iPhone X Face ID Again Unlocked With Mask, Even With 'Require Attention' Turned On

Since the iPhone X launched earlier this month, people have been attempting to fool Face ID, the new biometric facial recognition feature built into the device as a primary security feature. Face ID has thus far been tricked by twins, children, and even a mask.

Vietnamese security company Bkav made headlines in mid-November after uploading a video featuring Face ID accessed by a mask, but there were several questions about the unlocking methods used in the video, including whether "Require Attention" was turned on. Today, Bkav shared a second video with a new mask and a clearer look at how the mask was used to spoof Face ID.


As described in an accompanying blog post, Bkav used a 3D printed mask made of stone powder, which cost approximately $200 to produce. 2D infrared images of eyes were then taped over the mask to emulate real eyes.

Bkav reset Face ID on camera and then set it up anew with the demonstrator's face. "Require Attention for Face ID" and "Attention Aware Features" were both shown to be enabled on the iPhone X. For those unaware, "Require Attention for Face ID" is meant to add an extra layer of security by requiring you to look at your iPhone to use Face ID, and it's one of the features that's supposed to prevent Face ID from unlocking with a mask, with a photograph, or when you're looking away from your phone.

After activating Face ID, the Bkav demonstrator unlocks the iPhone X normally with his own face, and then unlocks it once again with the mask. The mask appears to be able to unlock the iPhone X right away, with no failed attempts and no learning, as Face ID was set up from scratch just before the test. The mask's 2D infrared eyes also appear to fool the "Require Attention for Face ID" setting.

bkavfaceidmask
Bkav claims the materials and tools used to create the mask are "casual for anyone" and that Face ID is "not secure enough to be used in business transactions," but it's worth noting that fooling Face ID in this way requires a 3D printer, several hundred dollars worth of materials, physical access to a person's iPhone X, and detailed facial photographs that can be used to reconstruct a person's face. Even then, if the 3D printed mask and the design of the infrared eyes aren't perfect, Face ID will fail after five attempts.

Bkav believes Face ID is less secure than Touch ID because it's easier to capture photographs from afar than it is to obtain a fingerprint, but this is still a very complex replication process that the average user does not need to be concerned with.

Bkav researchers said that making 3D model is very simple. A person can be secretly taken photos in just a few seconds when entering a room containing a pre-setup system of cameras located at different angles. Then, the photos will be processed by algorithms to make a 3D object.

It can be said that, until now, Fingerprint is still the most secure biometric technology. Collecting a fingerprint is much harder than taking photos from a distance.

Apple's Face ID security white paper [PDF] outlines several scenarios where Face ID has a higher probability of being fooled, including with twins, siblings that look alike, and children under the age of 13, but masks are of particular interest because Face ID features a neural network that was "trained to spot and resist spoofing" to protect against "attempts to unlock your phone with photos or masks." From Apple:

Face ID matches against depth information, which isn't found in print or 2D digital photographs. It's designed to protect against spoofing by masks or other techniques through the use of sophisticated anti-spoofing neural networks. Face ID is even attention-aware.

When Touch ID, Face ID's predecessor, was first released in the iPhone 5s in 2013, there were many similar demonstrations of how it could be fooled with a fake fingerprint, but there's little evidence that these methods were ever used to unlock devices in the real world on a wide scale basis, and it turned out to be something most iPhone users did not need to worry about. The same is likely true of Face ID.

Apple has made several improvements to Touch ID over the years, making it faster and more accurate, and similar improvements will undoubtedly be made to Face ID in the future. In the meantime, while Face ID can be fooled by a twin or a complicated facial replication process, it's largely secure for most users and has received mostly positive reviews for its security and ease of use.

Tag: Face ID

Top Rated Comments

alphaswift Avatar
44 months ago
X owner here. Am I worried? No.
Score: 115 Votes (Like | Disagree)
skywalkerr69 Avatar
44 months ago
“" but it's worth noting that fooling Face ID in this way requires a 3D printer, several hundred dollars worth of materials, physical access to a person's iPhone X, and detailed facial photographs that can be used to reconstruct a person's face.”

If someone wants to go through all of this just to get into my phone. I would be so flattered I would just hand it to them unlocked.
Score: 109 Votes (Like | Disagree)
gsmornot Avatar
44 months ago
I will bet you that you cannot, no matter how good your mask is, unlock my iPhone. (I have an 8 Plus)
Score: 79 Votes (Like | Disagree)
TiggrToo Avatar
44 months ago
Acid test. Give these guys a locked phone that they have no other access to, and a few minutes with an independent test subject, and let's see how successful they are given just FIVE attempts before the X disables the feature and requires a pass code instead.
Score: 54 Votes (Like | Disagree)
TiggrToo Avatar
44 months ago
To be fair, it sounds like these guys enjoyed an unfettered access to the phone and probably had hundreds of failures before this one mask worked. Correct me if I'm wrong, but won't the X disable Face ID after 6 odd failures (not got an X myself but I assumed it was the same logic as TouchID)?
Score: 53 Votes (Like | Disagree)
MR-LIZARD Avatar
44 months ago
It’s a technically interesting exercise but requires such a level of access to detailed photographs that it’s a non-issue.

My house has doors and windows that could be broken with no technical skills. They all do. I’m not going to be moving house.

