Appleās new Face ID security for the iPhone X has sparked a number of concerns, with the biggest being how secure the biometric system really is. The tech giant says that while the facial recognition system is intended for convenience rather than absolute security, itās less vulnerable than its Touch ID predecessorāthough testing has shown that the system generally works, but has a number of faults and unexpected behaviors.
Hereās yet another wrinkle for Face ID: Researchers at Vietnamese firm Bkav claim to have been able to defeat the iPhone Xās facial recognition with an elaborate mask made from a combination of 2D and 3D parts. In a video released this weekend, Bkav researchers showed off how the specially constructed face was able to unlock a brand-new device. According to Bkav, their āproof of conceptā was performed without training their iPhone X to recognize components of the mask, just a team memberās face.
The company didnāt specify how many attempts it took them to get past Appleās security, but they did write it cost around $150 for parts, not including a 3D printer. Without clearer video or seeing the experiment replicated, itās tough to know whether itās a genuine break-in.
But assuming Bkavās method really works as advertised, would this be a major security issue for casual users? Probably not. As Bkav explained in their blog post, āIt is quite hard to make the ācorrectā mask without certain knowledge of security. We were able to trick Appleās AI, as mentioned in the writing because we understood how their AI worked and how to bypass it.ā For example, in addition to relying on 2D and 3D printed parts, Bkav also had to recruit an artist to construct the maskās nose by hand. They added the process began āright after receiving [the] iPhone X on Nov 5,ā suggesting it was a complicated effort that took many iterations to achieve the desired result.
As Engadget reported, this is somewhat similar to when European hacker association Chaos Computer Club used a labor-intensive process requiring 2400 DPI photographs of a userās finger and a latex print to fool fingerprint recognition in 2013. Bkavās elaborate Face ID workaround is quite complicated compared to that, which bolsters Appleās claims the new system is more secure than Touch ID.
No security is foolproof, but bypassing Face ID in secrecy via this method generally seems to require a high degree of technical knowledge, time, and effort, not to mention direct access to the iPhone X in question. If someone with all of thoseālike police, spies, hackers, and criminalsāis going after a target, that target should probably not be relying on off-the-shelf consumer-grade security. Additionally, any malicious parties would have a limited window to get into a stolen phone, since Apple has built in various restrictions on how often Face ID can be used alone (such as limits on the length of time or number of failed attempts that can occur before requiring the user to input a passcode).
If the person looking to break in isnāt worried about subtlety, they could just physically force the user to unlock the biometric security anyways, or possibly scan the userās face while they were sleeping or incapacitated. Other slightly more esoteric known vulnerabilities include having the phone unlocked by an identical or near-identical twin.
Either way, the mask method doesnāt invalidate Face IDās utility for users willing to trade a little security for a little convenience. But if youāve got the nuclear codes, Bkav has provided slightly more evidence you shouldnāt rely on face-based security.
Weāve reached out to Bkav for more information, and will update this post if we hear back.
[Engadget]
Vietnamese Firm Bkav Claims to Have Beaten Apple Face ID With an Elaborate Mask
Reviewed by Rizwan
on
11:24āÆPM
Rating:
No comments: