Site navigation

iPhone X and Face ID: The Good, The Bad, and The Ugly

Chloe Henderson

,

iphone x face id

Apple’s new face-scanning security technology was arguably the most attention-grabbing piece of news to come out of Tuesday’s conference, but it could come with a whole host of security and usability issues… 

Tech-giant Apple held its annual big event on Tuesday, announcing the launch of the brand new iPhone 8 and iPhone X (ten). It was the latter that caught the most attention, thanks to a whole host of new features promising to usher in ‘the future’ of smartphones. Of course, these include the usual shtick such as an updated camera, a reinvented look (including the loss of the ‘home’ button), and a powerful new processor “purpose-built for machine learning, augmented reality apps and immersive 3D games.”

The most notable addition, however, is the introduction of new biometric security technology that allows iphone x face idusers to unlock their devices by holding them up to their face. Creatively dubbed ‘Face ID,’ the feature will replace fingerprint-scanning with a mechanism that maps and recognises users’ facial features through a TrueDepth camera system made up of a dot projector, infrared camera and flood illuminator.

According to Apple, Face ID projects more than 30,000 invisible infrared (IR) dots, which are then pushed through neural networks to create a mathematical model of a face. The data is then sent to a secure enclave to confirm a match, whilst adapting to physical changes in appearance over time. All saved facial information is supposedly protected by the secure enclave to keep data secure, whilst processing is done on-device and not in the cloud to protect user privacy.

Whilst the technology has been labelled revolutionary by many, it may also come with a host of security concerns that could potentially compromise the safety of users’ private data…

 

THE GOOD

To the chronically lazy, FaceID will likely come with a number of benefits. To start with, it’s arguably much more convenient then existing methods of security verification. Whilst inherently less secure, it will save you the ‘inconvenience’ of taking 2 seconds out of your day to type in a 6-digit passcode, and will also be integrated with a number of applications including the app-store and Apple Pay. What’s more, many of its features will be accessible from the home and lock screens, meaning you can make purchases and downloads without having to lift a finger.

“With the iPhone X, your iPhone is locked until you look at it and it recognises you. Nothing has ever been more simple, natural, and effortless,” Apple exec Phil Schiller effused in the launch keynote. “This is the future of how we’ll unlock our smartphones and protect our sensitive information.”

The technology will also have the ability to ‘learn your face,’ tracking slight changes such as beard growth and ageing to ensure reliability over time.

 

THE BAD

As previously mentioned, Face ID is inherently less secure than other proven methods of security. Whilst Apple maintains that the likelihood of someone else’s face being able to unlock your phone is 1,000,000 to 1, in the past it has proven notoriously easy to defeat. A group of security researchers in 2009 managed to trick face-based logins on laptops by holding up a photograph of the owner to a camera. In 2015, science writer Dan Moran fooled a Alibaba facial recognition system with a video of him blinking.

Obviously, the technology has come a long way in the last 8 years, but it’s certainly not invulnerable. Whilst hacking somebody else’s smartphone wont be as easy as holding up a photograph, one commentator has suggested that 3D printing could be used to bypass the technology. In an interview delivered before Apple’s big reveal, Marc Rogers, the first person to demonstrate spoofing the TouchID system, commented on on the safety of facial scanning technology:

iphone x face id“The moment someone can reproduce your face in a way that can be played back to the computer, you’ve got a problem,” he said. “I’d love to start by 3-D-printing my own head and seeing if I can use that to unlock it.”

Beyond security, Face ID could come with a host of additional flaws. Whilst the technology is supposed to be able to track minor changes in users, how well would it hold up against long-term ageing, or significant facial transformation? Lighting is another issue – how will the technology perform in a dimly lit environment? Apple claimed that Touch ID had a 1 in 50,000 likelihood for error. They haven’t exactly revealed the statistic for Face ID, but it’s likely to be less reliable than fingerprint scanning. This was even demonstrated live at the event,  when Apple exec Craig Federighi’s phone refused to recognise his face…

 

THE UGLY

There’s a decidedly more sinister side to Apple’s Face ID technology that has to be taken into an account. Facial scanning might be convenient for iPhone owners, but it will also make it easier for the police, and other actors, to unlock devices against users’ will.

In the US, it is illegal for the police to unlock a phone by forcing you to hand over your password without a warrant. But they CAN and have pressured users into providing their fingerprints, as biometric scanning isn’t covered by the same laws as PIN codes. Whilst the law prohibits the latter in the UK (but not the former), Stateside it is extremely likely to apply to Face ID as well, meaning that everyone from customs officers to airport security can access your private data at a whim. If an owner doesn’t comply to a request, there is nothing stopping them from merely holding up the camera to their face.

Dodgy actors such Muggers and thieves could also take advantage of the technology, using Face ID force a user into unlocking their phone under duress. This isn’t necessarily different to Touch ID,  but at least with fingerprint scanning you had the option to present the wrong hand.

 

THE SILVER LINING

On a more positive note, it’s worth remembering that Apple has a fairly good track record with protecting user data and devices from state agents. A notable example is the San Bernardino case of last year, when the tech giant refused to unlock the phone of a terrorist suspect for FBI investigators. There is little reason iphone x face idto suggest that Apple would go back on their previous stances now.

In terms of privacy, it should come as some relief to learn that mapped profiles WON’T be stored on some dystopic data-base of faces. Much like with Touch ID, Face ID will store mappings of your face locally on the  phone, and they wont be passed back to Apple.

As always, the full extent of Face ID’s security flaws wont be realised until somebody takes advantage of them. Until then, we’ll have to wait and see.

Chloe Henderson

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data