Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> biometric data is a username/id.

> why do companies insist on getting this shit backwards?

They don't have it backwards, but they're also simplifying when they say it's your password. In the presentation they actually say specifically that there's a chance that someone else can unlock your phone (1 in 50'000 for fingerprint, and supposedly 1 in 1'000'000 for Face ID, given that you don't have a twin).

Reality is that it's somewhere in between. A fingerprint sensor or face reader will keep casual snoopers - and most people who find your phone on the street - out. That's all that matters for most people. It's not a username. It's at least moderately hard for someone to duplicate, and it's not something you'd actively share with someone. It's not as safe as a password, but Apple isn't trying to claim that either.

I think it's a good idea to avoid false dichotomy here. Biometrics is biometrics. It should be treated as distinct from passwords or usernames.



Watching someone key in a PIN and recording it, then swiping the phone is easier than building a 3D printed color model of someone's face. Not to mention that having the biometric unlock sitting on top of a PIN means that there are many fewer chances for the PIN to be observed.

Whether biometric access is a password or username is trying to force the wrong paradigm. Going back to first concepts, we had keys and we tried to make them hard to copy but not too inconvenient. The face is the key. No, there's no practical way to re-key this lock, but it's still a lock and key. But the door also has a deadbolt (PIN code) which has to be disengaged for the "face key" to function.

The username concept applies when you have multiple people using the same resource (and don't want to know or reveal whether any 2 people use the same password) -- which again doesn't apply to a single-user device.

Finally, all this combined with the quick "hard lock" of the device (5 taps of power button) gives me the impression of a very thorough approach to security.


> Watching someone key in a PIN and recording it, then swiping the phone is easier than building a 3D printed color model of someone's face. Not to mention that having the biometric unlock sitting on top of a PIN means that there are many fewer chances for the PIN to be observed.

With how cheap video surveillance is these days, any PIN that you've regularly entered on your phone in public is probably recorded on video somewhere.

So is your face, of course, but like you said that's much harder to reproduce.


Yeah it's probably out there if you could magically aggregate all of the video surveillance footage in the world.


> Watching someone key in a PIN and recording it, then swiping the phone is easier than building a 3D printed color model of someone's face

Right, but couldn't somebody just use my actual face? Steal my phone, hold it up to my face for a second to unlock it and then run off?

A really interesting thing to think about is what happens if somebody is in custody and is refusing to unlock their phone, but uses face authentication? Can the police just hold their phone up to their face and unlock the device that way or is there any protection from that in the law?


I thought something was mentioned about "active gaze" in the keynote? The phone detects if you're paying attention; it doesn't unlock if you have your eyes closed, it doesn't unlock if you aren't looking directly at it.

Should make it more difficult (though not impossible) to force an unlock by waving the phone in an unwilling person's face?


Not necessarily.

"Excuse me. Is this your phone?"

Or some derivative of that.

You only need to look at the phone for a brief moment. It's designed to quickly unlock. If you had to stare at the phone for 10 seconds it would be a frustrating experience.


yea but you realise the implication when revealing your pin in public. By contrast your face is something you wear in public without a second thought.


It's more like walking around with your pin written on your forehead.


Except that a regular pin pad lets anyone enter the pin. Your pin code can only be keyed in by 1:1000000 people [citation needed]. So no, your pin is not on your forehead. Your pin is an organic material with color and depth and movement that for all intents and purposes is your actual forehead.

The average opportunist thief won't be able to duplicate that key. The best that they can do is use your actual face, within a few feet from you, while you're staring directly at the phone in their hands.


Funny you should say that, here's a video of a guy accidentally unlocking a phone and using his apple pay by pointing it at him https://youtu.be/WYYvHb03Eog?t=1m27s


> building a 3D printed color model of someone's face.

A 3d rendering on a screen is probably enough. The device seems to infer 3D from motion, but would probably be fooled by a rendering or even a recording.

That makes all the interlocutors you had on video chat as potential ID thieves.


False. iPhone X has points(invisible) projected on your face from what depth is calculated. Same as xbox kinect i assume. So 3D rendering on flat display wont fool iphone.


I stand corrected. A depth sensor on the user-facing camer. That one of the weirdest design decision I have seen yet.


It's been done one some laptops via Intel RealSense depth cams or similar hardware. Not sure if any other phones have featured this, though. The ones I've seen typically add the depth cam on the back for niche stuff like 3D scanning.


1 in 1 000 000 is the same odds as a 6 digit PIN (though you can always change a PIN). That's acceptable to me.


Unless you have a twin... that's probably OK. Ease of use is probably most important. I didn't like that the first demo phone failed!


It wasn't that it failed to recognize, it was that it had restarted, and all iPhones require the passcode to unlock the very first time after restarting. (You can tell by the small text over the PIN pad in the video.)

My guess is that he didn't want to dwell on the issue, or didn't know the passcode.


Is it really true that adult identical twins will easily fool this or other modern face detection systems?


Facial recognition is something humans are known to be better at than computers, and identical twins throw off humans all the time.

Even when computers surpass humans at this task (probably not that far off) they will likely have difficulty with identical twins because of how they do facial recognition. At the moment computers do it by identifying points that correspond to the geometry of the face, like nose, eyes, and cheeks. These are all features that would be similar between twins. Usually humans can differentiate twins by fatness, scar tissue, hair style, etc. Not something that can't be overcome, but also not something common with current approaches.


Problem solved: We'll just add scars to twins' faces to distinguish them. /s


I don't know how they wouldn't. Hell, genetically they are probably similar enough that a DNA test can't tell the difference.


Actually DNA tests exist that can tell apart twins.


Is it a specific test, or all tests? If there is a story exploring this, I'd be somewhat interested in reading it.


The FAR rate is quite misleading especially for facial recognition. FAR counts on the data being "random" for that 1:50,000 or 1:1 million to be true. But you can bet whoever is targeting you will build a 3D profile of your face out of all the pictures it can find on you online. I at least assume it won't be "easy" from the get go to bypass Apple's face unlock tech, like it was for the Galaxy S8 with a god damn 2D picture that we've been known for a decade that's an effective attack, but I also don't think it's impossible. Machine learning techniques will become advanced enough in a few years to build someone's 3D profile like that.

Plus, as the parent said on the issue of not being able to replace your face as you can your password, they can still target your face data stored on the phone.


Yes, touchId/faceId sits in between, it's quick access token, which is enough for 95% of the time, but those other 5% are very important.


Those other 5% might be too important to have your phone involved with them.


Or, if one needs those 5% moments on phones, it's always a possibility (as stated on the keynote) to add password additionally.


Okay, but shouldn't developers make security easy? This makes introducing a sizable hole into existing security easy, which is the opposite of what you'd want.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: