I wonder if the tech team involved with Face ID factored the birthday paradox into their security factor. They touted a "1 in 1,000,000" chance that someone else's face unlocks one's iPhone X.
Well, with the birthday paradox, let's say there were, say, exactly 1179 people in the Steve Jobs Auditorium and they all had iPhone Xs. That's 694,431 unique pairs of people, and there would be roughly a 50% chance of two of the attendees faces unlocking the same phone.
That's not helpful for brute forcing a single phone, but it is mildly disconcerting that a security factor of only 1 in 1,000,000 is considered a "wow" factor.
Edit: Some people are asking, "But isn't that equivalent to a six digit pin?" Yes, of course. I am just opining on the marketing spiel for security not being nearly as impressive as it sounds. More boring features like the secure enclave play a much larger role in the security of the iPhone than the "1 in X" chance of a successful unlock.
The difference is that if two people in e.g. a class have the same birthday then there will be a day when those two have birthdays, whereas if two people in the same auditorium have the same code, or face, then that has no implications. There is no process where all faces are cycled through and applied to all phones or similar.
So regardless of how many people in a room, or a country, have the same face you still need to bring your one phone up to 1 million people to unlock it.
The thing is if two of you have the same birthday then it falls on the same day . But if two of you have the same face, that doesn't mean you have to use the same phone. So unlike the birthday paradox where your birthdays "clash", you'd still have to try everyone's face on everyone's phone.
An actual Birthday Paradox equivalent would be if you had 1,000,000 phones and the 1,179 people in the auditorium, and you assigned people to a phone based on their face recognition ID. Then you would get your high chance that not everyone would get a unique phone.
"There's a 50% chance that two people in this room have the same face" is not the same as "there's a 50% someone in this room has the same face as mine". The birthday paradox isn't really useful for conceptualizing FaceID's security.
I'm not saying 1 in 1,000,000 is great, but I don't see how the birthday paradox applies. Assume that I want to analyse whether face unlock is secure enough for me -- why is the chance that anyone else's phone gets unlocked by someone else's face even relevant?
Because if you're an actor with a lot of faces (eg, state level actor with a face db) to feed it, and you're sweeping large numbers of phones rather than trying to hit one in particular, this suggests they'd have an easier time than it sounds like when you're considering it in the private use context.
I think it can be assumed that the facial recognition is rate-limited, just like PIN entries. Even if you had a million phones and a million faces in your database, you could only try perhaps 30 faces on each phone.
If you have the kind of surveillance tech people are postulating here, you already have a high-res-enough scan of the actual face of the person you target in order to produce something to unlock their phone.
Not likely - they used professional hollywood mask makers to test against... Remember, this is infrared with a 30k dot projector - the most accurate 3d visual record you could make would appear to be insufficient.
Choosing someone that looks like the owner would increase the odds greatly. You can't narrow down the search field like that with a PIN or a fingerprint.
Especially for groups of people who are less likely to be represented in the training data. Someone with the last name "Tillekeratne" for example is Sri Lankan, and Sri Lankans are probably underrepresented in Apple's training data. If you harvested images of Sri Lankans online you would probably need less than a million to get a false positive.
>If you harvested images of Sri Lankans online you would probably need less than a million to get a false positive.
Bearing in mind that FaceID uses a depth map of the face, you'll need more than photos harvested online. They also specifically said that they've tested against realistic masks to make sure they won't work, so I don't think it'll be quite as bad as you imagine!
The names FaceID and TouchID are apt. They are IDs. Not passwords. You should unlock your phone by something in your memory. Unlock by face or fingerprint is an anti-feature for me.
Perhaps, but what if they ensured that FaceID only worked when you had both eyes open? It would then, be much easier to be non-compliant than it would with TouchID since it's harder to hold someone's eyes open without obscuring the face than it is to press the phone's home button against someone's finger.
Wink/Blink if you don't want to unlock your phone seems, to me, to give more consent to unlock than a fingerprint.
When you record your face for the unlock, strike a pose that is not your default expression. Put your hand on your face with the sherlockian "hmmm" expression.
Guards/police won't know, they'll just hold the phone up to your face and try to unlock it.
For a 4 digit pin, yes. I believe iPhone now defaults to a six digit pin (equivalent to the 1 in 1,000,000), and the enclave will delay and lock out repeated attempts. They didn't say, but I would hope a similar lockout is employed on the iPhone X.
I strongly suspect that the number 1,000,000 was chosen due to marketing, and that the actual strength of the security lies in the enclave preventing repeated failures and this feature that disables Face ID by repeatedly pressing the power button.
It's interesting you're modelling the pairs as being unordered.
If person A's face unlocks person B's phone, does the reverse hold? I'd guess it's moderately likely, but not certain (e.g. the chance in the other direction becomes 1 in 1000 instead of the magical 1 in a million).
That's like saying "lightning is much more dangerous than thought, because what matters is not your risk of dying, but the risk of any one of 30,000 people dying".
If the risk is "1 in 1,000,000" that means it's 1 in 1,000,000. People understand that doesn't mean it never happens. But it's orders of magnitude lower than their risk of dying in any given year, so it's factually negligible.
I don't think anyone's considering faceid a "wow" factor in terms of its high security (or lack thereof). It's hard to get the general public excited about levels of security. Face ID is pretty much a hack, one that's existed on android phones for many years, that Apple has to polish as best it can.
I didn't watch the keynote: do they have touch ID on the back?
Sorry, I didn't mean to imply that it was "bad" when I said "hack". I meant that it was introduced in order to solve a problem introduced by another design change (i.e. the removal of touch ID).
Well they introduced completely new dedicated hardware components that I've never seen in a smartphone to enable this feature. For me "hack" doesn't do the feature justice.
If using a 30k dot projector, 2 cameras (one IR), and a neural network processor is your idea of a 'hack', I'd love to see what you think an elegantly designed solution is!
You should watch the keynote then. Calling it "existed on android phones" is borderline incorrect as it uses infrared sensors to match 3D models of your face.
Nope, no Touch ID. The presenter also failed to unlock via Face ID several times in a row, prompting a "please enter your pin to unlock phone message". Worst time for it to happen.
You are seriously misrepresenting what happened. The display phone was showing the “passcode is required to unlock” screen that iPhones show when they are cold-booted.
Huge mistake, IMO. People really love touch id, and it would've essentially been 'free' had they just moved it to the back. I've been using Huawei's equivalent on the Nexus 6P for over a year now, and it works like a dream.
Well, with the birthday paradox, let's say there were, say, exactly 1179 people in the Steve Jobs Auditorium and they all had iPhone Xs. That's 694,431 unique pairs of people, and there would be roughly a 50% chance of two of the attendees faces unlocking the same phone.
That's not helpful for brute forcing a single phone, but it is mildly disconcerting that a security factor of only 1 in 1,000,000 is considered a "wow" factor.
Edit: Some people are asking, "But isn't that equivalent to a six digit pin?" Yes, of course. I am just opining on the marketing spiel for security not being nearly as impressive as it sounds. More boring features like the secure enclave play a much larger role in the security of the iPhone than the "1 in X" chance of a successful unlock.