Rocksolid Light

News from da outaworlds

mail  files  register  groups  login

Message-ID:  

Your lucky number has been disconnected.


comp / comp.mobile.android / Re: Be careful - they can lift a fingerprint off a digital photo

SubjectAuthor
* Be careful - they can lift a fingerprint off a digital photoMickey D
+* Re: Be careful - they can lift a fingerprint off a digital photoJörg Lorenz
|+- Re: Be careful - they can lift a fingerprint off a digital photoOliver
|`* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
| `* Re: Be careful - they can lift a fingerprint off a digital photoHank Rogers
|  `* Re: Be careful - they can lift a fingerprint off a digital photoWolfFan
|   `* Re: Be careful - they can lift a fingerprint off a digital photoWolfFan
|    `- Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
+* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|+* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
||`* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|| +* Re: Be careful - they can lift a fingerprint off a digital photoAndrew
|| |`- Re: Be careful - they can lift a fingerprint off a digital photoAlan
|| `* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
||  `* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
||   +* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
||   |`- Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
||   `* Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
||    `* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
||     `* Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
||      `* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
||       `* Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
||        +- Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
||        +- Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
||        `* Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
||         `* Re: Be careful - they can lift a fingerprint off a digital photoAndrew
||          `* Re: Be careful - they can lift a fingerprint off a digital photoAlan
||           `* Re: Be careful - they can lift a fingerprint off a digital photoBill Powell
||            +* Re: Be careful - they can lift a fingerprint off a digital photoJan K.
||            |+* Re: Be careful - they can lift a fingerprint off a digital photoLarry Wolff
||            ||+- Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
||            ||`* Re: Be careful - they can lift a fingerprint off a digital photoPeter Piper
||            || `- Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
||            |`- Re: Be careful - they can lift a fingerprint off a digital photoCarlos E.R.
||            +- Re: Be careful - they can lift a fingerprint off a digital photoAlan
||            `- Re: Be careful - they can lift a fingerprint off a digital photoAlan
|`* Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
| +* Re: Be careful - they can lift a fingerprint off a digital photoCarlos E.R.
| |+* Re: Be careful - they can lift a fingerprint off a digital photoChris
| ||`- Re: Be careful - they can lift a fingerprint off a digital photoCarlos E.R.
| |+* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
| ||`* Re: Be careful - they can lift a fingerprint off a digital photoAndrew
| || +* Re: Be careful - they can lift a fingerprint off a digital photoAlan
| || |`- Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
| || `* Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
| ||  `- Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
| |+* Re: Be careful - they can lift a fingerprint off a digital photoPaul
| ||+* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
| |||+* Re: Be careful - they can lift a fingerprint off a digital photoPaul
| ||||`- Re: Be careful - they can lift a fingerprint off a digital photoAndrew
| |||`* Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
| ||| `- Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
| ||`- Re: Be careful - they can lift a fingerprint off a digital photoCarlos E.R.
| |`- Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
| `* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  +* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
|  |+* Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  ||`* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  || +* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
|  || |`* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  || | `* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
|  || |  `* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  || |   `* Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
|  || |    `- Re: Be careful - they can lift a fingerprint off a digital photoAndrew
|  || `* Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  ||  `* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  ||   `* Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  ||    `* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  ||     +* Re: Be careful - they can lift a fingerprint off a digital photoFrank Slootweg
|  ||     |`* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  ||     | `* Re: Be careful - they can lift a fingerprint off a digital photoFrank Slootweg
|  ||     |  +* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  ||     |  |+- Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  ||     |  |`* Re: Be careful - they can lift a fingerprint off a digital photoFrank Slootweg
|  ||     |  | `- Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  ||     |  `* Re: Be careful - they can lift a fingerprint off a digital photoThe Real Bev
|  ||     |   +* Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||     |   |`* Re: Be careful - they can lift a fingerprint off a digital photoChris
|  ||     |   | `- Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
|  ||     |   +- Re: Be careful - they can lift a fingerprint off a digital photoAlan Browne
|  ||     |   `* Re: Be careful - they can lift a fingerprint off a digital photoFrank Slootweg
|  ||     |    `* Re: Be careful - they can lift a fingerprint off a digital photoThe Real Bev
|  ||     |     +- Re: Be careful - they can lift a fingerprint off a digital photoHank Rogers
|  ||     |     `* Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||     |      `* Re: Be careful - they can lift a fingerprint off a digital photoCarlos E.R.
|  ||     |       `* Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||     |        `* Re: Be careful - they can lift a fingerprint off a digital photoThe Real Bev
|  ||     |         +- Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  ||     |         `* Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||     |          `* Re: Be careful - they can lift a fingerprint off a digital photoThe Real Bev
|  ||     |           `* Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||     |            `* Re: Be careful - they can lift a fingerprint off a digital photoThe Real Bev
|  ||     |             `* Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||     |              `* Re: Be careful - they can lift a fingerprint off a digital photoThe Real Bev
|  ||     |               `- Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||     `* Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  ||      `* Re: Be careful - they can lift a fingerprint off a digital photoAndrew
|  ||       +- Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  ||       `* Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  ||        `* Re: Be careful - they can lift a fingerprint off a digital photoAndrew
|  ||         `* Re: Be careful - they can lift a fingerprint off a digital photoJolly Roger
|  |`* Re: Be careful - they can lift a fingerprint off a digital photoR.Wieser
|  +* Re: Be careful - they can lift a fingerprint off a digital photoChris
|  +- Re: Be careful - they can lift a fingerprint off a digital photoAlan
|  `- Re: Be careful - they can lift a fingerprint off a digital photoArno Welzel
+* Re: Be careful - they can lift a fingerprint off a digital photoMickey D
`- Re: Be careful - they can lift a fingerprint off a digital photoChris

Pages:123456
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Arno Welzel
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Tue, 7 May 2024 06:53 UTC
References: 1 2 3 4
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@arnowelzel.de (Arno Welzel)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 08:53:50 +0200
Lines: 31
Message-ID: <l9u1fuFj4iiU3@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<ukgmgkxnbf.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Trace: individual.net qB6CwkXdcDpGnIEEjiuVcwnOlAKh4MDn61TPUe9RVb5esNW6W/
Cancel-Lock: sha1:FVjBLrD1v/4fAVTNM+Ms0ExWAUY= sha256:zucWCZYcNBd+blcAjRzDTMiIWAFQPDMun+NRxOE60pM=
Content-Language: de-DE
In-Reply-To: <ukgmgkxnbf.ln2@Telcontar.valinor>
View all headers

Carlos E.R., 2024-05-06 10:23:

> On 2024-05-06 10:04, Arno Welzel wrote:
>> R.Wieser, 2024-05-05 22:20:
>>
>>> Mickey,
>>>
>>>> Be careful - they can lift a fingerprint off a digital photo.
>>>
>>> And thats just one of the more complex methods there are.
>>>
>>> You touch surfaces almost every day without even realizing it - hey, that is
>>> what hands and fingers are for, right ? - effectivily broadcasting that
>>> feature of yourself to everyone around you.
>>>
>>> Same goes for "faceprints". Even easier, as your faceprint can be "taken"
>>> from literally tens of meters away.
>>
>> Except that unlocking with your face in iOS is *not* only using an image
>> of your face but also the three dimensional shape of it. That's the
>> reason why the "notch" in the iPhone displays is bigger since there is
>> not only a camera but also a 3D sensor to capture the shape of your face.
>
> What is a "3D sensor" actually? :-)

A sensor which is able to scan the shape of the face in three dimensions.

