Breaking into a locked iPhone X shouldn't ever be described as simple, but according to a group of security researchers, that's exactly where we find ourselves.
The same Vietnamese team that managed to trick Face ID with an elaborately constructed mask now says it has found a way to create a replicated face capable of unlocking Apple's latest and greatest biometric using a series of surreptitiously snagged photographs.
SEE ALSO: No one agrees on whether or not a dead body will unlock a smartphoneApple has copped to the fact that Face ID, for all its technical prowess, isn't perfect. It can be tricked by twins. For most people, however, that security threat is a nonexistent one. But what about masks? The Cupertino-based company assured customers that it had designed the biometric-powered safeguard with that attack in mind — yet the researchers at Bkav are here to rain on that particular parade.
"These materials and tools are casual for anyone."
They built a relatively inexpensive mask which, according to a blog post and video demonstration, was able to fool Face ID into unlocking.
"In this new experiment, Bkav used a 3D mask (which costs ~200 USD), made of stone powder, with glued 2D images of the eyes," researchers explained in a blog post. "Bkav experts found out that stone powder can replace paper tape (used in previous mask) to trick Face ID AI at higher scores. The eyes are printed infrared images — the same technology that Face ID itself uses to detect facial image. These materials and tools are casual for anyone."
To make matters worse, getting the data needed to construct the mask could be done without the target's knowledge, the researchers wrote — no elaborate face scans or up-close photographs required.
"Bkav researchers said that making 3D model is very simple," the blog post noted. "A person can be secretly taken photos of in just a few seconds when entering a room containing a pre-setup system of cameras located at different angles. Then, the photos will be processed by algorithms to make a 3D object."
Just how easy would it be for someone to pull this off in the real world? We reached out to Apple for comment, but received no response as of press time. We'll update this post when and if we hear back.
The researchers at Bkav, on the other hand, did get back to us, and their comments didn't inspire much confidence in Face ID's security.
"[When] targeting a person, [an attacker] can pre-install HD cameras of 3D scanning system in a meeting room or in an exhibition to secretly take photos of the target," explained a company spokesperson over email. "It takes only around 2s to get photos of the target’s face. Very fast."
As for making the mask itself? "[We] printed only one 3D mask, only one infrared image," the spokesperson noted. "We cut the eyes’ parts and pasted them on the mask, only one time. We succeeded at first try. There was no modification needed."
Should iPhone X owners be worried about this? Well, maybe. It's not like a common thief is going to go to the trouble of surreptitiously scanning your face before (or after) he's jacked your phone from you on your subway commute.
However, if someone wanted access to a specific something on your phone — and felt that it was worth the time and effort of building a mask — you might have a reason to be concerned. Although, of course, using an alphanumeric password in lieu of Face ID would negate that concern.
If anything, Bkav's findings are a reminder that no form of consumer biometric is infallible, and that as security improves, so do the tools and techniques hackers use to beat it.
This story has been updated to include additional comments from Bkav.
Copyright © 2023 Powered by
Face ID has been defeated again, and this time it was 'simple'-铁板歌喉网
sitemap
文章
4
浏览
94
获赞
2256
The best viral videos of 2019
Can you believe that2019 is finally coming to an end? These days it seems like the internet meme macPS5 accessories on sale: $50 DualSense controllers, Sony INZONE headsets up to $70 off
TL;DR:Need some new peripherals for your PS5? PlayStation DualSense wireless controllers (now $49.993 tips for using Google Maps more effectively, according to Google
I'm the kind of person who would get lost going down the street if it weren't for my phone having suWe read X's new privacy policy so you don't have to
Twitter - excuse us, X - has a new privacy policy. It's a long, boring read. But we've done the workDavid Attenborough is teaching online geography lessons to kids at home
Children all over the world are adapting to a new way of learning as schools closed due to the new cTwitter implements DM limit for unverified users
Last week, Twitter changed its DM settings so users only receive messages from verified users (whichNASA telescope discovers a bizarre, half
Scientists have discovered a world that is almost identical in size to Earth, with a star almost ideFormer Neuralink employee alleges Musk wasn't telling the truth about test monkey deaths
On the same day Elon Musk announcedthat his brain implant device company Neuralink is preparing forThe COVID tech that dominated CES 2021
With virtual booths and digital portals taking the place of convention center halls and showcases, CFormer Neuralink employee alleges Musk wasn't telling the truth about test monkey deaths
On the same day Elon Musk announcedthat his brain implant device company Neuralink is preparing forIs Friend.tech, the crypto social media app, a scam?
Remember when we were inundated with crypto commercials starring Matt Damon, major sports league spoNASA's car
Ancient Mars wasn't simply just wet. It experienced momentous floods. As clear evidence of this wateApple is giving its digital assistant Siri a much
It looks like Apple is finally acknowledging that Siri's default female voice isn't a good look. AccNASA telescope discovers a bizarre, half
Scientists have discovered a world that is almost identical in size to Earth, with a star almost ideNintendo Switch successor could launch next year
Don't look now, but the Nintendo Switch is more than six years old.That's relevant because, in the w