Security

iPhone X’s Face ID raises security and privacy questions

Comment

The new top-of-the-range iPhone does away with the home button and its built-in fingerprint reader in favor of a new biometric — called Face ID — which uses a 3D scan of the user’s face for authenticating and unlocking their device. It also replaces Touch ID for Apple Pay too.

Apple suggests this is an advancement over a fingerprint reader because it’s an easier and more natural action for the user to perform — you just look at the phone and it unlocks; no need to worry if you have wet fingers and so on. Apple is working the convenience angle hard.

However offering to gate the smorgasbord of personal content that lives on a smartphone behind a face biometric inevitably raises lots of security questions.

And of course there’s already a mountain of high-pitched Twitter chatter on the topic, including speculation about whether the face of someone who is dead or sleeping, or otherwise unwilling to unlock their device in your presence, could be used to do so against their will.

This is exacerbated by existing face unlock systems on smartphones having a dire reputation.

A different facial recognition unlock feature used by Samsung has, for example, been shown to be fooled with just a photo of the face in question — making it laughably insecure in a digital era where selfies are traded publicly as the standard social communication currency…

Not to single Samsung out here. Android had a face unlock feature that could be just as easily spoofed way back in 2011. Even a subsequent version of Android Face Unlock, which required users to blink before it would unlock and give up its secrets, was shown to be conquerable with a sly bit of photoshopping.

However it’s clear that Apple has packed in both a lot more hardcore technology and a lot more thought to try to put its implementation of facial biometrics on a more solid footing.

The iPhone X’s camera is not just looking for a 2D image of a face; the sensor-packed notch at the top of the device includes a dot projector, flood illuminator and infrared camera, as well as a traditional camera lens, so it’s able to sense depth and read face-shape (including in the dark).

As we wrote yesterday, it’s essentially an Xbox Kinect miniaturized and put on the front of your phone. Ergo, Face ID would interpret a photo of a face as a flat surface — and therefore not actually a face.

Although the proof of the pudding will be in the eating, as they say.

There was a brief on-stage demo fail when an iPhone X apparently failed to identify Craig Federighi’s face, and therefore wouldn’t unlock — displaying the other potential problem here, given that a tech that’s too unyielding in opening up to its owner may be highly secure but it won’t be at all convenient.

The Apple exec’s first reaction at being unexpectedly locked out appeared to be to wipe sweat from under his eyes — suggesting the sensors may be confused by shine. We’ll have to wait and see.

Face ID needs your attention

Yesterday, Apple showed how the iPhone X user has to record a 3D scan of their face from multiple angles, with the interface asking them to tilt and turn their head to enroll the biometric.

The biometric is of course stored locally, in the secure enclave, so it does not leave the device.

Apple also revealed that it’s created neural networks to mathematically model faces so that the tech can be smart enough to adapt to the changing landscape and aspects of a person’s face — such as if they start wearing glasses, or get a new hairstyle, put on a scarf or grow a beard (less clear: Whether it works if a user is wearing a fuller face covering) — apparently training their model with more than a billion images of faces from around the world.

The risk of bias in the training data here is obvious. But Apple at least sounds confident that it’s nailed the technology, claiming the overall risk of another person being able to unlock someone’s device is 1 in one million.

It also said Face ID cannot be fooled by photographs of faces, and noted testing the system against face masks — seeming confident that even a photorealistic face mask won’t fool it, likely on account of the infrared sensor. (Though one wonders whether a heated silicone face mask might not do the trick… )

It did confirm that Face ID does get confused by identical twins, as you’d expect.

More interestingly, Apple said that Face ID needs “your attention” — specifying that means a user’s eyes have to be open and on the device for Face ID to work. So it appears it will require some kind of user interaction to successfully unlock it, not just for the face to be in the sensors’ line of sight.

This is one of the most interesting unknowns here.

Demos of Face ID yesterday in Cupertino were locked to Apple staff, so we haven’t yet had the chance to freely play and test its parameters. But TechCrunchers who were in Cupertino suggested it was not that easy to trigger Face ID, and that a person would only have to screw up their eyes for it not to work.

Again, though, it’s unclear how much and how active a user’s ocular attention needs to be for the device’s virtual padlock to pop open.

Could someone pry open a sleeping or deceased person’s eyeball to pass muster with Face ID? Or do eyes have to be seen to move — and to move willingly — towards the phone before it will unlock?

