[1] PDF: Paper by Nguyen Minh Duc and Bui Quang Minh from Bach Khoa Internetwork Security Center/Hanoi University of Technology
http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackH...
Pick up phone, hold it out at arm's length in front of you. Hold it real still. Now wait. Bloop bleep boop now it's unlocked!
Compare with:
Pick up phone, swipe your unlock gesture. Hurray!
For something the user is doing constantly, many times, every single... I just don't see why anyone would pick the more uselessly time-consuming (and more effort required) option.
It seems quicker than swiping an unlock code.
Surely you're still going to touch it after you've unlocked it? :-)
Those finger-swipe locks that people seem to be so fond of on my University campus are less secure than decent facial recognition software IMO. Hypothetically I could find a phone left behind in the library and see their passcode pretty clearly in their finger smudges on the screen. Do you remember to wipe your screen clean every time?
Facial recognition will not deter someone who is deliberately targeting you, no. Maybe some combination of facial recognition AND numeric-passcode would be more suitable.
It's still wouldn't be secure, but it'd mean attackers would need a video of you instead of a simple facebook photo.
Main concern would be slowing down the user.
It detects the light conditions via the sensor and auto-flashs you when necessary. Nice while driving at night.
If they chose ROT13 for encrypting user data, would you say "It's a limitation/drawback of ROT13. I would not consider it as Google's fault to use it"?