I QUIT

There are other face-recognition systems, even on telephones, but Face ID on the iPhone X will be the gold standard to beat. Hence it becomes an amusing parlour game to imagine ways to defeat this still-unreleased technology.

Update

(2018.05.13) In retrospect I feel stupid about this post in a couple of ways.

  • A sure sign I shouldn’t be writing something is hoping it gets noticed. I hoped this got noticed. It didn’t.

  • The overall tone is too exhaustive (borderline exhausting) and overly enthusiastic.

  • Like everyone, I didn’t apply rational thinking and didn’t come up with the environment where Face ID is sure to fail, and proved to do so: In the ultraviolet bath of a tanning bed. Absence of light was never going to be an issue.

Much later, I bought an iPhoné X and found Face ID is defeated by my Mountain Equipment Coöp shades.

References

  • Apple released a security white paper (PDF) that was banged out in Pages, has widows and orphans, is not a tagged PDF, and has no business being anything other than HTML. (Corporations operate under the delusion that a PDF is more real, more official, more credible, or less likely to be silently edited.) So I created an HTML version.

    (Apple support document with slightly different claims.)

  • Many photos via Manshooter Photography’s Folsom 2017 album.

    (This is what “diversity” is really good for: Gay fetish photos as defeat vectors for face recognition. Not quite gay CEO Tim Cook’s cup of tea, I expect.)

  • I ran these by a noted security expert, with no expectation of or even a request for an attributable comment, and didn’t get one.

Now we can look at some use cases.

First of all: Disabled users

  • Persons with little to no vision have zero cause to spend a fortune on an iPhone X.

    • They can already use iPhones eyes-free (by definition) but also eight-fingers-free, as by holding down a Home button (could be on headphones or EarPods) and talking to the phone. As with sighted people, you can keep your phone in your pocket while you do that.

    • If you’re a blind person, you have to run through a flowchart to figure out if and when face detection is actually in use.

      • If VoiceOver is on, face detection is on but the attention requirement is off.

      • You can separately just deactivate the attention requirement. (But if you do that, why are you spending 1,500 bucks on this phone?) Doing so vitiates most of the security advantage of face detection.

      • You can turn off Face ID altogether. (But again: Why?)

      Hence for any reasonable use case for a blind person, the iPhone X forces you to pull the phone out and at least semi-accurately aim it at your face – and that’s just to unlock it. Then you have to work around the fact that there is no hardware Home button in a predictable place.

      The same arguments apply to Apple Watch. Sighted people just turn their wrists and glance at their watches. But a blind person has to use two hands and intentionally touch and inspect an Apple Watch for all but the most trivial uses.

  • Anyone with head tremors or with athetosis (ceaseless involuntary motion), as with cerebral palsy (cf. Christopher Hills), is not going to be able to unlock this phone.

  • Quadriplegics and some people with, say, multiple sclerosis can mount this thing on their chairs (that’s where their phones are anyway), and, if positions are dialled in well, use the iPhone X more conveniently than previous models.

I would describe those use cases as informed speculation. I expect I will be proved correct, though.

Clear-cut scenarios

Indisputably should unlock

  1. Blind people with missing or seriously askew and unhealthy eyes (many of them, in my direct experience)

  2. Blind people with degrees of eyelid openness or droop that vary day by day

  3. Visually impaired persons with nystagmus (ceaseless motion of eyeball)

  4. Hijab

  5. Bonnet

  6. Facial anatomy

    1. Dentures out vs. in

    2. Serious acne or rosacea (I don’t think port-wine stains or nevi, even giant ones, are an issue)

    3. Neurofibromatosis

    4. And, obviously, just missing parts of your face for one reason or another (especially divots in skull)

    5. And, less obviously, prosthetic replacements of same (reflectivity may differ)

Well-known facial coverings and/or eye obscurants that should not deter unlocking

  1. Sunglasses on/off

  2. Multiple kinds of sunglasses on different days

  3. Regular eyeglasses vs. bifocals

  4. Glasses that change tint or opacity according to light conditions

  5. Switching from long-term use of one untinted pair of glasses to long-term use of a new pair with tint (actually happened to a blind person I know – I tried on his yellow-tinged glasses)

  6. Glasses with attached monocular

  7. Coloured contact lenses

Makeup and facial hardware that should not deter unlocking

  1. Facial piercings in/out

  2. Horns

  3. Face tattoos (minimal pair: one face tattoo vs. one neck tattoo)

Does not unlock and indisputably should not

  1. Absolutely the biggest one: burqas (an obvious fail)

  2. Not just identical twins (they defeat the system) but identical triplets and quadruplets

  3. Siamese twins joined at the head (of whom there are approximately six individuals living, if I have that correct; in one pair, the faces are partially joined)

  4. Wraparound sunglasses worn by elderly Floridians on the way to bingo

  5. Giant snow goggles used by e.g. snowboarders

  6. Standard hospital germ mask (but cf. N95 mask)

  7. Standard such mask but with eye protection (cf. dental surgeon)

  8. Hazmat-suit mask with ostensibly transparent faceplate (will deflect infrared)

  9. Full-face motorcycle or bicycle helmet (even with visor off or up)

  10. Juggalo

  11. Geisha

  12. Drag (i.e., RuPaul in no makeup and in full makeup), but cf. Sisters of Perpetual Indulgence, with exaggerated eye outlines and the equivalent of horns or Mickey Mouse ears

