Hackers just broke the iPhone X's Face ID using a 3D-printed mask
wired.co.uk
wired.co.uk
The researchers concede, however, that their technique would require a detailed measurement or digital scan of a the face of the target iPhone's owner. That puts their spoofing method in the realm of highly targeted espionage, rather than the sort of run-of-the-mill hacking most iPhone X owners might face.
Yes, if you have precise enough tools and can print a face that resembles the owner's, and you wear that face, you're going to 'bypass' the recognition software, but are you really 'breaking' it?
You can really see the researcher playing hard to the validity and value of the work here;
Bkav, meanwhile, didn't mince words in its blog post and FAQ on the research. "Apple has done this not so well," writes the company. "Face ID can be fooled by mask, which means it is not an effective security measure."
I don't know, it's not 'hacking' or even 'breaking' enough to concern me.
"Face ID can be fooled by mask, which means it is not an effective security measure."
It's like saying "This lock can be fooled by key, which means it is not an effective security measure."
ANY biometric is not going to be an effective security measure!
I'm sick of seeing these! Fingerprint scanners, face scanners, etc...these should be branded as convenience features, not security features! While Face ID is hard to fool right now, who knows how long it'll take for someone to fool it quickly!
Using your fingerprint/face/etc. as a password means you're creating a password that not only can you not change, but gets left around wherever you go! This insanity needs to stop!
And also disabling Face/TouchID and instead using a 6 digit PIN which has been available as an option since the beginning. For the rest of the convenience of FaceID outweighs the minimal risk of a security compromise.
Think about the level of work this requires vs spoofing a fingerprint. It is much higher and requires much more information.
In other words : if you spend a lot of time and money, you can spoof Face ID, but it’s a lot easier to do the fingerprint.
For reference, here’s an article (also from Wired) about how they hacked the fingerprint reader: https://www.wired.com/2013/09/iphone-fingerprint-cracked