--
Arno Welzel
https://arnowelzel.de

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Chris
Newsgroups: comp.mobile.android, misc.phone.mobile.iphone, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Tue, 7 May 2024 07:02 UTC
References: 1 2 3 4 5 6 7
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: ithinkiam@gmail.com (Chris)
Newsgroups: comp.mobile.android,misc.phone.mobile.iphone,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 07:02:02 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 112
Message-ID: <v1cjla$347va$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v19hsj$3p0nl$1@paganini.bofh.team>
<v19s6f$ope$1@nnrp.usenet.blueworldhosting.com>
<v1adqg$2haqt$1@dont-email.me>
<v1aggg$1c6j$1@nnrp.usenet.blueworldhosting.com>
<v1ao5v$2joho$1@dont-email.me>
<v1b94h$qra$1@nnrp.usenet.blueworldhosting.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 07 May 2024 09:02:03 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="02a154f46d54787f633f80171629da67";
logging-data="3284970"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/Prbjuv0yVRjU+VF9yF2Y7uTCNBZETfR4="
User-Agent: NewsTap/5.5 (iPhone/iPod Touch)
Cancel-Lock: sha1:MJkm7bp0jyy8d4M97vRXP0JOc2w=
sha1:YoMjADIcHgEWAZcwsk/Jrdk+bHk=
View all headers

Mickey D <mickeydavis078XX@ptd.net> wrote:
> On Mon, 6 May 2024 15:06:54 +0100, Chris wrote:
>
>>> You misunderstood. It's all about identifying the EXACT camera.
>>
>> Like I said, it's been a while. Things might have improved.
>>
>>> There are many forensic techniques which take advantage of the unique
>>> errors inherent in any camera sensor, all of which improve over time.
>>> https://www.mdpi.com/2313-433X/10/2/31
>>
>> Thanks.
>>
>> Not sure I see what you're seeing. The review is not very precise in its
>> language. Looking at a couple of specific papers, they still are
>> comparing make/model not specific cameras.
>>
>> This one - not peer-reviewed - supposedly labelled as "individual
>> camera" with an accuracy of 99.15%, is actually only six different
>> devices (two phones and four cameras).
>> https://repository.derby.ac.uk/download/45e22f10d5dfc1d211a4392c591cd80d392237fa032ccc9f37f772a325fc91f5/922645/DIGITAL%20VIDEO%20SOURCE%20IDENTIFICATION%20BASED%20ON%20GREEN-CHANNEL%20PHOTO%20RESPONSE%20NON-UNIFORMITY%20%28G-PRNU%29.pdf
>>
>> And this one - peer-reviewed - has 11 smartphones from six difference
>> manufacturers is similarly labelled as "individual camera" with an
>> accuracy of 96.18%.
>> https://www.sciencedirect.com/science/article/abs/pii/S1742287616300998
>>
>> I don't understand how either of those studies can be called
>> individual-level identification of cameras?
>>
>> The evidence (sorry!) just isn't there. A study needs to be done with
>> 15-20 examples of each camera across multiple models and brands and see
>> if they can be individualised.
>>
>>> There are even companies that sell this software already.
>>> https://www.mobiledit.com/camera-ballistics
>>>
>>> Don't ask me how they do it though as it uses sophisticated math.
>>
>> Sorry, but the forensic market is not very healthy with plenty of
>> products which sell a dream. If a product cannot back itself with
>> published scientific research - rather than hide behind math - then it's
>> snake oil. It's notable that the software has not been updated since 2017!
>>
>>> There are articles out there on how to defeat it if you care to look.
>>> https://duckduckgo.com/&q=how+to+defeat+camera+photo+forensics
>>
>> Which is probably why things haven't moved on: it's simply of academic
>> interest with little applicability in practice.
>
> I think you're doomed if you think fingerprinting

This isn't fingerprinting.

> is only of academic
> interest since there isn't a well funded TLA out there who isn't doing it
> (IMHO).

You'd be surprised how restricted funding is for stuff like this. They use
a lot academic research as a baseline.

> As I said, don't ask me how it works except from the basic fundamentals,
> (which everyone already knows) which is that every camera sensor has
> millions of pixel bits, where some have inevitable color encoding errors.
>
> Those hardware errors are permanent, and unique to the camera.

That's an assumption. That's no evidence to show that it's unique beyond
the camera model.

> They simply find the same hardware errors in multiple photos and bingo.
> It's a match for that specific camera. Just like fingerprints & DNA are.

You're misunderstanding how fingerprints and DNA profiles work. They're not
as unique as you think and there's no "match". All identification is
probabilistic of whether it is consistent with the source being the accused
over some random individual.

>
> Given the prevalence of phone photos on the net, I can't imagine that the
> well-funded TLAs aren't pouring billions of dollars into this research.

They aren't. They don't have billions.

> Since photo fingerprint can only get better over time, what the warning is
> for is just to let people know that now, since they will scrape all the
> photos on the net if that's what they want to do.
>
> There are almost certainly techniques you can use to foil them but you have
> to know what they're using first.
>
> https://duckduckgo.com/&q=photo+forensic+fingerprinting
>
> There are many news articles on sensor imperfection fingerprinting.
> https://www.bbc.com/future/article/20210324-the-hidden-fingerprint-inside-your-photos
>
> And there's even a book on Multimedia Forensics you can download for free.
> https://link.springer.com/chapter/10.1007/978-981-16-7621-5_4
>
> Here's the PDF for the sensor identification chapter.
> https://link.springer.com/content/pdf/10.1007/978-981-16-7621-5.pdf
>
> And the EPUB.
> https://link.springer.com/download/epub/10.1007/978-981-16-7621-5.epub

I'm not saying this is categorically not possible, but currently there's no
published research to showing anything other model identification is
possible. This in itself is helpful information for investigating cases,
but doesn't prove anything.

Things may improve further in the future, but currently reliably
identifying individual cameras from their photos isn't a thing.

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Arno Welzel
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Tue, 7 May 2024 07:05 UTC
References: 1 2 3 4 5 6
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@arnowelzel.de (Arno Welzel)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 09:05:15 +0200
Lines: 57
Message-ID: <l9u25aFj4iiU4@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<ukgmgkxnbf.ln2@Telcontar.valinor> <jf6_N.37870$nQv.18368@fx10.iad>
<v1b78p$p5r$1@nnrp.usenet.blueworldhosting.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net CJDBJmW7uo2T32xH5gGP9gkt9xiCswQZD0NItbGSoUI3LQvr1m
Cancel-Lock: sha1:dpgE5pM+xZMNG864/bk51gFB28M= sha256:uqv84sUGnjwFFfVhSXvTV1eNl2yt1YBy8h6qmHN7/LM=
Content-Language: de-DE
In-Reply-To: <v1b78p$p5r$1@nnrp.usenet.blueworldhosting.com>
View all headers

Andrew, 2024-05-06 20:24:

> On Mon, 6 May 2024 10:59:27 -0400, Alan Browne wrote:
>
>>> What is a "3D sensor" actually?� :-)
>>
>> In the case of iPhone the 'shape' of the face is determined as described
>> here:
>>
>> https://support.apple.com/en-ca/102381
>>
>> The term Apple uses is "depth map of your face"
>>
>> Further: "and also captures an infrared image of your face."
>
> Phone biometrics are nothing more or less than a marketing gimmick.

Scanning the *shape* of a face and not just the *image* is still a
different approach than just using the image and that's one of the main
reasons why Google does not include "face unlock" in their Pixel phones,
since just using an image of someones face is way to simple.

Besides that you can call most "real" biometrics a "marketing gimmick"
since you can *always* make a copy of the images which are used for
fingerprint scanners, eye scanners and so on. The question is not, if
something is absolutly secure and can never be broken at all but how
much effort is needed to break something.

When I got my last passport I also had to provide biometric scans of my
fingers. The way how that fingerprint scanner worked was just taking an
*image* of my fingerprints:

<https://www.dermalog.com/products/hardware/fingerprint-scanners/f1>

"DERMALOG F1 – One of the World’s Smallest Optical Fingerprint Scanners

Its compliance to international standards make the F1 suitable for a
wide range of biometric documents and application possibilities -
capturing fingerprints for ePassports, ID Cards and
verification-processes within the blink of an eye. The self-explanatory
DERMALOG solution meets international standards defined for biometric
workflows."

They even advertise the use of their fingerprint scanners for biometric
ID cards:

<https://www.dermalog.com/turnkey-solutions/government/biometric-id-cards>

And yes, it is just optical, nothing else. So anyone can fake the
fingerprints, even those which are included scanned with an "official"
device used by authorities.

--
Arno Welzel
https://arnowelzel.de

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Arno Welzel
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Tue, 7 May 2024 07:08 UTC
References: 1 2 3 4 5 6
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@arnowelzel.de (Arno Welzel)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 09:08:28 +0200
Lines: 32
Message-ID: <l9u2bcFj4iiU5@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<ukgmgkxnbf.ln2@Telcontar.valinor> <v1beh1$2p5c4$1@dont-email.me>
<Rzb_N.37889$nQv.20152@fx10.iad>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net eOG6fSmNaFKDgMV4bmWQkgYQNPoZSgmR0H8mlca9Pwoc8JWjOQ
Cancel-Lock: sha1:4rrtNNScvzc8b0Pgffd7+mU+F20= sha256:H3ou2f8jBtDRqY3IzW5q4SX+hrkUGRrKSlVz2R5LnEs=
Content-Language: de-DE
In-Reply-To: <Rzb_N.37889$nQv.20152@fx10.iad>
View all headers

Alan Browne, 2024-05-06 23:02:

> On 2024-05-06 16:28, Paul wrote:
>> On 5/6/2024 4:23 AM, Carlos E.R. wrote:
>
>>> What is a "3D sensor" actually?  :-)
>>>
>>
>> Stereoscopic imaging is a start.
>
> Which, alas is not what the iPhone does in FaceID. To be clear, stereo
> requires at least two points of view (say two cameras a little bit
> apart, or images taken from a slightly different position. This is a
> passive process as well (in most cases).

