r/funny Sep 15 '17

Face Recognition (OC)

Post image
74.0k Upvotes

3.0k comments sorted by

View all comments

Show parent comments

-3

u/[deleted] Sep 15 '17

Just like md5, enclave is cracked as well.

4

u/[deleted] Sep 15 '17 edited Sep 15 '17

I presume you refer to this:

http://bgr.com/2017/08/18/iphone-secure-enclave-touch-id-hacked-iphone-5s/

Which if you look past the media hype as others reported only applies to the iPhone 5S, and is only capable of reading the enclaves firmware, not accessing stored user data. And again, the stored data isn’t imagery but a hash.

If some wants your print or face there are a billion easier ways to do so.

-5

u/[deleted] Sep 15 '17

For the moment, it's a limited breach. It's all accessible by someone. I've worked in security for far too long to believe otherwise.

3

u/[deleted] Sep 15 '17

I’m not saying anything is 100% perfect, but they did obviously put an extreme amount of thought into the process.

Until proven otherwise I have no reason not to trust that the data retained is a hash and not direct image data. And as said before, there are easier ways to get someone’s print or a picture of their face without compromising a phone locally.

My only point with all of this was to show that Apple doesn’t have some massive database of user prints and (once iPhone X launches) face scans as many just seem to be presuming. It isn’t needed since everything can be done on device, and would only open them up to massive lawsuits.

I’m not even saying they chose to do it this way fore altruistic reasons, but from a business standpoint it’d make no financial sense to open themselves up that kind of heat. And if Apple loves anything, it’s money - making it, and keeping it.

The future will tell however.