HNHacker News
TopNewBestAskShowJobs

emilxix

23 karma · joined July 4, 2016

submissionscomments
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
HN, we want to address all the questions and concerns that have been brought up here. To do that effectively, are compiling a list of all of them and will be answering them live during an online event. If you are interested, RSVP here: https://forms.gle/ZWsiswJGLdLqaAoK7

Tentative agenda: Overview of the product

     - what is it, how it works
     - deep dive in tech 
     - security
     - comparison to other solutions
- Addressing individual concerns from HN comments

- Q&A

emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
As I've mentioned earlier, we will be publishing in-depth results soon. Meanwhile, you can read here the review of public datasets https://medium.com/xix-ai/quantifying-the-inherent-bias-in-m... Overview on adversarial examples is below. The upcoming post will cover the approach, performance and comparison. Stay tuned
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
Sorry, you feel this way, mate, but matters of "believe" are between you and your priest.

As for the "overall impressions", It is usually recommended to try something first and then form an impression. Otherwise, it's just an opinion

emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
That's great. It means that the subset of all users you've measured had their phones unlocked, next to the computer, and ready to click push notification
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
Got it. Let me share with you our experience, and please take it with a grain of salt.

Early on, we've conducted a handful of end-user interviews - knowledge workers, various industries, fluent with computers. We conducted a series of hour-long video calls, recorded them with permission to re-watch them later, and asked the questions like - how do you think about privacy? How do you think about the performance of faceID or similar? How do you think about biometrics and privacy? Will you be open to try a solution that uses your biometrics from an unknown vendor? Etc.

The result, somewhat surprisingly, boiled down to a few bullet points: 1. Performance- "If it works and I can log in, that's enough assurance." 2. Privacy and data - "Have an FAQ section or show in me onboarding that you don't sell my data for surveillance - that's good for me."

We've been prepared to answer the "SOC 2 Type2 -style" question regarding performance and data privacy, but no one really cared. What users did care about is "can I add this app to my account?" and other feature requests.

emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
Communicating assurance is challenging. Finding a balance between "FAR/FMR/FNMR metrics" and "it's safe to use" is an art. Apple's faceID. for example, claims "1:1,000,000 chance a random person can unlock an iPhone", which, I guess, is a good enough proxy to communicate assurance for the intended audience. Answering the question, yes we thought about it, but still a work in progress.
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
thank you for sharing your thoughts.

-> Fingerprints are just more convenient. Apple, for example, argued the false positive rate way too high. For me, as a user, I'm more concerned about the false-negative rate. I think Apple just wanted more screen real estate. They could've easily put the sensor on the back (eg like the Samsung Galaxy S8).

I agree, a matter of fact fingerprint sensor on the back of a phone is arguably the most efficient way to unlock a phone. With desktops, it varies quite significantly.

-> - Masks!

for what its worth, one user told us that they have successfully logged in while having a green mint facial care mask on..:)

-//-

By no means Entry is the best tool out there, nor we claim it to be so. Here are a few known flaws:

- if someone has two or three monitors and it is unclear where the camera is, it requires some time to get used to, which may be annoying - to your point, Entry will not work in a pitch-black room - Entry is by no means "fingerprints-fast": as a factor, Entry competes with the time it takes to reach a phone and click on push notification. For example, mean time to verify using Okta Verify (default mfa solution for okta sso) is ~21 seconds. For Entry it's 30 seconds. We still need to work on that (although our users still choose Entry over Verify, we ask to have both factors set up :) )

emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
Several layers of anti-spoofing.

They detect mask-attacks, replay attacks (put the phone with video into the camera; highjack a webcam input and send a pre-recorded video faking to be real-time from zoom for example), and, of course, still images.

Give it a try!

emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
Yes, you are right. To be clear, the pricing on the website is for the workforce identity (Entry as a factor to a Single Sign-on solution). If you are thinking about customer identity, we don't have pricing yet. Most likely, it will be volume-based. It would be great to brainstorm with you and come up with something that makes sense!
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
right, adversarial attacks are tricky, we wrote about it a while ago - https://blog.ycombinator.com/how-adversarial-attacks-work/

In reality, the production-grade security comes from a compound effect of three components: face-recognition, antispoofing for face recognition, and traditional controls of industry-standard protocols like SAML 2.0, OIDC, etc. Taking one of three out of the equation renders security nonexistent.

emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
Entry was designed to protect end-user privacy against malicious actions in the first place. Not just because we want to "do good", but also because it is commercially viable: End-users get full control of their data forever free, while organizations deploy Entry to solve tactical issues like fraud, security, and phishing prevention. But, I guess, without an independent audit by "the big four" or alike, these are just my words.
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
thanks for posting it here. It is still too high-level. We'd be publishing in-depth details soon.
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
good catch, I've fat fingered it while editing the comment
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
Absolutely, that's on the product map. KYC/AML and document verification use cases are super exciting but require some thoughtfulness around regulations. Sometimes it is easier to solve a hard technical problem than to navigate compliance requirements.
emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
That's right, successfully preventing spoofing attacks using 2D input is an extremely hard problem to solve. We've spent two years working on it. We published a high-level overview here - https://getxix.com/learn and plan to publish a deep-dive overview of the approach in the coming weeks.

For SSO, Entry can be added as SAML 2.0 Factor today. I agree if we would not have solved the spoofing problem, taking the Auth0-style route for native platforms is the way to go.

emilxix··on Launch HN: Xix.ai (YC W17) – Securely authenticate in web apps by face
thank you. You are right, Webauthn taps into SDKs of platforms like iOS, Windows Hello, google's version of android. They use infra-red depth perception sensors to create a mesh of the user's face as ID and store it on the device's secure enclave. It can only be accessed and used on that device. For that reason, Apple users have to set up fingerprints separately on iPhones and Macs. The same will be for FaceIDs on the new-gen of Macs - users will be setting it up separately on different devices. We instead store biometrics in the cloud so it is not tied to a specific device.