I did not state, that Apple uses steroscopic imaging, just an additional
sensor beside the camera so the three dimensional shape of the face is
also taken into account for the unlock process and not just the visual
image of it.

> What FaceID does is project a pattern onto the face and then measure the
> positions to generate a depth map from a single POV sensor (therefore
> not stereoscopic).

Exactly. And this is more than just comparing an image, so you can not
fool the system by just using an image of the owner in a flat medium in
front of the camera.

--
Arno Welzel
https://arnowelzel.de

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Arno Welzel
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Tue, 7 May 2024 07:13 UTC
References: 1 2 3 4
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@arnowelzel.de (Arno Welzel)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 09:13:00 +0200
Lines: 20
Message-ID: <l9u2jsFj4iiU6@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<v1a979$2g9jp$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Trace: individual.net k7zpitfNkrSnZN68hcy/cAaC/BbRCOwRmjQW0+kSnMDiB4AUbt
Cancel-Lock: sha1:U+T5Fwl9VS2VQAB0Ulm8wTctfzA= sha256:YDY4nV9agcpULLYMd/eL8NvMyRbCBFadpsAjReMOFpM=
Content-Language: de-DE
In-Reply-To: <v1a979$2g9jp$1@dont-email.me>
View all headers

R.Wieser, 2024-05-06 11:51:

[...]>> Yes, in Android using *images* of a face to unlock a phone is indeed
>> not a good idea.
>
> Its a *very good* idea. It should *not ever* happen though. :-)

If something should not ever happen, it is not a good idea.

[...]
> If you want to see examples of how locks, even expensive ones, can be
> bypassed with the proverbial paperclip I would like to refer you to the
> "Lockpicking Lawyer" clips on YouTube. Those are enlighting.

I know the Lockpicking Lawyer quite well.

--
Arno Welzel
https://arnowelzel.de

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Tue, 7 May 2024 07:17 UTC
References: 1 2 3 4 5 6 7 8 9 10
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 09:17:51 +0200
Organization: A noiseless patient Spider
Lines: 64
Message-ID: <v1ckk4$34dv4$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net> <v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad> <l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me> <Sz8_N.76363$neD.59472@fx11.iad> <v1bdf9$2ou59$2@dont-email.me> <uub_N.37887$nQv.32733@fx10.iad>
Injection-Date: Tue, 07 May 2024 09:18:29 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="97b47c682cbea37817c799367b9210e8";
logging-data="3291108"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1++SGkcPwTa7aEH9p3GE3iR3E3maFqAmsp2uLYCmNGPhQ=="
Cancel-Lock: sha1:Q/IOb8hkzlJhPwdaXyFCN85/uaU=
X-MSMail-Priority: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-RFC2646: Format=Flowed; Response
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
View all headers

Alan,

>>> You fail again. I suggest you take leave of the field, declare victory
>>> for yourself (another white ribbon as when you were a child) and find
>>> something more in line with your meagre talents.
>>
>> All I see is someone who claims stuff, but brings nothing forward to
>> support
>> it. A hot-air balloon.
>
> Well, it seems that your mirror is polished to perfection, at least.
> You've got that.

:-) You can't "win" your argument (because yo have no clue how to underbuild
your posirtion) so you decide that switching to a more personal attack is in
order ? Yeah, that always works well.

>> No, I don't. Thats the lock. The face would be the key. You would only
>> have to make an acceptable faximile of the key.
>
> Completely wrong and proving you don't understand the issue. At all - not
> an iota.

Claims made without underbuilding or at least explaining them aren't worth
worth the ink with which they are written.

.... oh, wait. :-)

>> Feel free to disagree - but I do expect a bit more than "I don't believe
>> you" responses.
>
> My responses are not based on my not believing you - they are based on you
> not understanding the basic problem at all.

I think the problem is reversed : you are supporting a technology which you
have little-to-no knowledge about, and can't even come up with obvious
solutions to things you think are a problem.

Just take your "you can't use picture" problem and how I had to tell you
that 3D imagery has existed for the longest time, and nowerdays even in
multiple forms.

.... and how you tried to derail that by complaining how wax figures are, in
your opinion, not at all alike the origional. As if that was what I was
talking about or even needed.

You also have otherwise resorted to try to disqualify examples I brought
forward - YT, the lockpicking lawyer - on the torturous grounds that those
"look too easy".

Bottom line :
I see someone who knows he has nothing to bring forward to the subject at
hand, and than just tries to derail the whole thing - No doubt in an "if he
doesn't win than I'm not losing" kind of idea.

Alas, I would not have minded to learn more about the technology, but you
sure aren't the one to do so.

Goodbye kid.

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Tue, 7 May 2024 07:40 UTC
References: 1 2 3 4 5 6 7 8
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 09:40:54 +0200
Organization: A noiseless patient Spider
Lines: 42
Message-ID: <v1cnsb$354en$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net> <v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad> <l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me> <l9t8k1Ffm7oU1@mid.individual.net>
Injection-Date: Tue, 07 May 2024 10:14:03 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="97b47c682cbea37817c799367b9210e8";
logging-data="3314135"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19JsRRaq01jmsAvdgtGtQ+rO+OAaAdc3XVQcO0j2Ie2dA=="
Cancel-Lock: sha1:ouYkWzmIpYv7+mW2obFhcMk4x1c=
X-MSMail-Priority: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-RFC2646: Format=Flowed; Original
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
View all headers

Jolly,

>>> These trolls are just replying the same lines they used back when
>>> Face ID was first announced. They were wrong then, and they're just
>>> as wrong now.
>>
>> And according to you, which of the pro/con parties is trolling ?
>
> The ones who are beating a dead horse about things we discussed when
> Face ID first hit the market and umpteen times after, always trying
> to claim it's "insecure" and so on, and never knowing or acknowledging
> how it differs from other smartphone facial identification designs.

Ah, now I see where you are coming from. One of Alans compadres, no ?

Feel free to explain/underbuild why that that face-ID was secure than, and
than how its still secure now - even with technology going forward.

And if you want to claim that what was once secure(?) still must be so, let
me point out to you how cracking several kinds of, now discarded, SSL
encryptions has changed from not in your lifetime to less than a day (and
even shorter than that) is now a thing.

No Jolly, the only thing I see here is someone who tries to kill a
discussion even before has the chance to start. And those people often
have something to hide. What is it that you are trying to hide ?

> They know who they are. Either you don't, or you are one of them and
> are now offended that anyone should dare to call them out. Which is it?

You post something that could easily have been about either/all of the
parties involved in that "back when Face ID was first announced" talk, and
you are offended by me asking for something less ambigue ? Why ?

And seeing how your current response could still be about any of those
parties I start to wonder if that is not intentionally ...

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Tue, 7 May 2024 08:12 UTC
References: 1 2 3 4 5 6 7
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 10:12:17 +0200
Organization: A noiseless patient Spider
Lines: 48
Message-ID: <v1cnsc$354en$2@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <ZvSZN.77967$yf_8.32920@fx14.iad> <v19vfi$2e66g$1@dont-email.me> <za6_N.78942$TyYf.50320@fx15.iad> <v1b34r$2mfh0$1@dont-email.me> <l9u1elFj4iiU2@mid.individual.net>
Injection-Date: Tue, 07 May 2024 10:14:04 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="97b47c682cbea37817c799367b9210e8";
logging-data="3314135"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18HrRKcinNTswLiVowKyS/EonG00Oad8yYNJlyPO51VMw=="
Cancel-Lock: sha1:jdFi6VnXaN7GDf8T2eFzjQ69ocs=
X-RFC2646: Format=Flowed; Original
X-MSMail-Priority: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
View all headers

Arno,

>> Not many people wil break into houses. Yet, you have a lock on
>> your outside doors. Your point ?
>
> That's the reason why banks have safes and do not only rely on
> the security of simple door locks.

