Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another thing is that an attacker only gets a few chances to use the face unlock before the phone requires a pin. How many tries did it take them while having to re-enable FaceId after locking the phone? IMO, it's only 'broken' if they can get the face right the first time without causing the phone to lock itself.


Hmm. I read somewhere that if FaceID doesn’t work and you use the PIN, it adds the face to the dataset. Is it possible they just slowly worked the mask into the dataset?


That's not what I'm saying. They made a face that managed to trick the FaceId, but how many times did they have to test it? In a real world situation, the face would have to work in 3 tries or the phone locks itself with a passcode. Given the elaborate process they went through to make the face, it would be very hard to make a face that basically works the first time (I've noticed FaceId will try multiple times and lock pretty quickly).


Doesn't sound like they took that approach:

> However, we knew about this "learning", thus, to give a more persuasive result, we applied the strict rule of "absolutely no passcode" when crafting the mask.


I was confused by this at first. I thought one of the concerns was the the algorithm would be more discerning about the real face over time. It doesn't seem as though they've addressed this issue.


Then again, if they wanted to make a name for their selves with BS, they would say that even if they have done the opposite.


How did they accomplish this though? Is there a timeout where, after enough FaceID failures cause a fallback to passcode, FaceID is accepted again without entering a passcode in the interim?


No, Face ID takes another snapshot after the passcode has been entered.

Source: "Face ID takes another capture and augments its enrolled Face ID data" https://images.apple.com/business/docs/FaceID_Security_Guide...


This only happens if the face is deemed similar enough to the original face data, which is unlikely if it's a completely different person.

Here's the entire quote:

"…if Face ID fails to recognize you, but the match quality is higher than a certain threshold and you immediately follow the failure by entering your passcode, Face ID takes another capture and augments its enrolled Face ID data with the newly calculated mathematical representation"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: