The Pixel 4’s face unlock works on sleeping people
arstechnica.com
arstechnica.com
You cannot change them, you leave this data everywhere and this data can be snooped and replayed easily.
Moreover, this data is singular for a person - its hard to assign yourself multiple roles or have multiple sets of credentials with different permissions or for different services.
We collectively should stop revolutionizing the access control sphere and use boring scheme with passwords, pins and tokens.
Actually that’d be a cool idea for an auto wipe feature! If you blink a Morris code SOS it should send out a 911 alert with your location and then permanently lock the phone.
Is this still a thing? It sounds decent to me. Most auth usually uses 1 or 2 from the list but rarely all 3.
You'd be in just about the same place if instead of saying "you need biometrics" you said "You need 2 devices".
Even number 2 can be done wrong. 2 Doesn't work if the thing you have is a knowledge based thing. 2 only works if in the case that it responds correctly to a stimulus. Think things like RSA.
You really are categorizing authentication factors by their weaknesses:
- Knowledge factors can be discovered/guessed and duplicated
- Possession factors should protect against guessing and duplication, but can be physically stolen
- Inherence factors should protect against guessing, duplication and physical theft, but cannot be replaced
Writing down a password doesn't make it an effective physical factor, just like embedding an NFC chip in your arm doesn't make it an effective biometric.
Similarly, SMS authentication is not #2. The mapping of your phone number to your phone is not something you possess, it is sitting in some phone company system somewhere and it can be changed.
> MFA
> Definition(s):
> Authentication using two or more different factors to achieve authentication. Factors include: (i) something you know (e.g., password/PIN); (ii) something you have (e.g., cryptographic identification device, token); or (iii) something you are (e.g., biometric). See Authenticator.
> Source(s):
> NIST SP 800-53 Rev. 4 under Multifactor Authentication
They are rather one of the three classes of authentication factors, all of which have fundamental drawbacks. This is why you should always require more than a single class of factor as part of your authentication. For example, mobile devices typically require both physical possession as well as a knowledge or biometric challenge.
Leaving fingerprints on your device is why fingerprints aren't the best factor for mobile devices. Captured biometric data being snooped and replayed is why remote biometrics are weaker than biometrics done locally.
You can have a Web Authentication authenticator (e.g. FIDO 2 key) act as multiple different credentials, all unlocked with the same biometric. Biometrics being tied to a single account (or an account being tied to a single biometric) is an implementation detail, same as having only a single account per email address on a site is today.
A good portion of the revolutionizing is trying to optimize the UX, not authentication. The core fundamentals of authentication have been known for a while, to the point we have government standards such as NIST 800-63b. Of course, some of the revolutionary UX turns out to not implement the fundamentals correctly, because it's the tech industry.
Something you are is the perfect form of authentication.
If you had a guard sitting at a door with only biometric information about the people they’re supposed to let in: faces, fingerprints, DNA samples, voice samples, etc. you could not fool them. Why? Because they can authenticate that the reading is coming from the actual person.
This is the revolution. If your phone can with good enough accuracy determine that it’s looking at a real alive attentive human face or a real finger then it’s game over. It’s an auth cred that can literally only be used by you, it can’t be copied, stolen, hacked, phished, and can be totally public while being useless to an attacker because they can’t mint a live human with real matching fingerprint.
If you think of biometric auth as “present a picture of your fingerprint” and not “present your actual finger” then of course you arrive at the conclusion that they’re useless as a credential.
If knife guy comes for me and says "Your phone and password or your life" I can give it to him. It's kind of important that I can or else he'll take my bloody finger with him and body integrity is way more important to me than any amount of my data.
Literally, I prefer my fingers attached and you can clear my bank account rather than the alternative.
I think relinquishable credentials are quite useful for a number of delegation related uses - but if they are relinquishable then they need to be expirable as well.
You may not be able to give these things but they can be taken, using that knife.
There currently is nothing secret like that that I'd give up my life to protect, and I can't conceive of anything of such import existing... for those cases where the item is truly dangerous (like the nuclear football) then a guy with a knife being a threat is already a failure of security.
Just... biometrics are such a terrible idea - let's not even open that door.
And now, that phones are moving toward face recognition isn’t kind of a moot point?
https://www.iphoneincanada.ca/iphone-5s/will-your-severed-fi...
From a practical standpoint, if someone was willing to cut off your finger, wouldn’t it be easier to just force you a gunpoint to unlock your phone? Someone who really wanted what’s on your phone bad enough to try the “unreliable” hack, would just force you to unlock your phone or give up the password.
Some may feel this is acceptable with the thought if your not guilty then you should have nothing to hide, but this is a fallacy as it tramples over our 4th amendment rights. With passwords locked in your head, you cannot be forced to give that information as that is protected by the 5th amendment. Accessing the device or any information protected by a password must then be done with other means or not admissible as longer delays violates due process.
On the other hand, it was reported in the UK (?) that law enforcement follows around suspects, wait for them to unlock their phone in public and tackle them before they re lock it.
