iPhone X Face ID Again Unlocked With Mask, Even With 'Require Attention' Turned On

Since the iPhone X launched earlier this month, people have been attempting to fool Face ID, the new biometric facial recognition feature built into the device as a primary security feature. Face ID has thus far been tricked by twins, children, and even a mask.

Vietnamese security company Bkav made headlines in mid-November after uploading a video featuring Face ID accessed by a mask, but there were several questions about the unlocking methods used in the video, including whether "Require Attention" was turned on. Today, Bkav shared a second video with a new mask and a clearer look at how the mask was used to spoof Face ID.


As described in an accompanying blog post, Bkav used a 3D printed mask made of stone powder, which cost approximately $200 to produce. 2D infrared images of eyes were then taped over the mask to emulate real eyes.

Bkav reset Face ID on camera and then set it up anew with the demonstrator's face. "Require Attention for Face ID" and "Attention Aware Features" were both shown to be enabled on the iPhone X. For those unaware, "Require Attention for Face ID" is meant to add an extra layer of security by requiring you to look at your iPhone to use Face ID, and it's one of the features that's supposed to prevent Face ID from unlocking with a mask, with a photograph, or when you're looking away from your phone.

After activating Face ID, the Bkav demonstrator unlocks the iPhone X normally with his own face, and then unlocks it once again with the mask. The mask appears to be able to unlock the iPhone X right away, with no failed attempts and no learning, as Face ID was set up from scratch just before the test. The mask's 2D infrared eyes also appear to fool the "Require Attention for Face ID" setting.

bkavfaceidmask
Bkav claims the materials and tools used to create the mask are "casual for anyone" and that Face ID is "not secure enough to be used in business transactions," but it's worth noting that fooling Face ID in this way requires a 3D printer, several hundred dollars worth of materials, physical access to a person's iPhone X, and detailed facial photographs that can be used to reconstruct a person's face. Even then, if the 3D printed mask and the design of the infrared eyes aren't perfect, Face ID will fail after five attempts.

Bkav believes Face ID is less secure than Touch ID because it's easier to capture photographs from afar than it is to obtain a fingerprint, but this is still a very complex replication process that the average user does not need to be concerned with.

Bkav researchers said that making 3D model is very simple. A person can be secretly taken photos in just a few seconds when entering a room containing a pre-setup system of cameras located at different angles. Then, the photos will be processed by algorithms to make a 3D object.

It can be said that, until now, Fingerprint is still the most secure biometric technology. Collecting a fingerprint is much harder than taking photos from a distance.

Apple's Face ID security white paper [PDF] outlines several scenarios where Face ID has a higher probability of being fooled, including with twins, siblings that look alike, and children under the age of 13, but masks are of particular interest because Face ID features a neural network that was "trained to spot and resist spoofing" to protect against "attempts to unlock your phone with photos or masks." From Apple:

Face ID matches against depth information, which isn't found in print or 2D digital photographs. It's designed to protect against spoofing by masks or other techniques through the use of sophisticated anti-spoofing neural networks. Face ID is even attention-aware.

When Touch ID, Face ID's predecessor, was first released in the iPhone 5s in 2013, there were many similar demonstrations of how it could be fooled with a fake fingerprint, but there's little evidence that these methods were ever used to unlock devices in the real world on a wide scale basis, and it turned out to be something most iPhone users did not need to worry about. The same is likely true of Face ID.

Apple has made several improvements to Touch ID over the years, making it faster and more accurate, and similar improvements will undoubtedly be made to Face ID in the future. In the meantime, while Face ID can be fooled by a twin or a complicated facial replication process, it's largely secure for most users and has received mostly positive reviews for its security and ease of use.

Related Forum: iPhone

Top Rated Comments

alphaswift Avatar
84 months ago
X owner here. Am I worried? No.
Score: 115 Votes (Like | Disagree)
skywalkerr69 Avatar
84 months ago
“" but it's worth noting that fooling Face ID in this way requires a 3D printer, several hundred dollars worth of materials, physical access to a person's iPhone X, and detailed facial photographs that can be used to reconstruct a person's face.”

