Breaking Into Android Phones with a 3D-Printed Head
forbes.com
forbes.com
I have a friend whose startup cared was doing a surgical product; after I told him my story he called up a bunch of plastic surgeons and went and observed a bunch of them.
Both of us were interested in workflow; the actual science we had done on animals of course, but our research was aimed at seeing if the product would be viable (could be medically wonderful but if the doctors don't care they won't use it on the patients, even if it improves outcome).
I don't think we could have done this at a hospital, but given that it was surgery (surgeons have a lot of freedom) perhaps we could have.
I had that happen to me, but it wasn't my face where the excision happened, or that was photographed, so it may really be standard procedure. My guess is so that in follow-up examinations it can be determined if any remnants remain and/or spread.
But my incident was about 20 years ago. Today I would be very suspicious, like you are.
Sounds ok to me, at least in the weird arithmetic of this tired talking point that invariable makes an appearance every time the subject is discussed, usually in a tone of letting us in on some great, newly discovered revelation.
Yes, “something you have + something you know” is more secure, but security is not a binary thing, and people’s real world behaviors need to be accounted for.
Before biometric authentication was available in cell phones, I had no passcode at all. My device’s security was just the physical security of the device itself. Constantly entering a passcode was just too much hassle, let alone a proper high-strength passcode. Moving to biometric authentication massively improved my security. Lots of people I know were in the same boat, or maybe had a four-digit passcode equal to their birthday and/or ATM PIN.
It’s not foolproof but it’s good enough for almost everyone.
Well, biometrics may be better than an a third-party email address in some cases (harder to lose throguht third-party action), but often worse than a first-party email address (e.g., Gmail for a Google account) or a nickname, for the same consideration.
Therefore, biometrics can conceivably be useful if used cautiously on a single device or a well-secured local network. As soon as you start sending them over the public internet or anywhere else that it's possible for a hacker to intercept, all advantage is lost.
I've been hearing the exact same arguments against biometrics in every thread on the topic long before Apple even did biometrics.
To wit: "[..] four Android models and an iPhone X.
Bad news if you’re an Android user: all four phones unlocked with the 3D printed head."
It seems like you could render the 3D model of the head on a monitor and point the phone's camera at the monitor. If the phone needs to see some sort of parallax change relative to its own motion (from internal sensors), then one could put a 6-DOF tracker onto the phone and use it to update the rendered viewpoint of the head (a form of user perspective rendering).
Such an approach would be quite useful for law enforcement to gain access with much less time waiting for printing.
Actually it might be possible to hack if your screen could output IR wavelengths.
[1] http://spie.org/newsroom/faces-light-up-over-vcsel-prospects...
>To detect whether there is something in front of the iPhone X, it is believed that the phone uses a "time-of-flight" (TOF) sensor, powered by an LED-based infrared illuminator... If the TOF sensor detects an object, it triggers the iPhone X's True Depth camera to take a picture. If that reveals a face, the phone activates its dot projector, shining a single infrared VCSEL through an optical system to create 30,000 spots while its infrared camera captures an image. It sends both regular and spottily illuminated IR face images to an application-processing unit (APU) that can recognize the owner and therefore unlock the phone.
There are definitely follow-up enhancements that could be investigated, some of which are likely to get past iPhone's checks too.
Seems like an interesting challenge to create a heated fake head.
I guess you could see temperatures, but you’d have to point it at something almost hot enough to emit visible light. For normal face temperatures you’d need something sensitive to far IR.
It’s really precise 3D with a greyscale non-thermal IR image. Could be inaccurate masks? Missing details around the eyes and mouth and other important areas? Do masks have eyes with a discernable gaze direction? Do they have microexpressions or natural facial deformation? Do the eyes move?
There’s a buttload of stuff they could be measuring that is insanely hard to replicate with a mask. Besides, a thermal map would be pretty much useless even if the hardware was capable of thermal imaging. Skin temperature varies a lot (and not always uniformly) based on ambient conditions, physical exertion, being sick, sitting in direct sunlight, etc, etc.
It could also be looking at small changes like the periodic flushing that happens (see [0]). Though I'm not sure how well that would work on a moving phone but it could work I think just at a broader scale. FaceID is really fast though so not certain there's enough time to gather the data for that either.
Edit: changed 'circumvented' to 'fooled'
Grant does a heck of a double-take, though, at one point. It is a fun episode so I won’t spoil it.
Some companies have massive annotated databases of people's faces from different angles, and the ability to do plausible 3D reconstruction of the faces.
No, the passcode might be in your head, but if someone sees you in a CCTV entering the passcode, it's not only there anymore.
Although the user is definitely compromising on security, the speed of face unlock is such that it is near-instantaneous. Double tap the display, and you don't even have to blink - the phone unlocks.
It may be a gimmick in the early days of Android (think Nougat or even Oreo), but it's definitely not a gimmick now, for me at least. It's fast enough to have proved its worth.
Please submit the original source to HN!
Forbes links seem to have a poor rep on HN because they are mostly poor blog entires that could have been on medium. The one you posted was an exception.
That might have been a compelling reason to actually buy one.
I have found many compelling reasons to buy the watch even though it can't unlock my phone. It can unlock my computer, but it's not much of a revelation, it's not that hard to type in my password quickly on a physical keyboard.
You could further make it so that the phone would lock if unlocked by the watch, and it was removed from the immediate vicinity of the watch or the watch was removed from your wrist.
Now where is it going to be easier to enter a good, secure, password? A six inch phone? Or on a tiny watch screen?
It would be nice if my watch could unlock my phone I guess. But I have a hard time seeing how it would be more secure than the reverse that’s currently true.
At least until we get “WristID” that uses the pattern of blood vessels under where my watch sits on my wrist.
Basically the workflow could be "type password into phone after putting on watch, to unlock, then things just work until you take off the watch".