The tactic you mentioned has been used here in the US aswell. Something similar was done to DPR that brought down The Silk Road.
You should be able to answer those yourself. Legal rights are not trumpt by illegal tactics, no matter what information is recovered.
No, but it happens all of the time.
Is any evidence gained through torture admissable?
If the police lie and say the person wasn’t tortured or do you believe that police don’t lie?
Are any law enforcement allowed to use torture to gain access to information?
Yes and police never lie and district attorneys never illegally withhold evidence from the defense....
You’re making a lot of assumptions that police, judges, and district attorneys play by the rules and that overworked public defenders have the time or the will to be great advocates for defenders.
> But at 3:15 p.m., the quiet was broken when, out of nowhere, a young woman in street clothes charged toward Ulbricht yelling, "I'm so sick of you!" and grabbed his laptop. Ulbricht leapt from his seat to grab it back, when the half dozen other readers at nearby tables suddenly lunged for him, pushing him up against a window.
https://www.rollingstone.com/culture/culture-news/dead-end-o...
Though the British police are using it as well:
> Undercover surveillance officers trailed Yew and waited for him to unlock his phone to make a call - thereby disabling the encryption. One officer then rushed in to seize the phone from Yew's hand
If the government will condone torture to get information out of people because of the “War on Terror”, why wouldn’t they do the same for the “War on Drugs”?
Disagree. A bank manger with a gun held to their head is not a bank manager for the intended purposes.
The bank manager is still authentically the bank manager, gun or not.
If we go by your definition login with id and password isn't authentication either. How would we know if the person is "intending to authenticate"!
Because in the other scenario the bank manager can be killed and the murderer can still use the "key" (the bank manager's lifeless face). Dead or alive the bank manager is still that same person.
With a password there's more security for the bank manager. If the robber kills the manager then the robber can't get in.
Biometric auth needs an "under duress" mechanism to be at all comparable.
What??? Of course you could. That's why no building that cares about security actually relies on a human guard for authorization.
1) Can pick up your phone 2) Wants to access your phone 3) Has access to you and your phone as you sleep 4) You don't want to have access to your phone
Bluntly - awaiting an Android update is the least of your problems if you hit the criteria above.
DID YOU KNOW YOUR FINGERPRINTS EXIST WHILST YOU SLEEP?!?!?!!
I'm now considering quitting my job to create lockable-kevlar-mittens the people can don, to ensure your biometrics are safe as you sleep.
Seems reasonable to raise the fact your suspicious sleeping-partner could press your digit to your phone, if they wanted access.
I know we all like a good story, but just taking pixels, I'm unsure how this issue makes your phone less secure than the last one.
Google never actually promised this. From The Verge:
> When reached by The Verge, Google didn’t say one way or the other whether this added layer of security is definitely coming. “We don’t have anything specific to announce regarding future features or timing, but like most of our products, this feature is designed to get better over time with future software updates,” a spokesperson said by email.
Maybe it'll be released, maybe it won't - but we know it's possible and I can't think of a reason google wouldn't add it.
These aren't super common situations but they do happen, and a security flaw like this can be the difference between someone stealing an electronic brick and someone making off with corporate secrets and customer PII (if it's a work phone).
6-year old "Child uses sleeping mom's fingerprints to buy Pokemon gifts" - https://www.cnet.com/news/child-uses-sleeping-moms-fingerpri...
"How A Clever 7-Year-Old Boy Bypassed Touch ID On iPhone 6 Plus" - https://www.redmondpie.com/how-a-clever-7-year-old-boy-bypas...
Those people will literally be able to rest easier when this problem is solved.
>awaiting Android update is the least of your problems if you hit the criteria above.
I am waiting for that Android update, because I have teenage kids
The lack of it is one of the major reasons I'm not upgrading my Pixel 2.
From Mythbusters: https://www.youtube.com/watch?v=MAfAVGES-Yc
"Remember, according to the manufacturer says this lock has never been broken...."
Watch the whole video --- even the photocopy of the fingerprint was sufficient, which was the third (of three) attempted methods.... all of which worked.
On such an expensive phone even.
Snowboarding is basically the reason I assign unique ringtones to different contacts - typically there aren't many contacts that require an urgent response, so if I hear anything other than those urgent contact notification tones from my jacket, I can ignore and continue riding.
I use a ski tracking app, and communicate with my wife and kids while on the hill (we often go on different runs).
Not that Face ID is perfect. When I go to the doctor, they make us wear masks, and I do breathing treatments a few times a day - all of which breaks Face ID.
I assume that the mask covers only a portion of your face; if it's a full-face mask, then obviously this would greatly degrade your device's security by allowing anyone wearing that mask to unlock it. However, I've found that Face ID can do a pretty good job of recognizing you from the nose up.
None of the locking mechanisms I know protect you against all "threat vectors".
In particular, in case a shitty partner wants to access your phone while you are asleep, both fingerprint and google face unlock fail.
I do like the fingerprint sensor on pixel 2.
It could be even better if there was one on the screen for when the phone is on a flat surface, but it does the job well otherwise.
