Slashdot Mirror


Hackers Say They've Broken Face ID a Week After iPhone X Release (wired.com)

Andy Greenberg, writing for Wired: When Apple released the iPhone X on November 3, it touched off an immediate race among hackers around the world to be the first to fool the company's futuristic new form of authentication. On Friday, Vietnamese security firm Bkav released a blog post and video showing that -- by all appearances -- they'd cracked Face ID with a composite mask of 3-D-printed plastic, silicone, makeup, and simple paper cutouts, which in combination tricked an iPhone X into unlocking. That demonstration, which has yet to be confirmed publicly by other security researchers, could poke a hole in the expensive security of the iPhone X, particularly given that the researchers say their mask cost just $150 to make. But it's also a hacking proof-of-concept that, for now, shouldn't alarm the average iPhone owner, given the time, effort, and access to someone's face required to recreate it. Bkav, meanwhile, didn't mince words in its blog post and FAQ on the research. "Apple has done this not so well," writes the company. "Face ID can be fooled by mask, which means it is not an effective security measure."

4 of 252 comments (clear)

  1. wait a minute.... by zantafio · · Score: 3, Funny

    .... ain't all asian all look alike anyway?

  2. Good morning, Mr. Phelps by RogueWarrior65 · · Score: 5, Funny

    Your mission, should you choose to accept it, is to somehow sedate the subject and create a life cast of their face without them figuring out that you're doing it. You must then jump though a bunch of other hoops in order to unlock the subject's phone. You are under no circumstances to use the subject's own face to unlock their phone. Should you or any of your IM force be caught or killed, you will be mocked mercilessly on Slashdot.

  3. Re:What happens when.. by 110010001000 · · Score: 5, Funny

    You use your passcode and stop dating NFL players.

  4. Re:What is wrong with a passcode? by Dog-Cow · · Score: 3, Funny

    If FaceId is a pain in the ass, you're holding it wrong.