Researchers Demonstrated Method for Bypassing Face ID on an 'Unconscious' Victim's iPhone Using Glasses and Tape

During the Black Hat USA conference in Las Vegas, researchers demonstrated a Face ID bypass method that used glasses and tape to unlock and infiltrate the iPhone of an "unconscious" victim.

According to a report from Threatpost (via iMore), researchers from Tencent aimed to fool the "liveness" detection feature in biometrics, which is meant to distinguish "real" from "fake" features on people.

faceidbypass
Liveness detection, said the researchers, detects background noise and response distortion or focus blur, allowing it to make sure that a face is a real face and not a mask. This liveness detection is used by Face ID, and Apple even has an "Attention Aware" feature that makes sure your ‌iPhone‌ doesn't unlock unless you're looking at it.

To trick Face ID, the researchers created prototype glasses with black tape on the lenses and white tape inside the black tape to emulate the look of an eye. When putting the glasses over a sleeping victim's face, they were able to access his ‌iPhone‌ and send themselves money through a mobile payment app.

This method worked because the researchers found that liveness detection works differently with glasses and essentially doesn't extract 3D information from the eye area when glasses are worn.

They discovered that the abstraction of the eye for liveness detection renders a black area (the eye) with a white point on it (the iris). And, they discovered that if a user is wearing glasses, the way that liveness detection scans the eyes changes.

"After our research we found weak points in FaceID... it allows users to unlock while wearing glasses... if you are wearing glasses, it won't extract 3D information from the eye area when it recognizes the glasses."

An attacker attempting to use this method in the real world would need a victim that's sleeping or unconscious, access to that victim's ‌iPhone‌, and then glasses would need to be placed over the eyes without waking the person up. It's worth noting that this isn't a situation most people are likely to run into, and there's also no secondary research on this alleged method this time.

To mitigate the eye detection loophole in the future, researchers suggested biometrics manufacturers add identity authentication for native cameras and "increase the weight of video and audio synthesis detection."

Apple has designed Face ID with easy access disabling measures for situations where a person might be coerced or forced into unlocking an ‌iPhone‌ with facial recognition. Pressing on the sleep/wake button of a Face ID-enabled ‌iPhone‌ five times in rapid succession brings up an emergency SOS screen that automatically disables Face ID and requires a passcode to be entered before Face ID works again. Pressing and holding the side/top button and a volume button also works on the ‌iPhone‌ and the iPad Pro.

Tag: Face ID

Top Rated Comments

Wilson1313 Avatar
30 months ago
And with Touch ID, you just grab a sleeping/unconscious victim's finger and...
Score: 83 Votes (Like | Disagree)
keysofanxiety Avatar
30 months ago
That's why I always wear sunglasses when I sleep in public... Everybody thinks I'm awake and just unengaged with the people around me. No one can break THAT fortress of security!
Sunglasses? You need to step up your game and get the always awake glasses. ;)

Score: 38 Votes (Like | Disagree)
keysofanxiety Avatar
30 months ago
This is a bit of a reach. I think for Face ID to be fooled by such a ridiculous circumstance just goes to show how hard they’ve tried to ‘break’ it — I highly doubt this was their first attempt or idea for how to circumvent it.

It’s a far cry from a photograph fooling facial recognition.
Score: 34 Votes (Like | Disagree)
Relentless Power Avatar
30 months ago
Article quote:

An attacker attempting to use this method in the real world would need a victim that's sleeping or unconscious, access to that victim's iPhone, and then glasses would need to be placed over the eyes without waking the person up.”