    Five transvestites in white face paint and headgear

    (Sadly, we cannot run a user test on Divine)

  13. Some disabled persons with tremors or athetosis, as above

  14. Gas mask (absurd case)

Headgear that might errantly deter unlocking

  1. Wool cap (en‑US: beanie; en‑CA: tuque)

  2. Peaked cap, including baseball cap

  3. Lumberjack hat with earflaps (and laced under chin yes/no)

  4. Football helmet with cage (produces shadows on face)

  5. Regular motorcycle or bicycle helmet

  6. Batter’s helmet with single covered ear (cf. requirements to show one or both ears in passport or visa-application photos)

Less-well-known coverings

Expected outcomes vary.

  1. Pup hoods, with various degrees of coverage

    1. Open chin (should unlock; beard would help here)

      Pup hood covers face through upper lip, open below that
    2. Full-coverage (should not unlock)

      Full-face pup hood with only blue eyes, some whispers, eartips visible

      You could also subcategorize that hood by its exaggerated ears, which at this point would be a tad ridiculous to claim are human. But cf. Mickey Mouse–ears cap.

      Primary issue here is covering human skin with a presumptively lightproof material. Hence hood colour should make no difference

    3. With greater exposed face area (either outcome might be defensible)

      Man in pup hood with spikes on either side of muzzle but uncovered eyes, upper cheeks, forehead
  2. Gags, which should not deter unlocking. (Yes, we are in a position to draw distinctions between variants of gags here)

    1. Ball gag

    2. “Regular” gag, including handkerchief or equivalent used as a gag (try polka dots or heavily textured fabric); duct tape

    3. Holding various items in mouth: doll; screwdriver; giant Flintstones-like replica femur

    4. Bridle

      Man in bridle (biting between teeth) that also straps around head, neck
  3. Muzzle

    Shirtless man in muzzle covering lower cheeks, mouth, jaw, with straps up and around head

    (Prediction: Covering lower half of face reduces prediction failure compared to covering eyes and nose. But, as with surgical masks, unlocking should be deterred)

No obvious correct outcome

  1. Hold cat or dog next to face

  2. Hold doll next to face

  3. Hold professionally created replica facemask next to face

  4. Hall of mirrors with kaleidoscope of faces

  5. Motion-picture-calibre makeup prosthetics that artificially age a young actor

  6. Through various opacities of glass

    1. Through polarized glass (allegedly not a deterrent with sunglasses)

    2. Through one-way mirror

    3. Through screen door or clear glass: The use case here is an oppositional-defiant teenager who has all the time in the world to work on tricking mom or dad into unlocking their phone. For example, imagine a teenager’s third attempt at the following:

      1. Mom puttering around on balcony

      2. Teenager yells “Hey, mom!”

      3. Mom looks up

      4. Teenager has phone flush against glass (or screen mesh) at exactly the right height

      What happens then? (Prediction: Glass will scatter infrared; mesh will not, at least if flush with emitters)

  7. Through tennis or badminton racquet (especially at angle)

  8. Pantyhose over head (like a bank robber in old movies): Should scatter infrared and correctly deter unlocking. But chain mail should also deter unlocking

    Two men, one shirtless in leather apron, on a leash, and wearing chain mail draped over head

    (Bridal veil made of cloth mesh seems too trivial, but should also deter unlocking)

  9. Other interference between sensor and face

    1. Rainfall

    2. Snow (especially in wind that blows snow in unpredictable directions)

    3. Inside a tanning bed (prediction: no conflict between ultraviolet tanning rays and infrared scanner)

Very dedicated efforts

  1. Young infant (enrol face, put phone away for two months, attempt to unlock phone): By design, the system requires a passcode after any restart

  2. Simians, especially gorillas

  3. Corpse (would need equivalent of Ludovico Technique)

Most difficult case that’s least difficult to set up

Swimmer’s cap and goggles.

  • Face ID implicitly disregards hairstyle. But if you had any hair to start with, you suddenly read as bald (with presumptively different infrared reflections on scalp).

  • Lenses on goggles may or may not block infrared, but they alter apparent eyeshape by sitting within orbits. Everybody gains Oriental or Eurasian eyeshape.

So test this option on, say, a black female who normally wears extensions.

Other research on defeating face recognition

Every so often, research pops up showing hairstyles and makeup you can put on to fool face-recognition systems (e.g., CV Dazzle). There never seems to be a pattern or a recipe you can follow; all they ever show you are the designs that worked, with no surefire recipe to make your own.

The foregoing posting appeared on Joe Clark’s personal Weblog on 2017.09.28 14:02. This presentation was designed for printing and omits components that make sense only onscreen. (If you are seeing this on a screen, then the page stylesheet was not loaded or not loaded properly.) The permanent link is:
https://blog.fawny.org/2017/09/28/faceid/

(Values you enter are stored and may be published)

  

Information

None. I quit.

Copyright © 2004–2024