) perhaps we could have.
- tedunangst 8y agoHow carefully did you check the surgeon's ID?
- reaperducer 8y agoWhen I had a skin cancer excised by a surgeon, in a followup visit a woman with no ID came in and made a point of taking closeup photos of full-face and profile. When I asked she said this was standard (for minor skin cancer removal). I had that happen to me, but it wasn't my face where the excision happened, or that was photographed, so it may really be standard procedure. My guess is so that in follow-up examinations it can be determined if any remnants remain and/or spread. But my incident was about 20 years ago. Today I would be very suspicious, like you are.
- matt4077 8y agoThe article is unfortunately unclear on this, but I believe they succeeded only on the Android phones, not with the iPhone X they also tried it on. To wit: "[..] four Android models and an iPhone X. Bad news if you’re an Android user: all four phones unlocked with the 3D printed head."
- agumonkey 8y agoReminds me of old Mission Impossible episodes where they prepped rubber masks.
- dbcurtis 8y agoMythbusters did an episode about those masks. They only fooled humans at a distance, and then not well. Grant does a heck of a double-take, though, at one point. It is a fun episode so I won’t spoil it.
- ricardobeat 8y agoSo the iPhone was not fooled? They seem to conveniently ignore this for the remainder of the article - more clickbait power.
- alansammarone 8y agoNo such luck with the iPhone X, though. Apple's investment in its tech - which saw the company work with a Hollywood studio to create realistic masks to test Face ID - has clearly paid off. It was impossible to break in with the model.
- SlowRobotAhead 8y agoI imagine this is because the printed head isn’t anything but one-color under IR, it’s all the same temperature, right? Seems like an interesting challenge to create a heated fake head.
- _tulpa 8y agoThe IR camera and the dot projector they use it with are in the near IR range (as in wavelengths near the visible part of the spectrum). It’s mostly only used to get depth data, and it’s near-IR so that you don’t get a bunch of visible dots projected onto your face every time you use it. I guess you could see temperatures, but you’d have to point it at something almost hot enough to emit visible light. For normal face temperatures you’d need something sensitive to far IR.
- SlowRobotAhead 8y agoIf it’s just 3D without heat mapping, why don’t masks work?
- _tulpa 8y agoI mean... A quick search would show you that masks can work. But I’ll bite. It’s really precise 3D with a greyscale non-thermal IR image. Could be inaccurate masks? Missing details around the eyes and mouth and other important areas? Do masks have eyes with a discernable gaze direction? Do they have microexpressions or natural facial deformation? Do the eyes move? There’s a buttload of stuff they could be measuring that is insanely hard to replicate with a mask. Besides, a thermal map would be pretty much useless even if the hardware was capable of thermal imaging. Skin temperature varies a lot (and not always uniformly) based on ambient conditions, physical exertion, being sick, sitting in direct sunlight, etc, etc.
- detaro 8y agoThis repeats the contents of another, IMHO better-worded article: https://www.forbes.com/sites/thomasbrewster/2018/12/13/we-broke-into-a-bunch-of-android-phones-with-a-3d-printed-head/ https://www.forbes.com/sites/thomasbrewster/2018/12/13/we-br... Please submit the original source to HN!
- gumby 8y agoThe Forbes link is indeed better. Forbes links seem to have a poor rep on HN because they are mostly poor blog entires that could have been on medium. The one you posted was an exception.
- dang 8y agoChanged from https://techcrunch.com/2018/12/16/3d-printed-heads-unlock-cops-hackers/ https://techcrunch.com/2018/12/16/3d-printed-heads-unlock-co.... Thanks!
- cronix 8y agoExcuse me while I (covertly) laser scan your face to create a 3d model so I can print it and unlock your phone.
- DanAndersen 8y agoFor now, at least. Some companies have massive annotated databases of people's faces from different angles, and the ability to do plausible 3D reconstruction of the faces.
- bsenftner 8y agoYep. My employer has several hundred thousand laser scans of real people, spanning every age, gender and ethnicity on the planet, multiple times over. Our FR system can perform 24 million high quality 3D reconstructions per second with two cores at 3.4 GHz. It's pretty amazing.
- cronix 8y agoYes, like some DMV's do facial scanning now, and some cities/counties are hooking it up to Amazons Rekognition with cameras mounted in public as well as Palintir software, among others. The FBI tends to use those DB's too. I'll stick to my password, which is actually constitutionally protected, unlike a face, which can be seen from public.
- deleted 8y ago[deleted]
- armenarmen 8y agoWhat level of detail do airport security body scanners have? Enough to print a head good enough to unlock a phone?
- DanAndersen 8y agoDoes anyone know if there's anything about the unlocking method that requires the model to be 3D-printed? It seems like you could render the 3D model of the head on a monitor and point the phone's camera at the monitor. If the phone needs to see some sort of parallax change relative to its own motion (from internal sensors), then one could put a 6-DOF tracker onto the phone and use it to update the rendered viewpoint of the head (a form of user perspective rendering). Such an approach would be quite useful for law enforcement to gain access with much less time waiting for printing.
- prepend 8y agoThe iPhone uses lasers so it’s not just imagining but depth measurement. I don’t think could be faked with only a monitor.
- rootusrootus 8y agoIn this example, though, the iPhone did not fall for the 3D printed head, so this attack would likely be just as effective with a picture.
- tantalor 8y agoJust as ineffective
- rootusrootus 8y agoI meant against the Android phones, which are just using a 2D camera for face detection.
- tinus_hn 8y agoI can imagine it requires the head to move like a real head.
- lifekaizen 8y agoNot lasers, it’s an infrared dot pattern. Projected on a surface and the distortions are viewed with an infrared camera and analyzed for depth. Actually it might be possible to hack if your screen could output IR wavelengths.
- dawnerd 8y agoWould be interested to see how well Windows hello stacks up on proper hardware.
- intopieces 8y agoI wish there were an option to make the successful face scan my username, not my password.
- gbaygon 8y agohow many usernames do you need in your phone?
- saagarjha 8y agoAndroid supports multiple "profiles", so it's convenient when you have a shared device such as a family tablet.
- intopieces 8y agoJust one, but that's the point. Don't present the person holding my phone with a chance to enter a password or passcode unless you know it's me, by scanning my face.
- tonyztan 8y agoI've always wanted a two-factor lockscreen, so that I can scan my fingerprint and then type a PIN. A face scan would work even better in this context.
- null000 8y agoConsidering I don't use face unlock on anything I care about (most financial apps, for instance, are protected by strong passwords and/or fingerprints) and the sheer fiddlyness of 3d printing, if they can get a scan and print of my head off, they earned what they find. Have fun looking through a bunch of porn and reddit shitposting, I guess.
- deleted 8y ago[deleted]
- lern_too_spel 8y agoDo any Android users actually use face unlock? It always seemed like a gimmicky feature from the early days of smartphones when everyone was just trying to build up their patent portfolios.
- sidkhanooja 8y agoI use a OnePlus phone (don't know if HN users have heard of it), and OP users rarely use the fingerprint unlock. Although the user is definitely compromising on security, the speed of face unlock is such that it is near-instantaneous. Double tap the display, and you don't even have to blink - the phone unlocks. It may be a gimmick in the early days of Android (think Nougat or even Oreo), but it's definitely not a gimmick now, for me at least. It's fast enough to have proved its worth.
- bunnycorn 8y agoI've watched the video and it ends terribly bad. No, the passcode might be in your head, but if someone sees you in a CCTV entering the passcode, it's not only there anymore.