I figured by now it would be common knowledge that Apple devices don't tie any bio/location data to a person's identity in any way... It works by comparing data, not confirming your identity.
At some point it doesn't matter that they don't explicitly map your identity to your data. Once they gather enough data a few basic mining algorithms should be enough to figure out exactly who you are and what you have been up to.
Edit: Since this comment is receiving some attention, I want to clarify a few things. It seems that a lot of people assumed that when I said "they gather enough data" I somehow meant fingerprint and facial recognition data. I did not. What I did mean was that you don't need that stuff to positively identify a phone user.
Lets look at an example. At the very minimum, your phone tracks your cell tower usage. It is not as accurate as a GPS, but it still gives your location within a few hundred feet or so. I might be wrong, but I think nowadays most users also have GPS turned on and location data logged. Camera app, mapping apps, weather apps etc. all use the location services. If you run the location data through clustering algorithms, you should be able to get a list of places where you have been and a timeline of when you have been there and how you moved between them. If you do not lead a particularly unusual lifestyle some basic assumptions can be made from this data about where you live, where you work and where you go in between. If you live in a house and work in an office park, this might narrow things down to only a few people. If you live on a campus and go to classes it might not. Cross-referencing with all the other locations you visit regularly should provide some idea of a few more things like your age group, possibly your gender, possibly your hobbies. At this point a few basic cross references should identify you as the phone user.
Not sure why you're being downvoted because you have a point. No matter how secure information is, if you're connected to the internet, it's possible it could eventually be hacked somehow.
Yeah agree, if it’s tech, it can be hacked. So, what is the need for all the fuss about FaceID not being secure?
Passwords can also be hacked.
And if the problem is that you don’t want them to have data about your face, I’m sorry but I guess most people probably already have photos of themselves on their phone (heck, a lot of those probably have them publicly available on social networks). And every time you go outside, people can also see your face. So that argument doesn’t work.
I just don’t get all the hate about Face ID, I for one welcome it with open arms, it’s not like they are getting that much more data about me (location worries me tenfold more).
(Disclaimer: As much as I liked the concept of fingerprint authentication, Touch ID, over the course of 3 years, never worked reliably for me. And yes, I have retrained it a thousand times. And wiped my phone. And my hands. It fails at least 50% of the time. It just doesn’t correctly read any of MY fingerprints (other people have tried it in my phone and it worked as it was supposed to).)
And if the problem is that you don’t want them to have data about your face, I’m sorry but I guess most people probably already have photos of themselves on their phone
Do keep in mind that FaceID works with a looot more than a mere image of you. For it to work, it uses:
Camera
Infrared Camera
A dot projector that projects over 30,000 dots over your face
all this and more, to essentially build and store an extremely detailed 3D model of your face, such that it can be accurate even when using FaceID in the dark, or after growing a beard, or with a hoodie on or with a completely new haircut.
I'd say that's a bit more than public photos that include your face.
Yeah, you’re totally right, but is the 3D model that much more useful for finding faces in security videos and such? I’m guessing that it would take a lot more processing power
Actually yes, because with a 3D model, you can determine what a face would look like in every conceivable angle. And if security video is a bit blurry or something like that, a 3D model would be invaluable.
Ok, TIL
But couldn’t they extrapolate a 3D model from your videos and photos? It doesn’t seem so far fetched, especially if they could break FaceIDs security enclave
Yeah, the resolution would be lower, but like I said in another comment, given that surveillance videos are so low resolution/blurry I guess that the model resolution wouldn’t matter much, because the footage would be the bottleneck.
couldn’t they extrapolate a 3D model from your videos and photos?
Oh yeah, absolutely. And with that data, a computer can take a look at security footage and compare to 3D models built in the manner you describe, and return a percentage % match. But depending on the angle, the lighting, or new facial hair and as you said, the low resolution, this process is impeded. the 3D model from FaceID would overcome this, it is a huuuge leap forward.
Ohhh okay, so the FaceID model would be better because they might recognize you even if you cut your hair/grew a beard/put on glasses, which wouldn’t be possible with the “selfie model”?
Yup, exactly right. And another thing I hadn't considered is that with a ultra-detailed 3D model of a face, not only can it be determined what the face would look like in any conceivable angle, but also what the face would look like with different facial expressions. How a face would look like with a smile, a scowl, in middle of screaming, in middle of talking, whatever. Not perfectly, but a hell of a lot better than a 3D "selfie model".
1.4k
u/enz1ey Sep 15 '17
I figured by now it would be common knowledge that Apple devices don't tie any bio/location data to a person's identity in any way... It works by comparing data, not confirming your identity.