From: ILPI Support <info**At_Symbol_Here**ILPI.COM>
Subject: Re: [DCHAS-L] [EXTERNAL] Re: [DCHAS-L] Alternate face ID
Date: Tue, 14 Apr 2020 15:05:52 -0400
Reply-To: ACS Division of Chemical Health and Safety <DCHAS-L**At_Symbol_Here**PRINCETON.EDU>
Message-ID: 8ED6446D-7356-4A6D-B35A-4355B7121E2C**At_Symbol_Here**ilpi.com
In-Reply-To


Face ID is unique to each device you use - it does not unlock all your devices.  An intruder would need physical access to the phone you've trained.  Face ID keys (not even the face data itself, just the cryptographic keys the scan process generates) are stored within the Secure Enclave chip on the iPhone.  The enclave is used only for the unlock/purchase process and is never shared.  In fact, the keys are inaccessible even by the phone operating system.  The likelihood of someone stealing your phone and using the printed mask to unlock it is probably on par with someone holding a gun to your head and forcing you to unlock it.  Especially given how most of us seem physically attached to our phones these days.

https://www.howtogeek.com/339705/what-is-apples-secure-enclave-and-how-does-it-protect-my-iphone-or-mac/ 

https://www.infosecurity-magazine.com/opinions/enclaves-security-world/ a little more technical and general

But yes, it is potentially a security risk, just exceedingly remote.

And, of course, just because you're paranoid doesn't mean that everyone is not out to get you.

Rob Toreki

 ======================================================
Safety Emporium - Lab & Safety Supplies featuring brand names
you know and trust.  Visit us at http://www.SafetyEmporium.com
esales**At_Symbol_Here**safetyemporium.com  or toll-free: (866) 326-5412
Fax: (856) 553-6154, PO Box 1003, Blackwood, NJ 08012




On Apr 14, 2020, at 1:47 PM, Frazier, Alicia S <ASFrazier**At_Symbol_Here**MARATHONPETROLEUM.COM> wrote:

Wouldn't that give the company that made it access to all your devices?  They could print more?  And even if that were not the case, it would be another thing for people to steal, like a key or combination, which kind of defeats the purpose of biometric type security.  Maybe I am just paranoid.
 
 
 
Alicia Frazier 
 
From: ACS Division of Chemical Health and Safety <DCHAS-L**At_Symbol_Here**PRINCETON.EDU> On Behalf Of Russell Vernon
Sent: Saturday, April 11, 2020 3:14 PM
To: DCHAS-L**At_Symbol_Here**PRINCETON.EDU
Subject: [EXTERNAL] Re: [DCHAS-L] Alternate face ID
 
Thank you Rob,
This is very useful
 
-Russ
 
 
On Sat, Apr 11, 2020 at 12:09 PM ILPI Support <info**At_Symbol_Here**ilpi.com> wrote:
 
Source of that story here with video (Chinese site): https://mp.weixin.qq.com/s/azr-yqe8VTY9ov5ITMzq_g? 
 
For $40 each, there is a company that will print your face on the mask but they haven't launched yet: https://wccftech.com/company-claims-it-will-create-face-id-compatible-masks-to-unlock-iphones/ 
 
iPhone's infrared projection system used for Face ID would normally not be fooled into opening based on a picture like that (Samsung uses the camera only and has been successfully spoofed using pictures and siblings; supposedly that's improving) , but if you train your iPhone to work on such a mask, then obviously half the face is identical no matter who wears the mask.  It would be interesting to know if the current iPhone would accept or reject this half-face on another person.
 
Video on how the Face ID IR scanner works: https://www.youtube.com/watch?v=g4m6StzUcOw 
 
You can also disable Face ID if you prefer. Go to Settings > Face ID & Passcode > Use Face ID, and disable iPhone Unlock or iPad Unlock.  You can also do that temporarily if you prefer: https://www.howtogeek.com/531453/how-to-temporarily-disable-face-id-or-touch-id-on-your-iphone/ 
 
If you're concerned about contamination using passcode unlock, you can bag your phone in a ziplock bag and it will still accept touch inputs for passcode etc.  iPhones can also be disinfected with hand sanitizer wipes or Clorox wipes: https://support.apple.com/en-us/HT204172?mod=article_inline  Numerous companies also sell UV disinfection devices.
 
Rob Toreki
 
 ======================================================
Safety Emporium - Lab & Safety Supplies featuring brand names
you know and trust.  Visit us at http://www.SafetyEmporium.com
esales**At_Symbol_Here**safetyemporium.com  or toll-free: (866) 326-5412
Fax: (856) 553-6154, PO Box 1003, Blackwood, NJ 08012
 

 

 
On Apr 11, 2020, at 11:55 AM, Dr. Craig Leivent <drleivent**At_Symbol_Here**GMAIL.COM> wrote:
 
Good Morning,
 
Do you know of a way to use the alternate Face ID on the Iphone to accommodate a face with a N-95 mask on.
 
 
Thank you,
 
Dr. Craig Leivent
--- For more information about the DCHAS-L e-mail list, contact the Divisional membership chair at membership**At_Symbol_Here**dchas.org Follow us on Twitter **At_Symbol_Here**acsdchas
 
--- For more information about the DCHAS-L e-mail list, contact the Divisional membership chair at membership**At_Symbol_Here**dchas.org Follow us on Twitter **At_Symbol_Here**acsdchas
-- 
Russell Vernon, Ph.D.
--- For more information about the DCHAS-L e-mail list, contact the Divisional membership chair at membership**At_Symbol_Here**dchas.org Follow us on Twitter **At_Symbol_Here**acsdchas
--- For more information about the DCHAS-L e-mail list, contact the Divisional membership chair at membership**At_Symbol_Here**dchas.org Follow us on Twitter **At_Symbol_Here**acsdchas

Previous post   |  Top of Page   |   Next post



The content of this page reflects the personal opinion(s) of the author(s) only, not the American Chemical Society, ILPI, Safety Emporium, or any other party. Use of any information on this page is at the reader's own risk. Unauthorized reproduction of these materials is prohibited. Send questions/comments about the archive to secretary@dchas.org.
The maintenance and hosting of the DCHAS-L archive is provided through the generous support of Safety Emporium.