What about if you sweep your eyes intentionally elsewhere to try to avoid looking at the device? Will the phone read that as your attention being willingly averted?

We don’t know yet. Testing this phone is going to be fun for sure.

But forcing someone to put a finger on a phone screen seems at least theoretically easier than compelling a person to open their eyes and look a particular way if they don’t want to. So you could argue that Face ID is a slight step up on Apple’s Touch ID fingerprint biometric.

Albeit, that might also depend on how much time you have on your hands to try to trick the iPhone X user into looking at their phone. Or how much force you’re willing to expend…

https://twitter.com/shanerichmond/status/907695795029377024

Safe to say, a lot rides on how Apple is interpreting and reading the user’s gaze.

But even if Cupertino’s engineers have designed this aspect of the tech in a very thoughtful and highly attention-tuned way, there’s no getting away from the fact that biometric security tends to make security experts uncomfortable.

Biometrics vs passcodes

And with good and multiple reasons. Not least the salient fact that you can’t change a biometric if that highly detailed 3D scan of your face, say, happens to leak.

Biometrics are also less secure than using a (strong) passcode. Though of course a poorly chosen passcode is a security nightmare. (Apple offers multiple options for iOS passcodes — default requiring a six-digit passcode, but also supporting longer strings of letters and numbers if a user chooses. Though it also lets users revert to a four-digit passcode if they really want to.)

Security is, as ever, a spectrum. And consumer-grade biometrics sit pretty low down the ladder — best used in combination with additional, more robust measures in multi-factor authentication scenarios. If you’re going to deploy them at all.

Passcodes and passwords have another advantage over biometrics too — in that they appear to offer more legal safeguards against state agents forcibly unlocking a device against an owner’s will.

In early 2016, Forbes found what it described as the first known case of a warrant being used to compel an iPhone owner to unlock their device with their biometric information — in that case using the Touch ID fingerprint biometric on an iPhone which had been seized by police.

While, in a landmark ruling in 2014, a U.S. judge said that while a defendant could not be forced to hand over a passcode they could be made to provide their biometric information to unlock their device.

Device security at borders has also become a matter of growing concern under the current U.S. administration — which has shown an appetite to expand Homeland Security’s powers to being able to demand passwords off visitors.

And while legislation is being proposed to outlaw such extralegal intrusions, it’s not clear whether forced unlocking of devices based on requiring a person to apply their biometric information might not present a continued loophole for border agents to go on accessing the content of devices without a warrant.

So there could be a wider risk attached to Apple encouraging people to adopt facial biometrics if overreaching state agents are able to use the tech as a route for circumventing individuals’ rights.

That said, the company has evidently been thinking about ways to mitigate this risk — adding a feature to iOS 11 that lets users quickly disable Touch ID, via an SOS mode than can be triggered to require the full passcode.

It has been confirmed there will be a similar shortcut to quickly disable Face ID, too.

In iOS 11, the passcode will also be specifically required to be entered before any data can be pulled off a device — limiting searches of unlocked devices at borders to agents being able to manually sift through contents there and then, rather than giving them unfettered access and the ability to easily download all the data.

Looking at how Apple is deploying a facial biometric within a wider security system is key.

If it was pushing Face ID as a complete replacement for a passcode that would indeed be irresponsible.

But, at the end of the day, it’s offering the tech as an option for users who want added usability convenience, while also providing a fallback of stronger security safeguards that can be invoked or can step in to gate content at key moments.

For a mainstream consumer player like Apple that looks — at this untested stage of the Face ID feature — to be a fairly thoughtful approach to the age-old security vs convenience problem.

There is another, wider concern here too, though.

Always watching me

Human faces inherently contain a wealth of personal information — from physical identity and features, to gender and ethnicity, mood/emotional state, even an approximation of age. A face could even indicate sexuality, if recent research is to be believed.

So technologies that normalize mass scanning of facial features do inexorably push in an anti-privacy direction — carrying the uncomfortable risk of misuse.

And it’s clear that for Face ID to function at least some of the iPhone X’s sensors will need to be always on, scanning for potential faces.

Which means it could be gathering very sensitive data without users being aware.

