You could very quickly rule out 95% of the field with little effort, and people already do things like say "you look so much like X": we have a short list of collisions already.
But at least it's not like people have pictures of their faces plastered across every social network...
... crap.
But I also don't think the "brother who already knows the phone PIN code" a real world attack vector of concern to most people. I get that it could be an issue in narrow situations: you share your pin code, lookalike sibling uses it to "train" your phone; you change passcode not realizing that phone will still unlock for now-untrusted sibling.
Even in that scenario, I would bet that after a few days of normal usage by the phone's rightful owner alone the attack wouldn't work anymore. But, it's too soon to know.
qbirthday(prob = 0.5, classes = 1e6, coincident = 2)
# 1178
You could also just calculate a bunch of the probabilities and find the minimum more "maunually"
in.room <- 1000:1500
probs <- sapply(in.room, function(x) prod(((1e6 - (x - 1)):1e6)/1e6))
in.room[which.min(abs(probs - .5))]
# 1178
Does it mean that if some random person who is not you tries to repeatedly unlock you phone, that person will succeed on average once every N tries?
Or does it mean that the set of all people can be sorted into two groups, (1) those who can unlock your phone almost all the time, and (2) those who cannot unlock your phone, with 1/Nth of the population being in the first group?
Obviously the phone requires a pin after 5 failures, but that’s another matter.