If someone wants to go through all of this just to get into my phone. I would be so flattered I would just hand it to them unlocked.
Score: 109 Votes (Like | Disagree)
gsmornot Avatar
84 months ago
I will bet you that you cannot, no matter how good your mask is, unlock my iPhone. (I have an 8 Plus)
Score: 79 Votes (Like | Disagree)
TiggrToo Avatar
84 months ago
Acid test. Give these guys a locked phone that they have no other access to, and a few minutes with an independent test subject, and let's see how successful they are given just FIVE attempts before the X disables the feature and requires a pass code instead.
Score: 54 Votes (Like | Disagree)
TiggrToo Avatar
84 months ago
To be fair, it sounds like these guys enjoyed an unfettered access to the phone and probably had hundreds of failures before this one mask worked. Correct me if I'm wrong, but won't the X disable Face ID after 6 odd failures (not got an X myself but I assumed it was the same logic as TouchID)?
Score: 53 Votes (Like | Disagree)
MR-LIZARD Avatar
84 months ago
It’s a technically interesting exercise but requires such a level of access to detailed photographs that it’s a non-issue.

My house has doors and windows that could be broken with no technical skills. They all do. I’m not going to be moving house.

I’m not going to be ditching my X or deactivating Face ID.
Score: 41 Votes (Like | Disagree)

Popular Stories

Delta Feature

Delta Game Emulator Now Available From App Store on iPhone

Wednesday April 17, 2024 9:58 am PDT by
Game emulator apps have come and gone since Apple announced App Store support for them on April 5, but now popular game emulator Delta from developer Riley Testut is available for download. Testut is known as the developer behind GBA4iOS, an open-source emulator that was available for a brief time more than a decade ago. GBA4iOS led to Delta, an emulator that has been available outside of...
iPhone 15 Pro Action Button Translate

All iPhone 16 Models to Feature Action Button, But Usefulness Debated

Tuesday April 16, 2024 6:54 am PDT by
Last September, Apple's iPhone 15 Pro models debuted with a new customizable Action button, offering faster access to a handful of functions, as well as the ability to assign Shortcuts. Apple is poised to include the feature on all upcoming iPhone 16 models, so we asked iPhone 15 Pro users what their experience has been with the additional button so far. The Action button replaces the switch ...
maxresdefault

Hands-On With the New App Store Delta Game Emulator

Wednesday April 17, 2024 12:19 pm PDT by
A decade ago, developer Riley Testut released the GBA4iOS emulator for iOS, and since it was against the rules at the time, Apple put a stop to downloads. Emulators have been a violation of the App Store rules for years, but that changed on April 5 when Apple suddenly reversed course and said that it was allowing retro game emulators on the App Store. Subscribe to the MacRumors YouTube channel ...
iOS NES Emulator Bimmy Feature

NES Emulator for iPhone and iPad Now Available on App Store [Removed]

Tuesday April 16, 2024 11:33 am PDT by
The first approved Nintendo Entertainment System (NES) emulator for the iPhone and iPad was made available on the App Store today following Apple's rule change. The emulator is called Bimmy, and it was developed by Tom Salvo. On the App Store, Bimmy is described as a tool for testing and playing public domain/"homebrew" games created for the NES, but the app allows you to load ROMs for any...
Provenance Emulator

PlayStation, GameCube, Wii, and SEGA Emulator for iPhone and Apple TV Coming to App Store

Friday April 19, 2024 8:29 am PDT by
The lead developer of the multi-emulator app Provenance has told iMore that his team is working towards releasing the app on the App Store, but he did not provide a timeframe. Provenance is a frontend for many existing emulators, and it would allow iPhone and Apple TV users to emulate games released for a wide variety of classic game consoles, including the original PlayStation, GameCube, Wii,...