Face ID therefore opens a potential conduit for users to be surreptitiously spied on, say by scanning their faces to try to determine how happy or otherwise they look when contemplating a particular bit of on-screen content; or even to glean insights about the domestic context of the device owner, such as by identifying and counting multiple different faces in the same location to estimate family size.

And even if only some of the sensors that are in play on the iPhone X powering Face ID are always on, some of this hardware and software has to be continuously watching, no matter where you are, who you’re with, what you’re doing…

Remember, people carry smartphones with them, on their person, everywhere they go — even from room to room within their own home. So while the Amazon Echo Look proposes to view you in your bedroom, the iPhone X has no such restrictions on the places it can watch you.

How third parties with apps on the iOS platform will be allowed to access the iPhone X’s camera and sensor hardware is a key consideration. It doesn’t take much imagination to consider what a data gathering behemoth like Facebook might like to do with this kind of technology — even if it can only make use of it when its own app is open and running on the device.

And it’s not yet clear whether or what kind of controls Apple might put in place to limit how app makers are able to access the X’s face scanning capabilities (yes, we’re asking). But the fact the hardware has been created and will soon be pushed out — doubtless promoted with the help of millions of Apple marketing dollars — already represents the next wave of tech-fueled privacy erosion.

So while smartphone technology has taught us to be accustomed to being continuously disturbed by digital prods and pings, at any and all times of the day or night — to the point of mobile OSes including a ‘do not disturb’ setting to manually switch off intrusions we otherwise now expect — Apple’s championing of facial recognition technology positions face-scanning and face-reading to become the new normal.

And from facial recognition for identity and authentication it’s but a small step to ushering in even more personally intrusive technology systems — like emotion-tracking timestamped against the content you’re browsing. As just one off-the-top-of-my-head example.

Perhaps future smartphones will come with a new type of underused control-toggle in the settings menu — which simply states: ‘Stop watching me.’

More TechCrunch

In September, California Governor Gavin Newsom considered 38 AI-related bills, including the highly contentious SB 1047, which the state’s legislature sent to his desk for final approval. He vetoed SB…

Here is what’s illegal under California’s 18 (and counting) new AI laws

California Governor Gavin Newsom has vetoed SB 1047, a high-profile bill that would have regulated the development of AI. The bill was authored by State Senator Scott Wiener and would…

Gov. Newsom vetoes California’s controversial AI bill, SB 1047

A number of YouTube videos featuring music from artists such as Adele, Green Day, Bob Dylan, Nirvana, and R.E.M. have been unplayable in the United States since Saturday. For example,…

YouTube blocks videos from Adele, Green Day, Bob Dylan, others in dispute with SESAC

Kevin Ryan has had a long and storied career as a pivotal force of New York City tech. He’s the founder and CEO of investment firm AlleyCorp, which has invested…

New York tech investor and serial entrepreneur Kevin Ryan explains when to sell your company

Featured Article

Elastic founder on returning to open source four years after going proprietary

Licensing kerfuffles have long been a defining facet of the commercial open source space. Some of the biggest vendors have switched to a more restrictive “copyleft” license, as Grafana and Element have done, or gone full proprietary, as HashiCorp did last year with Terraform. But one $8 billion company has…

Elastic founder on returning to open source four years after going proprietary

This week, Alex Goldman shares his setup. A former producer for WYNC’s On the Media, Goldman co-founded Reply-All with Emmanuel Dzotsi in 2014.

How I Podcast: Hyperfixed’s Alex Goldman

The Pixel 9 Pro Fold is back, bigger and better than before, with a thinner design and excellent tri-camera system.

Google Pixel 9 Pro Fold: Bigger, mostly better

Featured Article

In war-torn Sudan, a displaced startup incubator returns to fuel innovation

Businesses need stability to thrive. Unfortunately for anyone in Sudan, stability has been hard to come by for the past year and a half as the country quakes amidst a raging civil war. More than 20,000 people have been killed, and about 7.7 million people have been displaced just within…

In war-torn Sudan, a displaced startup incubator returns to fuel innovation

X (formerly Twitter) could soon resume service in Brazil — if it’s willing to pay an additional fine. Reuters and other publications have reported on an order from the country’s…

X faces additional $1.9M fine to end ban in Brazil

Meta Connect 2024 was this week, showcasing new hardware and software to support two of the company’s big ambitions: AI and the metaverse. CEO Mark Zuckerberg announced new Quest headsets,…

