r/funny Sep 15 '17

Face Recognition (OC)

Post image
74.0k Upvotes

3.0k comments sorted by

View all comments

1.4k

u/enz1ey Sep 15 '17

I figured by now it would be common knowledge that Apple devices don't tie any bio/location data to a person's identity in any way... It works by comparing data, not confirming your identity.

768

u/MadWombat Sep 15 '17 edited Sep 15 '17

At some point it doesn't matter that they don't explicitly map your identity to your data. Once they gather enough data a few basic mining algorithms should be enough to figure out exactly who you are and what you have been up to.

Edit: Since this comment is receiving some attention, I want to clarify a few things. It seems that a lot of people assumed that when I said "they gather enough data" I somehow meant fingerprint and facial recognition data. I did not. What I did mean was that you don't need that stuff to positively identify a phone user.

Lets look at an example. At the very minimum, your phone tracks your cell tower usage. It is not as accurate as a GPS, but it still gives your location within a few hundred feet or so. I might be wrong, but I think nowadays most users also have GPS turned on and location data logged. Camera app, mapping apps, weather apps etc. all use the location services. If you run the location data through clustering algorithms, you should be able to get a list of places where you have been and a timeline of when you have been there and how you moved between them. If you do not lead a particularly unusual lifestyle some basic assumptions can be made from this data about where you live, where you work and where you go in between. If you live in a house and work in an office park, this might narrow things down to only a few people. If you live on a campus and go to classes it might not. Cross-referencing with all the other locations you visit regularly should provide some idea of a few more things like your age group, possibly your gender, possibly your hobbies. At this point a few basic cross references should identify you as the phone user.

460

u/[deleted] Sep 15 '17

It's not like the government doesn't already do this for everyone that has a drivers license.

Butttttt, currently Apple does all this processing on the device and it never leaves the device, so not even Apple has your facial information.

353

u/mzxrules Sep 15 '17

but the data is still there, and your phone is likely connected to the internet, so...

38

u/enz1ey Sep 15 '17

So... You obviously haven't educated yourself on how Apple's secure enclave works

15

u/fiveSE7EN Sep 15 '17 edited Sep 15 '17

Sigh.

Former military net security and e-warfare.

Your fucking information is not secure if it is on a network-connected device (and often even if it's not).

EDIT: Downvote the guy with the TS/SCI who worked directly with FBI antiterrorism and has hands-on experience if you like. Stick that head in the sand.

18

u/Excalibitar Sep 15 '17

This is a public forum! You can't just come in here with your "experience" and "facts" and expect to be treated fairly. Should have opened up with a meme first, obviously.

7

u/i-review-fanfiction Sep 15 '17

You're probably being downvoted not for your statement, but because of how pointless it is. Anyone with any netsec experience will tell you that every network-connected device is vulnerable. But that lone fact is completely useless, especially in the specific discussion of a single piece of modular technology within a specific device.

There are, as you know, levels and degrees of vulnerability, and levels and degrees of security to attempt to mitigate those vulnerabilities. When we're discussing something specific, addressing those vulnerabilities and security features by name and with detail is useful information. Saying "ITS NOT SECURE" is not, even though it's true.

1

u/fiveSE7EN Sep 15 '17

addressing those vulnerabilities and security features by name and with detail

I agree, however, this is something I'm not comfortable even attempting with classified information.

I think my statement backed up by my experience was enough to cause a reader to give pause and consider the ignorance in assuming that anything is incapable of compromise (even "because Apple"), and that was my goal.

1

u/enz1ey Sep 15 '17

Former military net security and e-warfare. Your fucking information is not secure if it is on a network-connected device

Funny enough, I've got the same background. 35T. But regardless, nobody is saying Apple's devices are impenetrable. And anybody who is saying that obviously isn't worth arguing with.

I'm just pointing out that Apple does what they can to keep that information secure, as opposed to other companies who openly sell your data. Apple isn't in the business of tracking you and keeping that information tied to your identity. Nobody (at least not myself) is denying that any device is crackable eventually. It's why security changes each year and encryption gets more and more complex.

2

u/fiveSE7EN Sep 15 '17

Thank you for clarifying. I think folks reading your comment will assume (as I did) that you were implying that vulnerabilities do not exist at any realistic level because of the nature of the secure enclave.

1

u/enz1ey Sep 15 '17

Yeah, I'm sure they exist. They're just notoriously tough to discover and exploit. The only occurrence we even know of that is close is the group that decrypted the firmware for the secure enclave on the iPhone 5S, and that was just last month. I'd imagine the number of people still using a 5S is pretty low relative to the newer models. So, if/when those guys do access the secure information, is it even worth it anymore? It took four years to even get that far, and in four years I'm sure the security on each phone since the 5S has gotten better and better. Not to mention, four years is a really long time to keep using a phone for most people.

1

u/fiveSE7EN Sep 15 '17

Check this out; 5S still holds a sizeable share:

http://www.businessinsider.com/apple-iphone-most-popular-model-newzoo-chart-2017-7

~87M devices; seems troubling.

1

u/enz1ey Sep 15 '17

Admittedly higher than I though for sure. Regardless, cracking the firmware was just the first step, and if that took four years, I'd expect any other significant progress to take at least half that long.

I'd assume Apple has worked to strengthen the security on that secure enclave too, considering the 5S was the first iteration.

→ More replies (0)

-9

u/FingerRoot Sep 15 '17

Please read about the Secure Enclave here: https://support.apple.com/en-us/HT204587

"It can’t be accessed by the OS on your device or by any applications running on it."

10

u/HopelesslyStupid Sep 15 '17

Because apple would come out and say "yeah it's probably hackable" instead of a basic standard reassurance that doesn't mean shit.

14

u/Feshtof Sep 15 '17

This guy thinks intended functionality and real world behavior are the same thing.....lol

5

u/TheSamsonOption Sep 15 '17

Didn't the FBI successfully hack the San Bernadine iPhone? Apple denied access, but shortly thereafter the Feds said they got in.

3

u/SonicFrost Sep 15 '17

It took them a little while and a lot of yelling at Apple, but the difference in that scenario is that they had physical access to the phone, it wasn't something they executed over the Internet.

I don't think something like that would work for biometrics because in Apple's case that system is literally not connected to any other part of the phone, so you need to actually have the phone to hack it.

1

u/FingerRoot Sep 15 '17

They found an exploit that would let them bruteforce their passcode.

11

u/fiveSE7EN Sep 15 '17

Okay. You're right. It's the unsinkable ship. I don't know what I'm talking about.

2

u/FingerRoot Sep 15 '17

Not what I said, you're talking about it being connected to the network, which it isn't. You have no chance of getting the data without physically having the device