I just don't like the fact that my face becomes a password. I'm usually not in a position to _obscure_ my face, so I have no chances to decide if my face should act as a password in any given moment or not.
So, if you hold the phone up to my face, and I look at it, it just unlocks. That's the opposite of "security."
https://www.bbc.com/news/articles/c0kl4glp547o (bbc news article about it)
Attention awareness does not stop alarms, and it requires your eyes to be open and looking at the phone.
Attention awareness silences/drasticly reduces the volume of alarms, that's how it is designed.
If they have a bug in the attention awareness feature it stands to reason that it could not require your eyes to be open or looking at the device in question at the time.
[1] https://www.phonearena.com/news/court-ruling-cops-can-force-...
https://clcjbooks.rutgers.edu/books/why-torture-doesnt-work-...
I’m not sure what is the privacy risk there. The apps that authenticate you don’t have access to biometric data.
The main risk I see is if that data was compromised and made available for something else, but I haven’t seen any breach of that that ended up being useful for anything?
Or maybe I missed something?
* These days, I'd assume when, not if.
if you get involved with the wrong/right sort of people, they might do it for you
But really, I don't need a reason other than I'm uncomfortable with it. I worry about people who are comfortable with it..
I personally oppose all forms of biometrics for security, as it can neither be invalidated, nor is it safe from physical coercion. I also oppose biometric use for "tracking attention" because it's none of anybody's business but mine.
While I consider your example valid in a vacuum, it poses a substantial privacy and financial risk in the real world. If a car that tracks attention also phones home, your insurance carrier may raise your rates or cancel your plan for occasional glances away (sneezes, children, etc), regardless of an actual problem on the road. Such measures ought to only exist locally within a car, but I have absolutely no faith that it will be implemented that way given the current data shared along those lines.
And that is a completely different issue. The OP just wants to prevent that type of thing when they can.
If I walked up to several individuals (maybe even you) on the street with a camera and tried to take a close-up, a lot of them would object. I don't think "why not let me take it, it's already online someplace" would be a convincing reason to allow it.
In many jurisdictions including where I live in, taking pictures at public places is allowed by law whether or not some other human happens to be in the frame of my picture. It is called "incidental inclusion".
Others can request me to exclude them from my picture but they can only request, they cannot force me to do so. Of course, if someone asked, I am going to be nice to them and try and exclude them from the picture. Others could also try and move a bit this way or that way so that they don't get included in my picture. We live in a society and we can work it out.
In reality though, nobody makes such a request because most people know the law and they know that if they are out there in the public, they could become part of other pictures by incidental inclusion.
I might break your phone. How difficult would it be to sue me and for what purpose?
> I might break your phone. How difficult would it be to sue me and for what purpose?
Easily. Damaging someone else's property is not even remotely on the same level as taking a photo of someone? How do I know it wasn't their _job_ to do so?
Honestly if you think that level of escalation is okay I hope to never meet you in person.
And trust me I find people taking photos of me creepy also but it's easier to block my face myself than to smash the person's device and expect to walk away.
Then it is not assault. See? The problems already started. The best you can get after an ardous process is an apology and a reinboursement, the worst would be it coming back at you.
Where I live, they recently declared gazing at a woman "indecently" as a small sexual crime, same as unrequested flirtatious comments to strangers. I have grabbed phones before, but I admit I haven't broken any. YMMV
Correct! I don't see where I implied otherwise!
You are missing the point.
>those sensors are still pointing at your face
some phones have a popup front camera. The camera is inside the phone. It is obscured and it would be alarming if it pop up on its own accord.
This just sounds like textbook paranoia to me (as in, the actual dictionary definition as an illogical fear that impedes your normal life), because there's nothing reasonable about thinking FaceID is compromised to the point that you have increased your personal safety by not using it.
I don't agree with the premise that disabling bio-metric security impedes a normal life. Nor has OP given me any reason to believe they are afraid of it in the situations you described.
Passwords and pass codes (when managed well) are perfectly normal security tools to use to ensure your privacy on a device you own.
Maybe we should do something about this rather than being defeatist and giving up on privacy.
I have the legal right to ‘analyze your face’ if you are out in public. Why do you believe that there’s something special about a highly secured, on device FaceID capture that makes it more dangerous than a guy with a camera across the street?
Is this true? I mean, you can't really show an iPhone a photo of your face to unlock it, can you? Or are you thinking of a different attack vector?
My second objection is to the possibility of physical injury to me by someone that really wants to steal my credentials.
This possibility exists even if your creds are something you know. It also exists if your creds are something you have, and you happen to have them on your person.
If you have the information that the iPhone wants to see, it is possible to create a synthetic face matching that data and hold it up in front of the phone.[1] You could also probably open up the phone and hotwire the sensors to give the hardened processor holding your Face ID data the readings it wants.
Both of these things are super difficult to do, and much further out of reach of your average thief than simply printing out a picture of the person's face, but the point remains that it is theoretically possible.
[1] Bkav Corporation has made masks that can fool Face ID for about $150: https://www.pcmag.com/news/researchers-claim-they-can-dupe-i... https://www.bkav.com/top-new/-/view-content/65202/bkav-s-new...
I can hand over my credentials or secrets to a thief without injury to myself, but I can't safely hand myself over, or a piece of me.
And the day some manufacturer's database with 1.8 billion sets of facial data is going to get hacked and exposed, I'll feel pretty smug about it.
all the on-device stuff was just to ease the tech literati who probably is still 12 years away from being impacted by the actual tech doing the damage, since those are for the poor and foreigners first
If talking with AI becomes more mainstream, face detection will (at first) make the experience better.
https://www.theguardian.com/technology/2016/jun/22/mark-zuck...
Here in the UK face ID is pretty common place so I must admit my phone having this data is probably the least of my concerns. For example, one guy I know can't buy his own groceries anymore because he stole some food products from one of our major supermarkets, and since all major supermarkets in the UK have linked facial id systems he's now effectively banned from all supermarkets lmao.
IMO, the issues surrounding biometrics stem from the fact that they define you, in a way that nothing else - not a name, not an address - can.
try to buy an africel (usaid sponsored telecom in Africa) without showing up in person for a face scan.
you're all to sheltered and will have no idea what hit you in the near future