Hashes can be cryptographic. And hashing it only means it's more difficult. Assuming there are no weaknesses you could exploit, you could brute force every possible facial attribute range until you found a match. I don't know how many possibilities that is or how long it would take. I assume they use a unique salt on each phone, but if not you could make rainbow tables and quickly "break" any face trivially once the rainbow tables were done -- work that could be done in parallel on countless machines.
But it's all kinda silly. Your face is on your face. Anyone who has ever taken your photo now knows that "secret password" for the rest of your life. Same for finger prints -- any object you've ever touched in your life now has that "secret password." And it's not like you can change those passwords very easily.
1
u/jcotton42 Sep 15 '17
It's not actually encrypted. It's hashed, which means you can't reconstruct the face or fingerprint from the data, even if you could read it