Not the point I tried to make.

But if you want to talk about that, besides the problem that most banks had
their front doors wide open - how else could they let customers in - you're
now looking about how complex a lock must be* before it stop someone from
(easily!) entering.

* assuming they will actually try to open (fool/break) the lock, and not
just find an easier point of entry.

Did I already mention "the lockpicking lawyer" on YouTube ? Its
sometimes laughable to see how easy a, on first sight sturdy, lock can be
defeated.

>> Yes, in Android using *images* of a face to unlock a phone is
>> indeed not a good idea.
>
> Its a *very good* idea. It should *not ever* happen though. :-)

If something should not ever happen, it is not a good idea.

You misunderstood : Its a very good idea to *try*. If it works you know
that it failed its primary duty. :-)

Too many people build stuff that does {this} when you do {that} - but forget
to check if {this} cannot also be gotten by doing {something else}.

I remember a gate which needed a key to open it - but you could also reach
thru the gate to get to the handle on the other side, and open it that way.

> I know the Lockpicking Lawyer quite well.

In that case I withdraw my above suggestion in that direction. :-)

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Alan Browne
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: UsenetServer - www.usenetserver.com
Date: Tue, 7 May 2024 12:27 UTC
References: 1 2 3 4 5 6 7
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!panix!weretis.net!feeder9.news.weretis.net!border-1.nntp.ord.giganews.com!border-3.nntp.ord.giganews.com!nntp.giganews.com!npeer.as286.net!npeer-ng0.as286.net!peer01.ams1!peer.ams1.xlned.com!news.xlned.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx42.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Content-Language: en-US
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<ukgmgkxnbf.ln2@Telcontar.valinor> <v1beh1$2p5c4$1@dont-email.me>
<Rzb_N.37889$nQv.20152@fx10.iad> <l9u2bcFj4iiU5@mid.individual.net>
From: bitbucket@blackhole.com (Alan Browne)
In-Reply-To: <l9u2bcFj4iiU5@mid.individual.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 28
Message-ID: <R6p_N.19099$n_S2.1201@fx42.iad>
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Tue, 07 May 2024 12:27:29 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Tue, 7 May 2024 08:27:29 -0400
X-Received-Bytes: 1994
X-Original-Bytes: 1855
View all headers

On 2024-05-07 03:08, Arno Welzel wrote:
> Alan Browne, 2024-05-06 23:02:
>
>> On 2024-05-06 16:28, Paul wrote:
>>> On 5/6/2024 4:23 AM, Carlos E.R. wrote:
>>
>>>> What is a "3D sensor" actually?  :-)
>>>>
>>>
>>> Stereoscopic imaging is a start. [AAA] <-------
>>
>> Which, alas is not what the iPhone does in FaceID. To be clear, stereo
>> requires at least two points of view (say two cameras a little bit
>> apart, or images taken from a slightly different position. This is a
>> passive process as well (in most cases).
>
> I did not state, that Apple uses steroscopic imaging,

<snipped>

You left a TL;DR sort of reply. By bringing up (to get going) an item
irrelevant to the subject [AAA] above doesn't get you much traction, alas.

--
“Patriotism is when love of your own people comes first;
nationalism, when hate for people other than your own comes first.”
- Charles de Gaulle.

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Alan Browne
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: UsenetServer - www.usenetserver.com
Date: Tue, 7 May 2024 12:29 UTC
References: 1 2 3 4 5 6 7 8 9 10 11
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx42.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Content-Language: en-US
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad>
<l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me>
<Sz8_N.76363$neD.59472@fx11.iad> <v1bdf9$2ou59$2@dont-email.me>
<uub_N.37887$nQv.32733@fx10.iad> <v1ckk4$34dv4$1@dont-email.me>
From: bitbucket@blackhole.com (Alan Browne)
In-Reply-To: <v1ckk4$34dv4$1@dont-email.me>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 27
Message-ID: <y8p_N.19100$n_S2.7551@fx42.iad>
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Tue, 07 May 2024 12:29:18 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Tue, 7 May 2024 08:29:18 -0400
X-Received-Bytes: 1937
View all headers

On 2024-05-07 03:17, R.Wieser wrote:
> Alan,
>
>>>> You fail again. I suggest you take leave of the field, declare victory
>>>> for yourself (another white ribbon as when you were a child) and find
>>>> something more in line with your meagre talents.
>>>
>>> All I see is someone who claims stuff, but brings nothing forward to
>>> support
>>> it. A hot-air balloon.
>>
>> Well, it seems that your mirror is polished to perfection, at least.
>> You've got that.
>
> :-) You can't "win" your argument

You brought up several examples of your utter lack of understanding of
how Face ID works.

So, true to troll form you counter with more nonsense.

--
“Patriotism is when love of your own people comes first;
nationalism, when hate for people other than your own comes first.”
- Charles de Gaulle.

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Jolly Roger
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: People for the Ethical Treatment of Pirates
Date: Tue, 7 May 2024 15:18 UTC
References: 1 2 3 4 5 6 7 8 9
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jollyroger@pobox.com (Jolly Roger)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: 7 May 2024 15:18:58 GMT
Organization: People for the Ethical Treatment of Pirates
Lines: 42
Message-ID: <l9uv32Fne73U1@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad>
<l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me>
<l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me>
X-Trace: individual.net o6f0fzP9Xa8HeMwpYQ/vfAf0GuDrtnBF5RD1OoBORqw0/CkCHR
Cancel-Lock: sha1:dOIxyB/jGsKkXPmSSKAKEkg6wmI= sha256:wbSxqlGv2BaGeBZo/Lf9YPTXXiDVqkKV/r70b5fNux4=
Mail-Copies-To: nobody
X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1<n@LQ!aZ7vLO_nWbK~@T'XIS0,oAJcU.qLM
dk/j8Udo?O"o9B9Jyx+ez2:B<nx(k3EdHnTvB]'eoVaR495,Rv~/vPa[e^JI+^h5Zk*i`Q;ezqDW<
ZFs6kmAJWZjOH\8[$$7jm,Ogw3C_%QM'|H6nygNGhhl+@}n30Nz(^vWo@h>Y%b|b-Y~()~\t,LZ3e
up1/bO{=-)
User-Agent: slrn/1.0.3 (Darwin)
View all headers

On 2024-05-07, R.Wieser <address@is.invalid> wrote:
> Jolly,
>
>>>> These trolls are just replying the same lines they used back when
>>>> Face ID was first announced. They were wrong then, and they're just
>>>> as wrong now.
>>>
>>> And according to you, which of the pro/con parties is trolling ?
>>
>> The ones who are beating a dead horse about things we discussed when
>> Face ID first hit the market and umpteen times after, always trying
>> to claim it's "insecure" and so on, and never knowing or
>> acknowledging how it differs from other smartphone facial
>> identification designs.
>
> Ah, now I see where you are coming from. One of Alans compadres, no ?

Hardly. Arlen and his little band of trolls is more like it. They've
been at this for literal years here.

> Feel free to explain/underbuild why that that face-ID was secure than,
> and than how its still secure now - even with technology going
> forward.

Is that supposed to be English?

> And if you want to claim that what was once secure(?) still must be
> so, let me point out to you how cracking several kinds of, now
> discarded, SSL encryptions has changed from not in your lifetime to
> less than a day (and even shorter than that) is now a thing.

"SSL can be cracked, therefore Face ID is insecure" is a new sentence I
hadn't anticipated reading this morning. Thanks for the giggle.

You're clearly not a sincere person. I see no need to continue wasting
my time with you.

--
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Arno Welzel
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Tue, 7 May 2024 15:28 UTC
References: 1 2 3 4 5 6 7 8
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@arnowelzel.de (Arno Welzel)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 17:28:32 +0200
Lines: 23
Message-ID: <l9uvkvFmqjmU9@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <ZvSZN.77967$yf_8.32920@fx14.iad>
<v19vfi$2e66g$1@dont-email.me> <za6_N.78942$TyYf.50320@fx15.iad>
<v1b34r$2mfh0$1@dont-email.me> <l9u1elFj4iiU2@mid.individual.net>
<v1cnsc$354en$2@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Trace: individual.net NhyHhECF3vXHcTWUiKx+gwkFbaW7Y/hGDWo8fzYb6vTjcPz7oB
Cancel-Lock: sha1:ja4v5ojyleZmGRtaltp4l3kuGak= sha256:SfDGcNUd3yLzZUuEH7/4mSMwI15fZ0egnMIrIjXlDJs=
Content-Language: de-DE
In-Reply-To: <v1cnsc$354en$2@dont-email.me>
View all headers

R.Wieser, 2024-05-07 10:12:

[...]
>>> Yes, in Android using *images* of a face to unlock a phone is
>>> indeed not a good idea.
[...]
> You misunderstood : Its a very good idea to *try*. If it works you know
> that it failed its primary duty. :-)

Ok, that makes more sense.

