My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.
You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.
If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.".
Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.
In the phone case, they don't need a warrant if your authentication method is literally your face.
Detective: "Is this yours?"
_Suspect glances in the direction indicated, phone unlocks._
Detective: "Nevermind, I got it from here."
-----
At least TouchID required physical assault to get you to unlock the phone. FaceID on the other hand can be defeated with perfectly legal attention grabbing techniques.
Without a warrant: No information taken from your phone by the police is admissible.
With a warrant: A judge can compel you to unlock any device with a biometric lock, regardless of what sort of biometric lock we are discussing. Fingerprint, iris scan, or face, it simply does not matter.
Fruit of the poisonous tree is a legal metaphor in the United States used to describe evidence that is obtained illegally.
For example, if a police officer conducted an unconstitutional search of a home and obtained a key to a train station locker, and evidence of a crime came from the locker, that evidence would most likely be excluded under the fruit of the poisonous tree legal doctrine.
https://en.wikipedia.org/wiki/Fruit_of_the_poisonous_tree
Border agents operate under a different set of rules and have been searching mobile devices without a warrant or even probable cause.
However the ACLU and EFF have filed a new lawsuit challenging this behavior, now that the Supreme Court has ruled that the police cannot conduct warrantless searches of cell phones inside the US.
Doesn't (or can't) law enforcement also use parallel construction (based on information obtained without a warrant)? I believe the point about what's admissible is not as clear cut as you state in a single sentence.
And even there, would this stop a police force who routinely abuses, beats up, or even kills innocent people on the street for no or imagined provocation?
Depends on the country. Not everywhere, including western Europe, is this true.
If all 3 of these are true, you need a warrant (at least in the US). Doesn't matter if the keys, or in this case your face, are right there. The fact that you locked your phone with something the cop doesn't normally have is enough to require a warrant.
For one, there are tons of loopholes, from border searches to "evidence of criminal activity" (dead easy to "prove" for a black/latino/poor person and have the court agree), and unless you can afford a good lawyer, good luck trying to prove your rights were violated:
https://en.wikipedia.org/wiki/Warrantless_searches_in_the_Un...
http://www.npr.org/2011/05/16/136368744/in-warrantless-searc...
Not to mention that warrants are not that difficult to obtain either -- except in the movies.
Nobody's saying that home security is good. The point the parent was making is that, even with a "liveness test", compared to other biometric identification, this is a regression from fingerprint-based authentication for the iPhone.
You think they can force you to look at it ("engage" with it) but not touch the phone?
Honestly, the easiest attack would just be to ask me about my dogs. 99.99% chance I'll unlock my phone, pull up pictures and show them to you (easy grab) or just hand you the phone and let you browse through them.
is how you work around that issue.
Keep in mind, you don't need to refuse to TouchID/FaceID forever, just for the timeout (which I do wish was configurable -- I think one hour is reasonable).
1. You're walking, with your phone in your pocket.
2. Suddenly, a cop accosts you. You don't have time to react.
3. They detain and restrain you (with handcuffs or otherwise)
4. They pat you down and find your phone
5. They hold up your phone to your face to unlock it
I know that people who've never been detained or interacted much with cops think that this is a completely unlikely situation, or easily avoidable, but I promise you it is not.
TouchID isn't great from a law enforcement perspective, but it's light years ahead of FaceID.
FaceID / TouchID are a "convenience" to be used when you are comfortable with your surroundings. Can you be caught off guard even when you are paranoid? Of course, nothing is ever guaranteed in life, except death and taxes as the saying goes!
You and I have incredibly different experiences of policing and detention if, for you, "be proactive when you're at-risk" is appreciably different from saying "don't use FaceID ever".
If you are in such high risk situations continuously that "be proactive when you're at-risk" is appreciably the same as "don't use FaceID ever", then I say you are doing something very wrong and not just incidentally being stopped for a suspicion of possibly doing something wrong.
Either way, your experience is definitely not in the 99.9999% of the population which FaceID would be sufficiently safe if it proves to be as secure as Apple implies. For you, let's hope you aren't using a numeric pin code either!
The biometric attacks being discussed here are ones that could quite plausibly be used against you in many/most districts in the US, and be totally legal for the police to use.
1. You're walking, with your phone in your pocket.
2. Suddenly, a cop accosts you. You don't have time to react.
3. They detain and restrain you (with handcuffs or otherwise)
4. They pat you down and find your phone
5. They take your hand and place it on the fingerprint sensor.
Ignoring #2 (and the terrible language you used), I don't see how my scenario is significantly more or less likely than yours.
Have you ever been detained?
As far as I'm concerned, "refuse to look at it" is useful as a prevention tactic as not having any lock at all.
