5 ms·
What does this mean for the security of FaceID? Anyone with deeper knowledge? I am not very knowledgable in this field.
by domano 5y ago
What does this mean for the security of FaceID? Anyone with deeper knowledge? I am not very knowledgable in this field.
- jw1224 5y agoI doubt Face ID would be vulnerable to these. Face ID uses projection mapping and infrared photography [1] to establish depth, ensuring a face is "genuine" and not simply a photograph. [1] https://support.apple.com/en-gb/HT208108 https://support.apple.com/en-gb/HT208108
- rbanffy 5y agoNot to this one, but if you use 3D faces for input, you'll end up with something that will: a) defeat Face ID b) look like the result of a horrific teletransporter accident.
- angulardragon03 5y agoIt would have to be device specific, as the dot projectors in each FaceID device have a randomised layout unique to that device [1]. This seems to be part of why the FaceID sensor is paired to a device. [1] https://www.apple.com/business-docs/FaceID_Security_Guide.pdf https://www.apple.com/business-docs/FaceID_Security_Guide.pd... (page 3)
- rbanffy 5y agoStill possible. You'd need to extract and operate multiple Face ID detectors to get the right signals and probably scan thousands of faces to learn signatures and what's needed to fake the inputs. Harder than photos/video, but still doable.
- skoskie 5y agoProps for the source AND page number. I’ve read it before but hadn’t recalled that detail about the randomized layout. TIL!
- jw1224 5y agoYou won’t defeat Face ID that easily. It needs to detect an infrared signature belonging to a real face. Face ID disables itself after 5 failed attempts, falling back to a password. In my experience, if you point it at something that’s definitely not a real face (but looks like one), it disables immediately.
- rbanffy 5y agoAll you need is to fake the right signals. The sensor itself has no concept of what a face should be - get enough inputs and the GAN will eventually figure out what it needs to get the right output.
- andyjohnson0 5y ago> Face ID uses projection mapping and infrared photography to establish depth It seems to me that this "just" expands the parameter space as a way to make defeating the algorithm much harder. I don't see how, in principle, that makes Face ID invulnerable to this type of attack. Given that Face ID is only accessible using Apple devices which lock-up after a number of failed attempts, training a sufficiently sophisticated GAN might be problematic. But a motivated attacker might, for example, use a device farm or a reverse-engineered implementation of Face ID.