[MENTION=116955]black[/MENTION]sWorksInc
FaceID and privacy/security:
https://techcrunch.com/2017/09/15/i...answers-some-burning-questions-about-face-id/
Quotes:
When it comes to customers — users — Apple gathers absolutely nothing itself. Federighi was very explicit on this point.
“We do not gather customer data when you enroll in Face ID, it stays on your device, we do not send it to the cloud for training data,” he notes.
There is an adaptive feature of Face ID that allows it to continue to recognize your changing face as you change hair styles, grow a beard or have plastic surgery. This adaptation is done completely on device by applying re-training and deep learning in the redesigned Secure Enclave. None of that training or re-training is done in Apple’s cloud.
When you train the data it gets immediately stored in the Secure Enclave as a mathematical model that cannot be reverse-engineered back into a “model of a face.” Any re-training also happens there. It’s on your device, in your SE (secure enclave), period.
“On older phones the sequence was to click 5 times [on the power button], but on newer phones like iPhone 8 and iPhone X, if you grip the side buttons on either side and hold them a little while — we’ll take you to the power down [screen]. But that also has the effect of disabling Face ID,” says Federighi. “So, if you were in a case where the thief was asking to hand over your phone — you can just reach into your pocket, squeeze it, and it will disable Face ID. It will do the same thing on iPhone 8 to disable Touch ID.”
It’s worth noting a few additional details here:
- If you haven’t used Face ID in 48 hours, or if you’ve just rebooted, it will ask for a passcode.
- If there are 5 failed attempts to Face ID, it will default back to passcode. (Federighi has confirmed that this is what happened in the demo onstage when he was asked for a passcode — it tried to read the people setting the phones up on the podium.)
- Developers do not have access to raw sensor data from the Face ID array. Instead, they’re given a depth map they can use for applications like the Snap face filters shown onstage. This can also be used in ARKit applications.
- You’ll also get a passcode request if you haven’t unlocked the phone using a passcode or at all in 6.5 days and if Face ID hasn’t unlocked it in 4 hours.
One anecdotal thing: If you lift your phone and swipe up immediately, there’s a good chance that the Face ID system will have performed its authentication fast enough to have unlocked your device by the time you finish your swipe. That’s how fast it is.
Federighi says that Apple has tested it extensively and it should not matter what your cultural background is, Face ID will work with your face.
The fact of the matter is that there is likely an outsized amount of skepticism about Face ID because other manufacturers like Samsung have shipped versions of facial recognition that are, frankly, crap. If it can be fooled by a simple photo, what the hell are you doing shipping it at all?
Face ID is not a simple image recognition system. It looks at a three-dimensional model of your entire face, recognizing features at a level of detail high enough that Apple is confident that masks will not fool it. It’s a different ballgame entirely.
Apple’s Face ID processes mirror very closely those they developed for Touch ID. And, even though there are caveats, those have largely stood up to probing from security researchers and nation states alike.