I'm honestly curious, what's the difference between "I refuse to look at my phone" and "I refuse to enter my PIN" when being detained?
It's in the marketing materials for the phone, was mentioned multiple times on stage during the introduction, and is in the introduction to the whitepaper that this entire HN thread is about. So yeah - a couple of sources are available...
Yeah, I'm going to say that this is an absolutely unrealistic expectation to have of someone who's just gotten detained and is concerned about having the contents of their phone viewed by law enforcement.
"Make sure that you don't open your eyes at any point in the direction where they might be holding your phone" is completely unactionable.
As is the assumption you won't be forced to touch your finger to the phone. I can assure you, if someone wants into your phone bad enough, they will break your fingers if thats what it takes.
Or you can apply a threat model and determine whether the people for whom TouchID/FaceID is keeping your phone secure against would have the resources to mount such an attack.
You can turn it off.
Is "don't use a lock" really the answer to "my key was stolen"?
The only risk is if somebody cracks the entire FaceID model and Apple cannot fix it in software. But even then, you would still disable FaceID and either return your phone or wait for a recall.
Did you even read what I wrote? You would turn off FaceID and revert back to a passcode/passphrase until it is fixed in software.
From the PDF:
"Once it confirms the presence of an attentive face, the TrueDepth camera projects and reads over 30,000 infrared dots to form a depth map of the face, along with a 2D infrared image. This data is used to create a sequence of 2D images and depth maps, which are digitally signed and sent to the Secure Enclave. To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern. A portion of the A11 Bionic chip’s neural engine—protected within the Secure Enclave—transforms this data into a mathematical representation and compares that representation to the enrolled facial data. This enrolled facial data is itself a mathematical representation of your face captured across a variety of poses. "
So, it's more like a hash of your face, which is very similar to how TouchID works. So, again, even if someone were able to break into the secure enclave and get that data, what could they do with it? It's a representation of yourself that is used for Apple devices.
Also, this is an OPTIONAL feature. If it doesn't fit your security model, don't use it. For the same reason a lot of people don't use TouchID -- they want the security of a passphrase. But for 90%+ of people that will buy that phone and are not at risk of the government or police pursuing them, the security it offers is more than adequate and it achieves this by not annoying the user and requiring them to have a 50 character passphrase.
This is trivial to do if the person is in custody. You could also profile a specific target and get their face walking past them on the street. You could do this in bulk in a public place.
Now your face is compromised and the person who stole it likely posesses your phone and is unlocking it now. You can't change your face, but it's too late anyway. You live in an oppressive regime, they found out you're gay from what they found in your phone, and you're going to be hanged in a week.
You can’t ‘get their face’ if they’re ‘walking by’, you have to go through the whole enrollment. How are you going to trick them into that?
Also even if they go through some Herculean process to get your ‘face hash’ Apple could simply change the hash algorithm and reset it. For all we know different phones will use a different per-device random seed in the algorithm and that attack wouldn’t work at all even if the algorithm isn’t changed.
Again, you’re talking about getting a fully accurate 3D model of someone’s face that passes the FaceID tests and can be used to trick the attention sensors. That’s an INSANE level of effort for Joe random.
This is not a realistic attack, and FaceID is not designed to secure anyone at any time from any government with unlimited funds and resources. It’s designed to be better than the trivial passcodes that almost no one used.
Second, the point of using an IR image (in addition to the depth image) is that a simple 3D print is not going to provide valid spoofing - it will not match the IR absorption profile of a live face. Additionally, they are also likely testing for liveness by looking for changes from image to image, even if it’s just saccades of the eyes.
Third, Apple implies that they are taking a sequence of images. They can, for example, look for changes in IR images associated with blood flow correlated with your heartbeat, which prove you are alive and may be distinguishing from individual to individual. The secure enclave could also request specific changes in the images that can’t be predicted in advance, thus foiling attempts at feeding in canned images.
In short, I don’t think it’s anywhere near as simple as you propose.
> To counter both digital and physical spoofs, the TrueDepth camera randomizes the sequence of 2D images and depth map captures, and projects a device-specific random pattern.
and
> An additional neural network that’s trained to spot and resist spoofing defends against attempts to unlock your phone with photos or masks.
It's effectiveness is yet to be seen, but the implementation details counter all the points you made.
Either way, let's say this attack you're talking about is possible. What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "trivial." If you're Edward Snowden, don't use this feature. Simple as that. But I wouldn't use TouchID if I was Snowden either.
Judging by your last paragraph, though, I'm guessing you're trolling. Have a nice day.
You don't need to shut off the phone to get into the hardware.
>What % of people that buy this phone are actually going to be at risk of someone taking their phone apart to compromise them in this way? This method you explained is in no way "trivial."