I’m not going to be ditching my X or deactivating Face ID.
Score: 41 Votes (Like | Disagree)

Top Stories

Top Stories 57 Feature

Top Stories: Apple Event Next Tuesday, Mini-LED iPad Pro, iPhone Rumors

Saturday April 17, 2021 6:00 am PDT by
It feels like we've been waiting forever for new Apple products, but the wait is almost over as Apple has announced a media event for next Tuesday, so make sure to tune into MacRumors for full coverage of everything Apple announces. While that was the big news this week, we also got some new details on Apple's iPhone plans for 2022 and 2023 courtesy of analyst Ming-Chi Kuo, and we also saw...
flat imac 3d 3 teal

Reliable Leaker Hints Redesigned Colorful iMac to Debut at 'Spring Loaded' Event

Saturday April 17, 2021 4:43 am PDT by
Reliable leaker known as l0vetodream has hinted that Apple may debut its rumored redesigned and colorful iMac at its "Spring Loaded" event on Tuesday, April 20. In a tweet, the leaker posted an image of Apple's logo used for marketing the upcoming event and an image of the retro rainbow Apple logo alongside the colorful lineup of G3 iMacs. Apple leaker Jon Prosser previously reported that...
third gen Apple pencil leaked video

Video of Alleged Third-Generation Apple Pencil Leaks Ahead of Apple Event

Friday April 16, 2021 6:13 am PDT by
A video purporting to be of the third-generation Apple Pencil has today been shared online, showing a glossy finish that mirrors previous leaks. New ✏️ ready to 🚢 #AppleEvent @TommyBo50387266 pic.twitter.com/s4RCDwDi5M— 漢尼斯·拉斯納 🇨🇳 (@ileakeer) April 16, 2021 The brief video from Twitter account @ileakeer, spotted by 9to5Mac, shows an Apple Pencil with a glossy finish much like the...
important battery message iphone 11

Some iPhone 11 Users Seeing Increased Battery Health Percentages After iOS 14.5 Recalibration Process

Friday April 16, 2021 6:32 am PDT by
In the sixth beta of iOS 14.5, Apple introduced a recalibration process for the battery health reporting system on the iPhone 11, iPhone 11 Pro, and iPhone 11 Pro Max to address inaccurate battery health estimates for some users. Apple said this process might take a few weeks to be completed, and now that two weeks have passed since the sixth beta of iOS 14.5 was released, some users are...
duan rui iphone 12 13 notch

New Images Show Smaller iPhone 13 Notch Compared to iPhone 12

Saturday April 17, 2021 11:38 pm PDT by
Leaker known as "DuanRui" has shared more images that could give us our best look yet at Apple's redesigned notch for the iPhone 13. The new pictures follow similar images shared by the leaker last week, but the latest shots include a comparison with the existing iPhone 12 notch. DuanRui posted three images on Twitter that apparently originate from Weibo, although source details remain...
iphone 13 pro max cads eap

iPhone 13 Series CAD Leaks Reveal Larger Camera Dimensions

Friday April 16, 2021 1:53 am PDT by
Information and alleged CADs of the upcoming iPhone 13 series, shared in a video from EverythingApplePro, indicates that Apple plans to make this year's iPhone camera module significantly bigger, likely to make way for larger sensors and sensor-shift stabilization. According to the CADs shared in the video, the iPhone 13 mini, Pro, and Pro Max camera module will all be a "perfect square."...
maxresdefault

Hands-On With Anker's MagSafe-Compatible Battery Pack

Thursday April 15, 2021 9:39 am PDT by
Anker, a company known for its range of accessories designed for Apple products, recently came out with one of the first MagSafe-compatible battery packs, so we thought we'd check it out to see how it compares to a standard battery pack. Subscribe to the MacRumors YouTube channel for more videos. Design wise, Anker's power bank looks like a typical battery pack, but it has magnets built in...
apple event spring loaded

Apple's 'Spring Loaded' Event Officially Announced for Tuesday, April 20

Tuesday April 13, 2021 9:04 am PDT by
Following an overnight leak by Siri, Apple today officially announced that it will be holding a special "Spring Loaded" event on Tuesday, April 20 at 10:00 a.m. Pacific Time at the Steve Jobs Theater on the Apple Park campus in Cupertino, California. As with all of Apple's 2020 events, the April 2021 event will be a digital-only gathering with no members of the media invited to attend in...
iphone 12 120hz thumbnail feature

LTPO Displays Supporting 120Hz Refresh Rates Again Rumored for iPhone 13 Pro Models

Friday April 16, 2021 10:01 am PDT by
The two higher-end "iPhone 13 Pro" models that are coming in 2021 are expected to use LTPO display technology to enable 120Hz refresh rates, according to display analyst Ross Young. Young reaffirmed the detail in a tweet that said he'd heard rumors about only one model featuring LTPO, which he says is inaccurate. Heard some rumors in the industry and media that there would only be one ...
apple music

Apple Music Tops Spotify With One Cent Paid Per Stream

Friday April 16, 2021 6:44 am PDT by
In a letter slated to be shared with artists today through the Apple Music for Artists dashboard, obtained by The Wall Street Journal, Apple has reportedly revealed that it pays music rights holders one cent per song streamed on Apple Music. The report claims that Apple Music's payment structure is thus roughly double what Spotify pays music rights holders per stream, which averages to about ...