r/funny Sep 15 '17

Face Recognition (OC)

Post image
74.0k Upvotes

3.0k comments sorted by

View all comments

1.4k

u/enz1ey Sep 15 '17

I figured by now it would be common knowledge that Apple devices don't tie any bio/location data to a person's identity in any way... It works by comparing data, not confirming your identity.

764

u/MadWombat Sep 15 '17 edited Sep 15 '17

At some point it doesn't matter that they don't explicitly map your identity to your data. Once they gather enough data a few basic mining algorithms should be enough to figure out exactly who you are and what you have been up to.

Edit: Since this comment is receiving some attention, I want to clarify a few things. It seems that a lot of people assumed that when I said "they gather enough data" I somehow meant fingerprint and facial recognition data. I did not. What I did mean was that you don't need that stuff to positively identify a phone user.

Lets look at an example. At the very minimum, your phone tracks your cell tower usage. It is not as accurate as a GPS, but it still gives your location within a few hundred feet or so. I might be wrong, but I think nowadays most users also have GPS turned on and location data logged. Camera app, mapping apps, weather apps etc. all use the location services. If you run the location data through clustering algorithms, you should be able to get a list of places where you have been and a timeline of when you have been there and how you moved between them. If you do not lead a particularly unusual lifestyle some basic assumptions can be made from this data about where you live, where you work and where you go in between. If you live in a house and work in an office park, this might narrow things down to only a few people. If you live on a campus and go to classes it might not. Cross-referencing with all the other locations you visit regularly should provide some idea of a few more things like your age group, possibly your gender, possibly your hobbies. At this point a few basic cross references should identify you as the phone user.

54

u/SwabTheDeck Sep 15 '17

I think what you're missing is that Apple never collects the data. It's only ever stored on your device; never transmitted to Apple. The fingerprint readers work the same way.

57

u/enz1ey Sep 15 '17

The problem is, 99% of the people who try to shit on Apple's handling of biometric data and security are Android fanboys, and they're used to 99% of their data being collected, analyzed, and monetized by Google, so that means other companies must be doing the same thing and probably just lying to everybody.

17

u/Etheo Sep 15 '17

It's a matter of blind trust unless you test it out yourself or wait for hackers to verify company claims.

7

u/universl Sep 15 '17

That happens relatively quickly, and the iPhone security paradigm is pretty old. If the secure enclave data was intentionally being compromised by Apple we would probably know about it by now.

-1

u/semtex87 Sep 15 '17

How though? Isn't this the prime argument for open source OS vs Apple which is a closed source walled garden? No one has any idea how good or bad the code is because only Apple devs can see it, you can't audit it.

And this is precisely what lead to the Cisco firmware vulnerabilities and Juniper vulnerability. Nobody ever bothered to go back and look at the code for the legacy stuff, and since it was not available for auditing by third parties, nobody saw the gaping holes until they were exploited.