ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Bypassing Apple FaceID's Liveness Detection Feature

lowResearchimportance 30
Full article153 words · extracted from schneier.com · click to collapse

Apple’s FaceID has a liveness detection feature, which prevents someone from unlocking a victim’s phone by putting it in front of his face while he’s sleeping. That feature has been hacked:

Researchers on Wednesday during Black Hat USA 2019 demonstrated an attack that allowed them to bypass a victim’s FaceID and log into their phone simply by putting a pair of modified glasses on their face. By merely placing tape carefully over the lenses of a pair glasses and placing them on the victim’s face the researchers demonstrated how they could bypass Apple’s FaceID in a specific scenario. The attack itself is difficult, given the bad actor would need to figure out how to put the glasses on an unconscious victim without waking them up.

Tags: Apple, biometrics, hacking, identification

Posted on August 15, 2019 at 6:19 AM24 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2019/08/bypassing_apple.html