On the other hand, I bet a company could easily implement such an attack on the cheap and sell it to LE, who would just pass the costs on to the defendant.
>Judging by your last paragraph, though, I'm guessing you're trolling. Have a nice day.
I'm setting the stakes. If you're not up for the discussion that's up to you.
Do you mean row hammer [1] or cold boot attack [2]?
I'm genuinely curious if this has been done before and if you can provide examples.
Its not merely secret service who can do this. Criminals can do it as well. The easy part of it? Your fingerprint is left all over your device. Including likely the one you authenticate with. If its your index finger of your primary hand, its bingo.
A fake 2G cell tower costs 250 EUR on the black market. That's also a bad way to use TOTP. However, 15 years ago those devices were either not sold or still very expensive. That's a different threat model.
FaceID is going to be hacked eventually (the question is when, not if), perhaps in the way you described. Until then it is reasonably good to keep criminals who steal your device at bay. Its also worth it to audit it (try to break it, e.g. in the way you described). State agencies, unlikely to keep those at bay with FaceID, given they can force you to authenticate. Criminals who mug you by force may also be able to force you to remove FaceID, but they may also compel you to give away your PIN. Government has already made devices to bruteforce PINs; we should've swapped to passwords ages ago.
[1] https://media.ccc.de/v/31c3_-_6450_-_de_-_saal_1_-_201412272...
While I am sure it is not impossible, nobody has been able to provably "trick" the current-generation Touch ID sensor. Only demonstrated on the first revision (found in the iPhone 5s, and possibly the iPhone 6 too).
I submitted this earlier today but it didn’t get traction.
Basically it could be done.
The fingerprint argument isn’t an argument against FaceID. And it’s still kind of pointless because Apple put out figures a few years ago that TouchID lead to a ~50% INCREASE in locked phones.
You seem to be arguing that a secure passcode without biometrics is better. It seems that if the public can’t use biometrics they prefer NO security. So even with that ‘flaw’ it’s no worse (often MICH better) for everyone.
“Biometrics are evil because you can’t change them.” Or “They’re usernames/passwords/whatever.” Or “FaceID can be subverted by a nation state with 3 years and $75 trillion”. Or “You can just unlock it with a single picture from Twitter.”
And of course “If only they added an esoteric and complex method of unlocking a fake environment under duress by winking the word tomato backward in French Morse code...”
None of it seems helpful. Using a FaceID discussion to argue TouchID is insecure... seems pointless. The arguments about how it can be bypassed (supposedly) with JUST a 3D printer and thousands of high resolution photos and a video of you looking into a camera and........ come on. This stuff would be unbelievable in an Oceans 11 sequel.
And people argue as if FaceID has to be perfect when it replaces a fingerprint (which is easier to fake) or basically nothing. We’re not securing the Crown Jewels here. We’re trying to keep the guy next to you at the bar from tweeting as you.
So in the end there is no useful on top discussion. It’s just a irrelevant story that people can use to tell about their pet biometric issues even when they don’t fit.
People are still arguing about things Apple said during the initial keynote. The only one I don’t see from before is the ‘will it work in the dark’ question which Apple explicitly mentioned in the keynote.
I want to know more about FaceID from people who know more about security. Instead we’re discussing how the technology it replaced is bad and fringe internet conspiracy theory level nonsense.
Edit to add one more thing: maybe this is rose colored glasses but I don’t remember the threads around TouchID being anywhere near this bad. People argued over how easy it was to get a fingerprint, sure. That’s fair. But the rest of the discussion seemed much more relevant.
Plenty of phones and cameras have 3D capability. That kind of tech is already being used in cosmetology courses to 3D print a model of your own face and hair for hairstyling practice. It wouldn't be that difficult to make a warm 3D mask to fool the infrared camera and sensors.
I mean sure you can knock someone out and use a handheld 3D scanner to get a whole bunch of good shots of them but that’s hardly someone walking down the street and you getting a quick grab of their face.
My point isn’t that it’s impossible it’s that it’s not feasible for any normal person or group without a large and noticeable undertaking. These are not reasonable threat models for normal people.
With a Lytro camera you could do it from just about any distance.
"but that’s hardly someone walking down the street and you getting a quick grab of their face."
All you have to do is even look remotely interested in your phone and pretend you're not taking a picture - boom info gotten surreptitiously. That's assuming the other person you're copying biometrics from is even paying attention - odds are they're probably too focused on their own phone to notice.
A very narrow bandwidth of IR thanks to what we term the "Infrared Window," which is trivially easy to duplicate or fool, as it's one of the same IR bands used for surface mineralogy done via satellite.
I'm really not oversimplifying at all; I am applying knowledge in fields in which I am competent to say "You think it can't be that easy, here's how easy it can really be."