> Too many people build stuff that does {this} when you do {that} - but forget
> to check if {this} cannot also be gotten by doing {something else}.

Of course. And this is the reason why unlocking a phone just providing a
picture of the owner is not possible with a Google Pixel 6a. Getting a
picture of a persons face is much easier than getting the fingerprints
and replicating them in a way that the fingerprint sensor will accept them.

--
Arno Welzel
https://arnowelzel.de

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Arno Welzel
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Tue, 7 May 2024 15:33 UTC
References: 1 2 3 4 5 6 7
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@arnowelzel.de (Arno Welzel)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 17:33:52 +0200
Lines: 64
Message-ID: <l9uvv0FmqjmU10@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<ukgmgkxnbf.ln2@Telcontar.valinor> <jf6_N.37870$nQv.18368@fx10.iad>
<v1b78p$p5r$1@nnrp.usenet.blueworldhosting.com>
<l9u25aFj4iiU4@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net REcWBnJpiqUY/TRndYs+aQ7o672AS6Ux95D8hCTmJjtvxKUixQ
Cancel-Lock: sha1:ivfYaVCpUfQ0Ne75zFm6onKxFGw= sha256:imZrGDSSr3TcP5aVEBmP9drEKwZRi3Ilr9W5lBhD4Lc=
Content-Language: de-DE
In-Reply-To: <l9u25aFj4iiU4@mid.individual.net>
View all headers

Arno Welzel, 2024-05-07 09:05:

> Andrew, 2024-05-06 20:24:
>
>> On Mon, 6 May 2024 10:59:27 -0400, Alan Browne wrote:
>>
>>>> What is a "3D sensor" actually?� :-)
>>>
>>> In the case of iPhone the 'shape' of the face is determined as described
>>> here:
>>>
>>> https://support.apple.com/en-ca/102381
>>>
>>> The term Apple uses is "depth map of your face"
>>>
>>> Further: "and also captures an infrared image of your face."
>>
>> Phone biometrics are nothing more or less than a marketing gimmick.
>
> Scanning the *shape* of a face and not just the *image* is still a
> different approach than just using the image and that's one of the main
> reasons why Google does not include "face unlock" in their Pixel phones,
> since just using an image of someones face is way to simple.
>
> Besides that you can call most "real" biometrics a "marketing gimmick"
> since you can *always* make a copy of the images which are used for
> fingerprint scanners, eye scanners and so on. The question is not, if
> something is absolutly secure and can never be broken at all but how
> much effort is needed to break something.
>
> When I got my last passport I also had to provide biometric scans of my
> fingers. The way how that fingerprint scanner worked was just taking an
> *image* of my fingerprints:
>
> <https://www.dermalog.com/products/hardware/fingerprint-scanners/f1>
>
> "DERMALOG F1 – One of the World’s Smallest Optical Fingerprint Scanners
>
> Its compliance to international standards make the F1 suitable for a
> wide range of biometric documents and application possibilities -
> capturing fingerprints for ePassports, ID Cards and
> verification-processes within the blink of an eye. The self-explanatory
> DERMALOG solution meets international standards defined for biometric
> workflows."
>
> They even advertise the use of their fingerprint scanners for biometric
> ID cards:
>
> <https://www.dermalog.com/turnkey-solutions/government/biometric-id-cards>
>
> And yes, it is just optical, nothing else. So anyone can fake the
> fingerprints, even those which are included scanned with an "official"
> device used by authorities.

Addition: yes, the device also checks, if the scanned finger is alive
and won't accept just an image. But the result is still just an *image*
which is used for the biometric data in the passport. And creating fake
fingers including the properties required for "alive" detection or fake
fingerprints you can stick to your fingertips is not impossible either.

--
Arno Welzel
https://arnowelzel.de

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Tue, 7 May 2024 16:42 UTC
References: 1 2 3 4 5 6 7 8 9 10
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 18:42:26 +0200
Organization: A noiseless patient Spider
Lines: 34
Message-ID: <v1dn6h$3ccfq$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net> <v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad> <l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me> <l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me> <l9uv32Fne73U1@mid.individual.net>
Injection-Date: Tue, 07 May 2024 19:08:33 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="97b47c682cbea37817c799367b9210e8";
logging-data="3551738"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/QRLkS87Huqkl7xvzgVH4lMlP07pSq2JcPL7nV45wMsg=="
Cancel-Lock: sha1:Hp8JcC5wVGKxOds9gxJtq6Vmu94=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Priority: 3
X-RFC2646: Format=Flowed; Original
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-MSMail-Priority: Normal
View all headers

Jolly,

>> Feel free to explain/underbuild why that that face-ID was secure
>> than, and than how its still secure now - even with technology
>> going forward.
>
> Is that supposed to be English?

What ? Thats too hard for you to understand ? Not "English" enough for
your taste ?

> "SSL can be cracked, therefore Face ID is insecure" is a new sentence
> I hadn't anticipated reading this morning. Thanks for the giggle.

Oh well, someone "doesn't understand" a simple example. How delightfully
new.

> You're clearly not a sincere person.

Goodness! After having read that "I can't understand a word of what you're
saying" drivel that was exactly what I was thinking about you.

> I see no need to continue wasting my time with you.

I see someone who refuses to answer a simple question, and than trying to
make a run for it, while making it sound as if its all the other persons
fault.

Yeah, thats not at all obvious. Not at all, no sirree. :-)

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Tue, 7 May 2024 17:07 UTC
References: 1 2 3 4 5 6 7 8 9
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 19:07:25 +0200
Organization: A noiseless patient Spider
Lines: 41
Message-ID: <v1dn6i$3ccfq$2@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <ZvSZN.77967$yf_8.32920@fx14.iad> <v19vfi$2e66g$1@dont-email.me> <za6_N.78942$TyYf.50320@fx15.iad> <v1b34r$2mfh0$1@dont-email.me> <l9u1elFj4iiU2@mid.individual.net> <v1cnsc$354en$2@dont-email.me> <l9uvkvFmqjmU9@mid.individual.net>
Injection-Date: Tue, 07 May 2024 19:08:34 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="97b47c682cbea37817c799367b9210e8";
logging-data="3551738"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+QltK6PQlVjvQEyF0OGjnuxb13IOv8fOJbD9cX8WRdcQ=="
Cancel-Lock: sha1:6RJ825ME/6CHWSV139Cl4lKRHR8=
X-RFC2646: Format=Flowed; Original
X-Priority: 3
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
View all headers

Arno,

>> You misunderstood : Its a very good idea to *try*. If it works you
>> know that it failed its primary duty. :-)
>
> Ok, that makes more sense.

Phew .... :-)

> Of course. And this is the reason why unlocking a phone just providing
> a picture of the owner is not possible with a Google Pixel 6a.

Thats what I've ben told too.

> Getting a picture of a persons face is much easier than getting the
> fingerprints and replicating them in a way that the fingerprint sensor
> will accept them.

I wasn't trying to compare the two, I was just trying to convey that its
quite likely that a face-ID can be fooled in the same way a fingerprint can
: by duplicating the key - or just a well-enough faximile of it.

And as the OP couldn't look further than a photograph - I mean - further
than his nose is long I tried to tell him that making 3D likenesses of a
head is well possibly older than our christian calendar.

And as the intended victim is showing off his key every moment of the day I
cannot escape the feeling that a few pictures (from diferent angles) would
be enough for a 'puter (or a person) to construct a 3D model from it. Take
few more pictures with an heat (IR?) camera and you likely have the
mentioned heatmap for that face too.

Did I forget anything ?

No, I didn't say it would be easy. But I don't think its impossible either.
Just, for the first few times(!), a lengthy and costly job.