Meta rethinks smart glasses with Orion

Amazon Prime Video could be getting into the live news business, if only for one night. Variety reports that the company is in talks with longtime NBC and MSNBC news…

Brian Williams might host a live election night special for Amazon

Apple faces a looming deadline to produce what it says are more than 1 million documents related to recent App Store changes. On Friday, Judge Thomas S. Hixson denied the…

Judge is unimpressed by Apple’s deadline extension request in Epic Games dispute

For years, Silicon Valley and Wall Street have questioned Mark Zuckerberg’s decision to invest tens of billions of dollars into Reality Labs. This week, Meta’s wearables division unveiled a prototype…

Meta offers a glimpse through its supposed iPhone killer: Orion

When the U.S. Feds cut interest rates by half a percentage point last week, it was a dash of good news for venture capitalists backing one particularly beleaguered class of…

VCs expect a surge in startups offering lower rate mortgages, other loans now that the Feds cut rates

The video debuted along with a research paper of the same name at IEEE’s International Conference on Robotics and Automation in Rotterdam this week.

Robot hand can detach from arm, crawl over to objects, and pick them up

There are many iPad apps to help you organize recipes; sync tasks across devices; be more productive; and manage your notes.

Best iPad apps to boost productivity and make your life easier

While online discourse would make it seem that venture has retreated to the Bay Area, with San Francisco being the most important place to build a startup, Index Ventures is…

Why Index Ventures is bulking up its investment team in NYC

In August, a Russian warlord posted a video on Telegram, showing a pair of Cybertrucks patrolling a road in Chechnya, armed seemingly with heavy machine guns. Leaving aside unanswerable (for…

A Russian warlord said he’ll take Cybertrucks into Ukraine; some experts think that’s unwise

WordPress.org has lifted its ban on hosting provider WP Engine until October 1, after putting a block on it earlier this week. The block prevented several sites from updating their…

WordPress.org temporarily lifts its ban on WP Engine

The world of WordPress, one of the most popular technologies for creating and hosting websites, is going through a very heated controversy. The core issue is the fight between WordPress…

The WordPress vs. WP Engine drama, explained

ChatGPT could get more expensive to use in coming years. The New York Times, citing internal OpenAI docs, reports that OpenAI is planning to raise the price of individual ChatGPT…

OpenAI might raise the price of ChatGPT to $44 by 2029

Binance founder Changpeng “CZ” Zhao was released from U.S. custody on Friday after serving out his four-month sentence in a low-security correctional facility. CZ’s sentence was the product of a…

Binance founder ‘CZ’ released from custody after four-month sentence

EV startup Canoo has been hit with two new lawsuits from suppliers linked to the drivetrains that power its electric vehicles, just weeks after the company kicked off a major…

Canoo hit with two supplier lawsuits as last remaining co-founder leaves

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. Want it in your inbox every Friday? Sign up here. This week…

AI dominated both YC Demo Day and startup news

Three Iranian hackers working for the Islamic Revolutionary Guard Corps (IRGC) targeted the Trump campaign in an attempted hack-and-leak operation, according to the Department of Justice.

Iranian hackers charged with hacking Trump campaign to ‘stoke discord’

Wordy is a new iOS app that offers a unique way to learning English. The app automatically translates and defines unknown words while you watch your favorite movies or TV…

Wordy’s new app helps you learn vocabulary while watching movies and TV shows

The WSJ reports that OpenAI’s next funding round, worth around $6.5 billion, could close as soon as the first week in October.

OpenAI’s $6.5B funding round may close as soon as next week

We’re thrilled to welcome Bret Taylor to TechCrunch Disrupt 2024. As the former co-CEO of Salesforce, founder of Quip, former CTO of Facebook, the co-creator of Google Maps, and current…

Bret Taylor of Sierra joins TechCrunch Disrupt 2024

The U.K.s’ antitrust authority has concluded that Amazon’s partnership and equity investment in AI startup Anthropic can’t be investigated under current merger rules due to the size and scope of…

Amazon dodges antitrust scrutiny in UK over Anthropic investment

We’re in the final hours to save up to $600 on TechCrunch Disrupt 2024 tickets! Grab your tickets now and seize this final opportunity for major savings before the countdown…

Last hours to snag up to $600 off TechCrunch Disrupt 2024 passes