Most Face Authentication Systems Can Be Bypassed By 3D Models Of Facebook Photos; Now What?

Face authentication systems have long had a problem with being tricked by still images. However, as the authentication systems became smarter, so did the mechanisms to fool them. Security researchers from the University of North Carolina discovered that 3D models of faces made from Facebook photos can bypass the majority of face authentication systems in use today, with up to 100% success rate if the photos are taken indoors.

Latest Videos FromTom's Hardware
TOPICS
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • InvalidError
    All forms of biometrics no matter how sophisticated will eventually get worked around of as long as would-be attackers have any form of access to the underlying data or enough related data to recreate it. I would not trust biometrics as anything more than a fancy and somewhat more secure user name replacement. I'd still require a password to complete authentication for anything requiring more than trivial security.
    Reply
  • pack3t
    Yea, no such thing as bullet proof in security. There will always be a workaround from someone. People should however understand that as techniques to bypass security are created depending on the use cases you will still reduce the number of attackers able to make effective use of the approach. So there is never a case where nothing is better than something. Just because researchers figured out a way around it does not mean that it should not be used. There are a number of things to consider to make that determination.
    Reply
  • Nintendork
    Can't you just auto delete user/post with "paycheck" "hours day" "online" in 1 comment?
    Reply
  • Nintendork
    The old trusty passowrd based secure system is still the best, better if you can have a 2-3 way password before accesing content (optional).
    Reply
  • bloodroses
    LOL, Now you know how Facebook has all your personal information. :)
    Reply
  • PartlyCloudy
    Do they get any credit for their work? Any links to their research?
    Reply
  • 3ogdy
    Totally against biometric security. Private espionage under a brand new excuse. Now go out and scream: SECURITY! SECURITY! SECURITY!
    Better tap your cameras, more elegantly (the way Asus did it) or less so...because your smartphone or laptop is not exactly yours, or under your control for that reason.
    How many times do we need to read news about newly discovered backdoors and bugs that were being exploited by the NSA to understand the world we're living in?
    Oh wait, yeah...let me go buy a smartphone with a fingerprint reader and that biometric security bullshit enabled. Just another chain tied to your neck.

    Some people would be capable of proposing a law according to which we shall all walk completely naked in public so that we cannot hide anything under our clothes, be it guns, counterfeit money or some "Allahu akbar" bomb.
    Reply
  • Jeff Fx
    This is a lot of work to defeat a simple lock that's not meant to provide heavy security.

    Holding your victims phone up to their face to access their phone would be much easier, and is also easier than beating a PIN out of them.
    Reply
  • InvalidError
    18485723 said:
    This is a lot of work to defeat a simple lock that's not meant to provide heavy security.
    It won't be that much work once automated tookits to do that job become more common and many people will make the mistake of underestimating the importance of the data they are protecting with vulnerable biometric locks.
    Reply
  • alextheblue
    Multiple factor security is important. Facial recognition is OK as a part of that, but not as the only solution. Although, when I read the headline I already knew that Windows Hello couldn't be bypassed so easily since I had read about it when it was first released. In fact it can tell apart supposedly identical twins in the tests I saw.
    Reply