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Frank Slootweg
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: NOYB
Date: Tue, 7 May 2024 18:35 UTC
References: 1 2 3 4 5 6 7 8 9 10 11
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: this@ddress.is.invalid (Frank Slootweg)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: 7 May 2024 18:35:11 GMT
Organization: NOYB
Lines: 32
Message-ID: <v1e39q.n0c.1@ID-201911.user.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net> <v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad> <l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me> <l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me> <l9uv32Fne73U1@mid.individual.net> <v1dn6h$3ccfq$1@dont-email.me>
X-Trace: individual.net cmZ/OzOCe6Byz0RfY+OpXA9R9Vmh4QA0pq+7dZizG5/ATZGEJl
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:yGSWq+2ZqbhYJUo9fE2IL93ty/M= sha256:TolZN62TBow6Mvm5dcRlPthfVtn91sdLNJ0peU+x2K8=
User-Agent: tin/1.6.2-20030910 ("Pabbay") (UNIX) (CYGWIN_NT-10.0-WOW/2.8.0(0.309/5/3) (i686)) Hamster/2.0.2.2
View all headers

> Jolly,
>
> >> Feel free to explain/underbuild why that that face-ID was secure
> >> than, and than how its still secure now - even with technology
> >> going forward.
> >
> > Is that supposed to be English?
>
> What ? Thats too hard for you to understand ? Not "English" enough for
> your taste ?

Not to support Jolly Roger, but there are many, probaby too many,
errors in your sentence.

You make *these* (two) errors very often - as in nearly always - so
let me explain, so you can try to prevent them in future.

You're mixing up 'then' [1] and 'than' [2]. In this case, the 'than's
should have been 'then's.

And (AFAIK), "underbuild" is not an English word/verb. You're probably
looking for the equivalent of Dutch 'onderbouwen'.

These are not the only errors in your sentence, but with these errors,
the sentence is indeed hard to parse for an English 'speaker'. (As a
Dutchman, I can quite easily parse this.)

[...]

[1] <https://translate.google.com/details?sl=en&tl=nl&text=then%0A&op=translate>

[2] <https://translate.google.com/details?sl=en&tl=nl&text=than%0A&op=translate>

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Tue, 7 May 2024 20:11 UTC
References: 1 2 3 4 5 6 7 8 9 10 11 12
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Tue, 7 May 2024 22:11:03 +0200
Organization: A noiseless patient Spider
Lines: 51
Message-ID: <v1e1tm$3ev5q$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net> <v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad> <l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me> <l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me> <l9uv32Fne73U1@mid.individual.net> <v1dn6h$3ccfq$1@dont-email.me> <v1e39q.n0c.1@ID-201911.user.individual.net>
Injection-Date: Tue, 07 May 2024 22:11:34 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="97b47c682cbea37817c799367b9210e8";
logging-data="3636410"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX192RpIrNAOH5yzJr2kt+JaZCy7eUS5PMrDtoRphYmom/g=="
Cancel-Lock: sha1:+juta3VatDbyZXLoIDguhT3ALNk=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-RFC2646: Format=Flowed; Original
X-Priority: 3
X-MSMail-Priority: Normal
View all headers

Frank,

>>> Feel free to explain/underbuild why that that face-ID was secure
>>> than, and than how its still secure now - even with technology
>>> going forward.

> Not to support Jolly Roger, but there are many, probaby too
> many, errors in your sentence.

Enough *not* to convey the meaning of what I tried to say ?

> You're mixing up 'then' [1] and 'than' [2]. In this case, the
> 'than's should have been 'then's.

I realized only after posting that I made that error. But are you sure,
*both* of them ? I though only the first one.

The second is indicating a moment after having done something else. In that
case I though that a "than" was in order. (
https://www.grammarly.com/blog/than-then/ )

But ok, I made a mistake there.

> And (AFAIK), "underbuild" is not an English word/verb. You're
> probably looking for the equivalent of Dutch 'onderbouwen'.

You hit the nail on the head. A too-literal translation. Strange, I've
been using it for a while now (as in: years), but as far as I remember
you're to the first one to remark upon it.

And I see (a quick google) that the word I *should* (I think) have used is
"support". I'll have to remember that.

> These are not the only errors in your sentence,

Pray tell. You might not believe it, but I've got zero problems with being
told wrong as part of an attempt to help me better myself (upto a point
ofcourse :-) ).

> but with these errors, the sentence is indeed hard to parse for
> an English 'speaker'. (As a Dutchman, I can quite easily parse this.)

I can understand that. Ill try to keep the "steenkolen Engels" outof my
writings.

Thanks for the heads-up.

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Jolly Roger
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: People for the Ethical Treatment of Pirates
Date: Wed, 8 May 2024 02:08 UTC
References: 1 2 3 4 5 6 7 8 9 10 11
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jollyroger@pobox.com (Jolly Roger)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: 8 May 2024 02:08:45 GMT
Organization: People for the Ethical Treatment of Pirates
Lines: 46
Message-ID: <la055dFsue1U1@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad>
<l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me>
<l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me>
<l9uv32Fne73U1@mid.individual.net> <v1dn6h$3ccfq$1@dont-email.me>
X-Trace: individual.net dflAsTo9bXgLOrAqI2WRgg0jqf6l5VEJ/S+HdpkCgaRJG769o8
Cancel-Lock: sha1:Dqye3myRGG0IsTFyOzIzIelmuV4= sha256:Z0VZJImopp91eGf0ygv3OC5QKO1Ut7lFLFyl0OohvEs=
Mail-Copies-To: nobody
X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1<n@LQ!aZ7vLO_nWbK~@T'XIS0,oAJcU.qLM
dk/j8Udo?O"o9B9Jyx+ez2:B<nx(k3EdHnTvB]'eoVaR495,Rv~/vPa[e^JI+^h5Zk*i`Q;ezqDW<
ZFs6kmAJWZjOH\8[$$7jm,Ogw3C_%QM'|H6nygNGhhl+@}n30Nz(^vWo@h>Y%b|b-Y~()~\t,LZ3e
up1/bO{=-)
User-Agent: slrn/1.0.3 (Darwin)
View all headers

On 2024-05-07, R.Wieser <address@is.invalid> wrote:
> Jolly,
>
>>> Feel free to explain/underbuild why that that face-ID was secure
>>> than, and than how its still secure now - even with technology going
>>> forward.
>>
>> Is that supposed to be English?
>
> What ? Thats too hard for you to understand ? Not "English" enough
> for your taste ?

You also don't put a space between the end of a sentence and the last
punctuation mark. So it seems you don't have a very good grasp of
English overall. Whoever taught you English really did you dirty.

>> "SSL can be cracked, therefore Face ID is insecure" is a new sentence
>> I hadn't anticipated reading this morning. Thanks for the giggle.
>
> Oh well, someone "doesn't understand" a simple example. How
> delightfully new.

More like a bad allegory. Nobody here has claimed Face ID is the most
secure thing on the planet. What people are objecting to is the tired,
old, crusty trolls trying to claim its supposedly "insecure" just
because someone with tons of time, money, and will power might be able
to crack it. These trolls are weak and boring to anyone who has seen
them before.

>> You're clearly not a sincere person.
>
> Goodness! After having read that "I can't understand a word of what
> you're saying" drivel that was exactly what I was thinking about you.

"No, you"? Is that the best response you have, really?

> Regards,
> Rudy Wieser

Bye now.

--
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Arno Welzel
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Wed, 8 May 2024 09:49 UTC
References: 1 2 3 4 5 6 7 8 9 10
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@arnowelzel.de (Arno Welzel)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Wed, 8 May 2024 11:49:39 +0200
Lines: 22
Message-ID: <la105jF29p9U1@mid.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <ZvSZN.77967$yf_8.32920@fx14.iad>
<v19vfi$2e66g$1@dont-email.me> <za6_N.78942$TyYf.50320@fx15.iad>
<v1b34r$2mfh0$1@dont-email.me> <l9u1elFj4iiU2@mid.individual.net>
<v1cnsc$354en$2@dont-email.me> <l9uvkvFmqjmU9@mid.individual.net>
<v1dn6i$3ccfq$2@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Trace: individual.net aH+pE/aJWxmAoow2OYr8dQQG354gayJP/izPrZnz3VT/RzNvqr
Cancel-Lock: sha1:S9jKGQRjJp3OFcELQo108pgPhu8= sha256:ge4x9RymAf1rDJgjJdv2abNz0ApMY9jv6B0+6BNSWKg=
Content-Language: de-DE
In-Reply-To: <v1dn6i$3ccfq$2@dont-email.me>
View all headers

R.Wieser, 2024-05-07 19:07:

[...]
> And as the intended victim is showing off his key every moment of the day I
> cannot escape the feeling that a few pictures (from diferent angles) would
> be enough for a 'puter (or a person) to construct a 3D model from it. Take
> few more pictures with an heat (IR?) camera and you likely have the
> mentioned heatmap for that face too.
>
> Did I forget anything ?
>
> No, I didn't say it would be easy. But I don't think its impossible either.
> Just, for the first few times(!), a lengthy and costly job.

