Hats/sunglasses/rain/lighting all cause problems for mobile devices and face recognition.
It'll be interesting to see if/how Apple overcome those problems
Touch ID: 1:50,000
Face ID: 1:1,000,000
Much easier to just 100% of the time splat out 4 numbers.
Local police? No fucking way. Random phone thief? Don't make me laugh.
And people seem to actively "forget" that this is a learning model, getting better with every unlock. Just like TouchID, but better.
It sounds like this in some ways is a step forward from touch id in that regard, but we'll have to see.
But still, with the dot projector, and that kind of processing power, they should be able to detect 3d gestures, similar to leap motion.
>All of these system have been proved easy to trick.
By what standard, and in comparison to what? Even ignoring that implementations vary dramatically and importantly in inherent hardness [1], even what you're describing is already significant effort. In terms of security categorization, what you're describing ("3d prints", "specially prepared photo", whatever) all fall into the fundamental form of a targeted physical attack. But once we're into targeted physical attacks everything becomes much harder. Passcode? We live in a world where cameras are everywhere already and becoming more ubiquitous still, along with drones. Even simple shoulder surfing is a thing, but when you're out in public and need to unlock your phone how certain are you really that there is not a single camera, anywhere, pointed in your direction? Even if it's not directly down at the screen merely seeing your finger/thumb movements may be enough. How much work are users in general actually willing to go through to unlock something they use constantly for often very short bursts of immediately desired information? Because if your system isn't actually something people will use and has a good work/value tradeoff, it's worthless. It's not the people who are wrong, it's the system.
This is why threat scenarios are vital in security evaluations, always. In general, there is a big topological difference between scalable attacks and targeted attacks, and with remote vs physical presence requirements. Coming up with convoluted attacks and scenarios quite literally misses the entire point. You need to consider what a system is trying to do, how well it does it, what it is trying to defend under what circumstances, the value therein, the audience targets, etc etc. You didn't do any of that, and on HN people really should know better.
FWIW, I do have significant concerns about Face ID, both in terms of implementation in practice, and in terms of how amenable it is to some real practical security practices I'd like to see like coercion code/variable unlock for example. But my list of concerns do not include anything that relates to a targeted physical attack unless it proves trivially scalable in the real world, as that's outside the core scope.
----
1. Seriously, it's immensely irritating how many tech people think ideas, theory and so forth have much of any value whatsoever vs real world implementations, or think they can always talk broad categories rather then specific implementations.
Someone running around with a perfect 3D model of your face isn't an every day occurrence, though.
Sure, when it comes to more organized crime or the government they'd be more capable. But at that point if you really want to protect your data then I don't think an iPhone is where you want to be putting that data in the first place..
Or I'm wrong.
But the guy did have issues on stage...
Apple is using 3-D scan data as well as infrared reflectivity and for all we know temperature sensing. You can't compare the two.
Did you have something that's a closer comparison?