Yeah, because this is a real easy to bypass the users Face using this method. :rolleyes:
Score: 31 Votes (Like | Disagree)
farewelwilliams Avatar
30 months ago
When putting the glasses over a sleeping victim's face,
ok. how is this any less secure than TouchID?
Score: 27 Votes (Like | Disagree)
Kardinal1911 Avatar
30 months ago
I appreciate these findings because it challenges Apple and others to improve the security of devices as we move to biometrics. But I highly doubt someone could slap some glasses on my face and I not wake up... moreover if what’s in my phone is this important that you’d make a pair of Face ID cooling glasses. I doubt I’d be around you anyway
[doublepost=1565302156][/doublepost]Weekend at Bernie’s type crap lol
Score: 25 Votes (Like | Disagree)

Related Stories

General black friday 20 sale feature 2

Best Black Friday Deals on Apple Watch, AirPods Pro, MacBook Pro, More

Wednesday November 24, 2021 8:06 am PST by
Black Friday 2021 has kicked off, and you can now get some of the year's best deals on numerous Apple products. In this article we're providing a quick summary of all the best sales we've seen so far this season. For more on the best sales happening this week, visit our Black Friday Roundup. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a...
apple wallet drivers license feature

Apple Delays iOS 15 Feature for Adding Your Driver's License to Your iPhone Until Early 2022

Tuesday November 23, 2021 9:35 am PST by
Apple recently updated its website to indicate that an upcoming iOS 15 and watchOS 8 feature that will let you add your driver's license or state ID to your iPhone and Apple Watch in participating U.S. states has been delayed until early 2022. Apple previously said the feature would launch in late 2021. In September, Apple said Arizona and Georgia would be among the first states to introduce ...
airpods pro blue holiday 3

Black Friday: AirPods Pro With MagSafe Drop to $159 on Amazon

Tuesday November 23, 2021 9:12 am PST by
Amazon is now matching Walmart's price on the AirPods Pro with MagSafe, available for $159.00, down from $249.00. These are shipped and sold directly from Amazon, and in stock now. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. Stock may begin dwindling soon, ...
airpods pro pink holiday

Black Friday: AirPods Pro With MagSafe Hit Lowest Ever Price

Tuesday November 23, 2021 7:47 am PST by
Apple's AirPods Pro with the new MagSafe Charging Case is now available for its lowest ever price thanks to Black Friday sales. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. The limited-time deal is available at both Amazon and Walmart, which are both...
maxresdefault

There's No Windows for Arm Macs Yet Because Microsoft Has Secret Exclusivity Deal With Qualcomm

Monday November 22, 2021 12:56 pm PST by
Microsoft has declined to make a version of Windows 11 available for Apple's M1, M1 Pro, and M1 Max Macs that are built on an Arm architecture, and now we may know the reason - a secret exclusivity deal with Qualcomm. Subscribe to the MacRumors YouTube channel for more videos. According to XDA-Developers, Arm-based Windows has only been made available on devices with Qualcomm SoC's because of ...
airpods pro holiday 2

Apple Black Friday: AirPods Pro With MagSafe Drop to All-Time Low of $159 ($90 Off)

Monday November 22, 2021 12:01 pm PST by
Update November 23: This deal is now also available at Amazon. Black Friday is officially in full swing this afternoon, with the launch of one of the first major discounts at Walmart. There you can get Apple's AirPods Pro with MagSafe Charging Case for just $159.00, down from $249.00. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a...
maxresdefault

HomeKit Accessories Worth Checking Out

Tuesday November 23, 2021 7:06 am PST by
Every so often, MacRumors videographer Dan rounds up some of his favorite home products that he's been using. We have another installment of our HomeKit series, this time featuring devices from Lutron, Belkin, Sonos, and more. Subscribe to the MacRumors YouTube channel for more videos. You can see everything in action in the video, and we have links and a short description for the HomeKit...
wrap up 3 homepod spotify 1

Spotify Users Growing Impatient and Canceling Subscriptions Over Lack of Native HomePod Support

Monday November 22, 2021 10:39 am PST by
Spotify users are growing impatient with the music streaming giant over its lack of HomePod support, pushing several customers to the brink of canceling their subscriptions entirely and moving to alternative platforms, such as Apple Music. More than a year ago, at the 2020 Worldwide Developers Conference, Apple announced that it would be adding third-party music service support to HomePod. A ...