*Nothing* is impossible to break. It is *always* a question of how much
effort is needed to break a thing. If anyone claims to have an
"unbreakable" solution he lies.

--
Arno Welzel
https://arnowelzel.de

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Wed, 8 May 2024 10:31 UTC
References: 1 2 3 4 5 6 7 8 9 10 11
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Wed, 8 May 2024 12:31:34 +0200
Organization: A noiseless patient Spider
Lines: 20
Message-ID: <v1fkav$3tf5j$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <ZvSZN.77967$yf_8.32920@fx14.iad> <v19vfi$2e66g$1@dont-email.me> <za6_N.78942$TyYf.50320@fx15.iad> <v1b34r$2mfh0$1@dont-email.me> <l9u1elFj4iiU2@mid.individual.net> <v1cnsc$354en$2@dont-email.me> <l9uvkvFmqjmU9@mid.individual.net> <v1dn6i$3ccfq$2@dont-email.me> <la105jF29p9U1@mid.individual.net>
Injection-Date: Wed, 08 May 2024 12:31:59 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="a56a530f4f48ce34d5fb2c7b88caf44c";
logging-data="4111539"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19bDHABtc+9LGNsvV7X5V8QK16ci3XZnSTbrIfY85XROg=="
Cancel-Lock: sha1:arfn6XoToG9uog8TGGOcGeHnr+0=
X-Priority: 3
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-RFC2646: Format=Flowed; Original
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
View all headers

Arno,

> *Nothing* is impossible to break. It is *always* a question of how much
> effort is needed to break a thing. If anyone claims to have an
> "unbreakable" solution he lies.

Absolutily.

But what I tried to convey is that the "first rule" of keys is to keep them
outof sight of other people - which you simply can't do with either finger
or faceprints. *Thats*, as far as I'm concerned, the bloody stupid thing
about it.

People using such "broadcasted" biometrics just make it too easy for a
malversant.

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Carlos E.R.
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Wed, 8 May 2024 10:36 UTC
References: 1 2 3 4 5
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Wed, 8 May 2024 12:36:57 +0200
Lines: 38
Message-ID: <971sgkxksu.ln2@Telcontar.valinor>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<ukgmgkxnbf.ln2@Telcontar.valinor> <v1ac5i$2gr7m$2@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
X-Trace: individual.net ountCLfVnlG1OaAEfPoyHA7LeLavaTvUba1CeYxFwILqNTkM7R
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:inRCsf5CB+gaHjx7stMsORFHMtA= sha256:y0dnaOfCaK8OylEDYka1+AW8meLwTQx9UVpLDEr7w1Q=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <v1ac5i$2gr7m$2@dont-email.me>
View all headers

On 2024-05-06 12:41, Chris wrote:
> On 06/05/2024 09:23, Carlos E.R. wrote:
>> On 2024-05-06 10:04, Arno Welzel wrote:
>>> R.Wieser, 2024-05-05 22:20:
>>>
>>>> Mickey,
>>>>
>>>>> Be careful - they can lift a fingerprint off a digital photo.
>>>>
>>>> And thats just one of the more complex methods there are.
>>>>
>>>> You touch surfaces almost every day without even realizing it - hey,
>>>> that is
>>>> what hands and fingers are for, right ? - effectivily broadcasting that
>>>> feature of yourself to everyone around you.
>>>>
>>>> Same goes for "faceprints".  Even easier, as your faceprint can be
>>>> "taken"
>>>> from literally tens of meters away.
>>>
>>> Except that unlocking with your face in iOS is *not* only using an image
>>> of your face but also the three dimensional shape of it. That's the
>>> reason why the "notch" in the iPhone displays is bigger since there is
>>> not only a camera but also a 3D sensor to capture the shape of your
>>> face.
>>
>> What is a "3D sensor" actually?  :-)
>
> It's an infrared projection of a known pattern onto your face which
> provides a 3D map of the shape of your face. By comparing the
> distortions of the pattern between known and unknown faces you can check
> whether a person is able unlock the phone.

Interesting.

--
Cheers, Carlos.

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Carlos E.R.
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Date: Wed, 8 May 2024 10:43 UTC
References: 1 2 3 4 5
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Wed, 8 May 2024 12:43:33 +0200
Lines: 28
Message-ID: <lj1sgkxksu.ln2@Telcontar.valinor>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<ukgmgkxnbf.ln2@Telcontar.valinor> <v1beh1$2p5c4$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
X-Trace: individual.net /YBevXZHINhFTZOZP07gwgTq5f4O1zc1DAbSSFJW5ST6+m3IFH
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:zs/6CeFvIdJ8SyKBFAA8wvdDqOA= sha256:c3VjPHeYcAPsPIPaDxBgG/hefGUPAylCWg4q9LIFNDo=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <v1beh1$2p5c4$1@dont-email.me>
View all headers

On 2024-05-06 22:28, Paul wrote:
> On 5/6/2024 4:23 AM, Carlos E.R. wrote:
>> On 2024-05-06 10:04, Arno Welzel wrote:
>>> R.Wieser, 2024-05-05 22:20:

....

>>> Except that unlocking with your face in iOS is *not* only using an image
>>> of your face but also the three dimensional shape of it. That's the
>>> reason why the "notch" in the iPhone displays is bigger since there is
>>> not only a camera but also a 3D sensor to capture the shape of your face.
>>
>> What is a "3D sensor" actually?  :-)
>>
>
> Stereoscopic imaging is a start.
>
> For an encyclopedic article, you have to do a lot of guessing here.
>
> https://en.wikipedia.org/wiki/Intel_RealSense

....

Thanks :-)

--
Cheers, Carlos.

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: Frank Slootweg
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: NOYB
Date: Wed, 8 May 2024 13:53 UTC
References: 1 2 3 4 5 6 7 8 9 10 11 12 13
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: this@ddress.is.invalid (Frank Slootweg)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: 8 May 2024 13:53:09 GMT
Organization: NOYB
Lines: 102
Message-ID: <v1g750.oeo.1@ID-201911.user.individual.net>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net> <v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad> <l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me> <l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me> <l9uv32Fne73U1@mid.individual.net> <v1dn6h$3ccfq$1@dont-email.me> <v1e39q.n0c.1@ID-201911.user.individual.net> <v1e1tm$3ev5q$1@dont-email.me>
X-Trace: individual.net ayTqjHc0vF5rVfWieL/vAQd7Cx9+EYbGHX7apjeB9ZoZlSOBZZ
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:8ltfYVyxXIjDdGiwjTNNi3wiE3g= sha256:HDre3zBoWl6nxwDqDxeNyW2IxXgp5Lur0YSP0Kr7FXA=
User-Agent: tin/1.6.2-20030910 ("Pabbay") (UNIX) (CYGWIN_NT-10.0-WOW/2.8.0(0.309/5/3) (i686)) Hamster/2.0.2.2
View all headers

R.Wieser <address@is.invalid> wrote:
> Frank,
>
> >>> Feel free to explain/underbuild why that that face-ID was secure
> >>> than, and than how its still secure now - even with technology
> >>> going forward.
>
> > Not to support Jolly Roger, but there are many, probaby too
> > many, errors in your sentence.
>
> Enough *not* to convey the meaning of what I tried to say ?

Yes, not enough for a native English speaker. Speakers of languages
similar to Dutch might be able to parse (more of) it.

> > You're mixing up 'then' [1] and 'than' [2]. In this case, the
> > 'than's should have been 'then's.
>
> I realized only after posting that I made that error. But are you sure,
> *both* of them ? I though only the first one.

Yes, both of them. Neither of them is a comparison, which would call
for 'than'.

> The second is indicating a moment after having done something else. In that
> case I though that a "than" was in order. (
> https://www.grammarly.com/blog/than-then/ )

That's a good reference, but I think my (snipped) references are
simpler, i.e. not so many words.

> But ok, I made a mistake there.

When I'm unsure about 'then' versus 'than', I ask myself if it's a
comparison, i.e. "greater than", "lighter than", etc.. If so, it's
'than', else it's then.