Nevertheless, an easy to use secure enough solution should work well enough against the threat most people worry about : somebody stealing their phone / forgetting it somewhere.
Which is fine. The value of a perfect condition pixel 2 is around 150 $ IIRC
Which is not very high .. BUT you can get a pretty nice first hand phone at this price. So I can understand why its value is way below what I bought it for and tbh I am kind of amazed at the technological marvel that even the shittiest smartphone on earth is.
I have marked the phone as "turns on, screen cracked". Which is accurate. The screen is VERY cracked but if you repair it, you have a perfectly working phone.
Repairing this screen would indeed cost me 150-200 $ .. So far I have decided that it is not worth it.
I get face unlock (because closed eyes and your muscles will be more relaxed), but why does the fingerprint sensor fail while you're asleep? Does it measure heart rate?
Since I live in Chicago and winter is approaching, I think it'll be pretty handy. I'm hoping their radar gesture thing will eventually allow triggering the Google Assistant, and then I can unlock and use most of my phone via voice without taking my gloves off.
I've got that combined with smart lock on the Pixel 3 - it goes a really long way, especially now that I have a smartwatch. (Which admittedly makes the phone assistant a touch redundant, but...)
Also - why not just use "Ok/Hey google"?
Yes. They brand it as "Active Edge" if you want a better google keyword.
He was a little less excited about the feature after that...
Is such a thing possible? My understanding is that IR emission from ordinary objects is primarily determined by their temperature. To imitate the IR signature of a human face, one would need a special-purpose, actively-powered device.
The Pixel 4 removed the fingerprint sensor, relying on the face recognition. I imagine that what happened is that the full functionality wasn't ready for launch, and they had to decide between shipping a partial implementation or postponing the phone's launch date.
1) Delay - yet another year where the pixel doesn't have good facial recognition. During this period all of the OEMs will probably implement some crappy FaceID knock off which will damage Androids image.
2) Bank on in-development facial recognition - Google has lots of talent, they can probably get it done. Risk, they don't get it done.
3) Include both - hardware costs go up, internal size goes up, and people will expect both the next year.
4) Skip facial recognition entirely - Get "left behind". AFAICT people expect facial recognition for unknown reasons. Further, there are several applications of facial scanning that enable non-biometric-security features (anti-features?).
Its easy to see how they chose option two. Sucks it didn't work out.
I don't know how Google weighed it or how they chose their priorities so I can't say whether or not they made the right call at the time (hindsight is 20/20). But based on your list, option 3 is the obvious choice to me.
There's also the question of how long they had from the hardware cutoff date to the software cutoff date - I'd guess many months. Why not allocate more resources to help with the facial recognition software? That project by itself for a company at Google's scale should not take that long. Like I said, this is no longer cutting-edge tech.
I guess we have to agree to disagree, but I think Google really fucked up the Pixel 4 and I bet it was a Product Manager who is responsible.
I worked in consumer electronics before. Your release date is set in stone as you have millions or even billions of € tied in marketing, ads and promotion prepared months in advance to go live on that one date.
You already booked air time on TV and rented billboards worldwide months in advance, you can't delay it on a short notice as airtime would be fully booked and you can't have ads for a product the consumers can't immediately buy.
That's why I left this industry.
Everything was run by marketing people who had no idea of engineering resources and would just promise clients everything to get the sale done and once the ink was dry on the sales contract they'd get a bonus and we'd get the overtime hours to try to implement whatever magical features they promised.
it’s not just electronics, consumer software is like this too…
You can even point it at your face while looking away, and it won’t unlock until you make eye contact.
To me it's like a front door lock. It's there to dissuade people. If someone is adamant enough they will get in.
Apple claims its Touch ID is 5x more secure than a 4 digit passcode[1], based the probability of two fingerprints being the same. They claim that its Face ID is 20x more secure than Touch ID[2], or 1 in 1,000,000, which is similar to the probability of guessing a 6 digit password.
In my opinion, part of a secure implementation is requiring that the user is aware and looking at the device. So the fact that Pixel doesn't take this into account is a huge security flaw.
[1] https://support.apple.com/en-us/HT204587 [2] https://support.apple.com/en-us/HT208108
> Samsung: Anyone's thumbprint can unlock Galaxy S10 phone
beyond someone cloning your face in latex and gluing it on thiers, there is facial excision, and it would be nasty to need caution about someone using your actual face. working hack or not just the attempt is disasterous to the victim
could you just point the phone at a picture of the person? or if depth is needed, just use a projection on a dummy head?
they facial movement pattern could become a sort of biometric and they'd get millions of samples for sentiment analysis / AI
Maybe it's slightly better than a fingerprint unlock. Maybe it's slightly worse. Who cares. It feels like smartphones have moved firmly into the realm of silly marketing features (at the cost of security, apparently) and we've left behind any kind of substantial, interesting advancements. I mean, we now have a radar that let's us skip a song by waving (sometimes, if it works)? The future of smartphones is increasingly dumb.