> > And (AFAIK), "underbuild" is not an English word/verb. You're
> > probably looking for the equivalent of Dutch 'onderbouwen'.
>
> You hit the nail on the head. A too-literal translation. Strange, I've
> been using it for a while now (as in: years), but as far as I remember
> you're to the first one to remark upon it.

Yes, you use it frequently and already for a long time. I think in
most cases it was not a problem, because what you meant could be
'guessed' from the context, or the word was somewhat redundant, i.e. the
text could still be understood without the word (as I think was the
case this time)

> And I see (a quick google) that the word I *should* (I think) have used is
> "support". I'll have to remember that.

Yes, 'support' suits here. I sometimes use 'substantiate'.

> > These are not the only errors in your sentence,
>
> Pray tell. You might not believe it, but I've got zero problems with being
> told wrong as part of an attempt to help me better myself (upto a point
> ofcourse :-) ).

It's the syntaxis ('zinsbouw') of your sentence. It looks like you
more or less translated a Dutch sentence word-for-word to English.

Let me try to change it to how I think it would be 'good'/better:

[Repeat:]

> >>> Feel free to explain/underbuild why that that face-ID was secure
> >>> than, and than how its still secure now - even with technology
> >>> going forward.

Feel free to explain/substantiate why face-ID was secure
then, and how it's still secure now - even with technology
going forward.

[N.B. "it's" or "it is", not "its"]

I deleted "that that", which we Dutch would say ('dat dat', or just
'dat'), but English speakers won't.

I also deleted the second 'than'/'then'.

I think the first 'then' should be changed, because it refers to the
past, but not in a very clear way. So probably something like this is
better:

Feel free to explain/substantiate why face-ID was secure
in the past, and how it's still secure now - even with [cracking]
technology going forward.

> > but with these errors, the sentence is indeed hard to parse for
> > an English 'speaker'. (As a Dutchman, I can quite easily parse this.)
>
> I can understand that. Ill try to keep the "steenkolen Engels" outof my
> writings.

It's indeed a case of "steenkolen Engels" or Louis van Gaal English. :-)

> Thanks for the heads-up.

You're welcome.

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: R.Wieser
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: A noiseless patient Spider
Date: Wed, 8 May 2024 15:36 UTC
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: address@is.invalid (R.Wieser)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Wed, 8 May 2024 17:36:29 +0200
Organization: A noiseless patient Spider
Lines: 95
Message-ID: <v1g66d$1lb6$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com> <v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net> <v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad> <l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me> <l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me> <l9uv32Fne73U1@mid.individual.net> <v1dn6h$3ccfq$1@dont-email.me> <v1e39q.n0c.1@ID-201911.user.individual.net> <v1e1tm$3ev5q$1@dont-email.me> <v1g750.oeo.1@ID-201911.user.individual.net>
Injection-Date: Wed, 08 May 2024 17:36:46 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="a56a530f4f48ce34d5fb2c7b88caf44c";
logging-data="54630"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18O6eRpBW34uBRauWy4vrdngsb8q/Ekn32bES84Ty2wtA=="
Cancel-Lock: sha1:+pRQBKnrEx5wowJoIsgx+i11IAI=
X-Priority: 3
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-RFC2646: Format=Flowed; Original
View all headers

Frank,

>>>>> Feel free to explain/underbuild why that that face-ID was secure
>>>>> than, and than how its still secure now - even with technology
>>>>> going forward.

>> I realized only after posting that I made that error. But are you sure,
>> *both* of them ? I though only the first one.
>
> Yes, both of them. Neither of them is a comparison, which would call
> for 'than'.

Not a comparision ? Makes sense.

>> > And (AFAIK), "underbuild" is not an English word/verb. You're
>> > probably looking for the equivalent of Dutch 'onderbouwen'.
>>
>> You hit the nail on the head. A too-literal translation. Strange, I've
>> been using it for a while now (as in: years), but as far as I remember
>> you're to the first one to remark upon it.
>
> Yes, you use it frequently and already for a long time.

I wish I didn't need to (use it that frequently) ... :-\

> I think in most cases it was not a problem, because what you meant
> could be 'guessed' from the context,

I thought that the same was true here. But as I wrote that line I'm not
really the one who should be judging it in that regard ("Wij van WC-Eend
....").

>> And I see (a quick google) that the word I *should* (I think) have used
>> is "support". I'll have to remember that.
>
> Yes, 'support' suits here. I sometimes use 'substantiate'.

Substanciate. That sounds more like what I'm normally after. "Give
substance".

> It's the syntaxis ('zinsbouw') of your sentence. It looks like you
> more or less translated a Dutch sentence word-for-word to English.

D*mn. I though that with all my book reading I would have absorbed the
syntax rules from them a bit better. :-|

>>> These are not the only errors in your sentence,
>>
>> Pray tell. [snip]
>
> Let me try to change it to how I think it would be 'good'/better:
>
> Feel free to explain/substantiate why face-ID was secure
> then, and how it's still secure now - even with technology
> going forward.

I'm trying to get myself to disagree with you, but I can't. :-)

> I deleted "that that", which we Dutch would say ('dat dat', or
> just 'dat'), but English speakers won't.

It was an attempt to make it clear I was talking about the Face-ID of that
time (and not the current version).

> I also deleted the second 'than'/'then'.

I noticed. There I tried to indicate a sequence : first do {this}, and only
/after/ thats done do {that}.

> I think the first 'then' should be changed, because it refers to the
> past, but not in a very clear way. So probably something like this is
> better:
>
> Feel free to explain/substantiate why face-ID was secure
> in the past, and how it's still secure now - even with [cracking]
> technology going forward.

Yes, the sentence certainly flows better.

But you changed the subject with that "[cracking]" part. I really tried to
refer to the Face-ID technology - as I assume it has, just as the "cracking"
methods, also progressed.

>>> but with these errors,

Truly errors ? As in syntax errors ? Man ... :-(

Thanks for the explanation. I appreciate it.

now the only thing I need to do is to remember to apply them ...

Regards,
Rudy Wieser

Subject: Re: Be careful - they can lift a fingerprint off a digital photo
From: The Real Bev
Newsgroups: misc.phone.mobile.iphone, comp.mobile.android, alt.comp.os.windows-10
Organization: None, as usual
Date: Wed, 8 May 2024 16:05 UTC
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: bashley101@gmail.com (The Real Bev)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.android,alt.comp.os.windows-10
Subject: Re: Be careful - they can lift a fingerprint off a digital photo
Date: Wed, 8 May 2024 09:05:50 -0700
Organization: None, as usual
Lines: 12
Message-ID: <v1g7t0$223q$1@dont-email.me>
References: <v18k8r$ss5$1@nnrp.usenet.blueworldhosting.com>
<v18pn8$2209c$1@dont-email.me> <l9rh8kF7d7iU1@mid.individual.net>
<v1a979$2g9jp$1@dont-email.me> <Vh6_N.37873$nQv.3362@fx10.iad>
<l9sehrFbtdbU1@mid.individual.net> <v1b34s$2mfh0$4@dont-email.me>
<l9t8k1Ffm7oU1@mid.individual.net> <v1cnsb$354en$1@dont-email.me>
<l9uv32Fne73U1@mid.individual.net> <v1dn6h$3ccfq$1@dont-email.me>
<v1e39q.n0c.1@ID-201911.user.individual.net> <v1e1tm$3ev5q$1@dont-email.me>
<v1g750.oeo.1@ID-201911.user.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 08 May 2024 18:05:53 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="67eca9a0716f719524c86c49670331d9";
logging-data="67706"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/z9NGF9/miwjs1xtDeRk7lKndetr57TH8="
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101
Firefox/68.0 Thunderbird/68.12.1
Cancel-Lock: sha1:V56+FW0TdnlsWJKd30NKEnsJA5E=
Content-Language: en-US
In-Reply-To: <v1g750.oeo.1@ID-201911.user.individual.net>
View all headers

On 5/8/24 6:53 AM, Frank Slootweg wrote:

> I deleted "that that", which we Dutch would say ('dat dat', or just
> 'dat'), but English speakers won't.

Yes we do, or at least I do. "I believe that that is the truth." Carry on.

--
Cheers, Bev
"Yahoo has released its own search engine. For more info,
type 'yahoo search engine' into Google." -D.Miller

Pages:123456

rocksolid light 0.9.8
clearnet tor