Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

tardman91

macrumors 65816
Original poster
Oct 21, 2009
1,170
398
Tampa Area, FL
Odd article about the iPhone X and it's security. Consumerist reported the following:
https://consumerist.com/2017/09/29/...e-id-may-be-fooled-by-evil-twins-little-kids/

When Apple introduced the iPhone X’s new “Face ID” feature — which scans a user’s face to unlock the phone — the company said it had considered the “Evil Twin” scenario. And now, it’s admitting that if you have a twin — or an alternate reality doppelgänger– he or she could totally break into your phone.

In its Face ID Security Guide [PDF], Apple notes that the probability of a random person successfully unlocking your phone is about 1 in 1,000,000 — compared to versus 1 in 50,000 for Touch ID.

However, the likelihood of a false match is different for twins, as well as siblings who may look like you.

And in case there are any kids out there running around with the $1,000 phones, you should be warned that False ID may provide false matches for children under the age of 13, “because their distinct facial features may not have fully developed,” Apple explains.

There are two solutions. First, don’t use Face ID and just lock your overpriced iPhone X with a passcode. Or… buy a different phone that doesn’t use such a problematic unlocking mechanism.
 
Last edited:
The twin/doppelgänger part is of interest to me. I wonder how similar the two people need to look to fool FaceID? Even identical twins don't have the same fingerprints, yet TouchID is less reliable than FaceID. Just seems odd to me.
 
  • Like
Reactions: 5105973
What are the odds of my evil twin finding me for the sole purpose of stealing my iPhone X to try and get into it not knowing if I am even using FaceID?
Depends, do you live in the plot of a Nick Cage or John Travolta movie?
 
  • Like
Reactions: Ladybug
If the "Evil Twin" is a child under 13 does the X burst into flames?

This reminds me of when TouchID was announced and people (literally, go back and look...) asked "what if someone cuts off my finger, or incapacitates me and uses it to unlock my phone without me being conscious???".

It's what I like to call the "James Bond" fallacy:

If you are so important that someone would actively try to break into your phone by exploiting security considered "good enough" for millions of people, you need to re-evaluate what security you use on your phone.

But don't worry. You're not that important. It'll be fine.
 
Not too worried about it compared to Sammy’s phones which are fooled by a piece of paper.

Such non-news.

They’re sure glad to have the clicks & ad revenue though.
 
OMG! I can't believe Apple never mentioned that twins could possible fool Face ID!!! Well other than telling us in the keynote of course ;)

This will be REALLY bad for the 0.35% of the population that it affects and all those little kids who will be getting iPhone Xs :p
 
When my girlfriend's daughter first got her 6S, she setup the fingerprint reader. Then she handed it to me and asked me to unlock it. And I did on the first try. Keep in mind, there is no blood relationship between us. So the fact that a twin (which I don't have) might be able to unlock my phone isn't a giant concern to me. Nor do I see it as evidence that TouchID is better than FaceID.
 
Nothing really new evil twins and little kids are the achilles heel of every face id system on the market today apart from iris scanning (but that's not really face id).
 
Nothing really new evil twins and little kids are the achilles heel of every face id system on the market today apart from iris scanning (but that's not really face id).

Tell me about it. If I had a dollar for every time I wanted to secure my top secret data with my face structure alone, and then my freaking EVIL TWIN showed up, I'd have at leas...

Well the exact amount isn't important. The fact is, it's a terrible problem. Shame on Apple!
 
  • Like
Reactions: willmtaylor
Good grief! Paranoia seems to be epidemic! What in the world are people keeping on their phones??

I would suggest some folks need to get rid off their cell phones, unplug their computers, get off the grid, find a nice mountain lake and build a cabin!

Actually, that sounds like a pretty good plan!
 
Preparing to steal phone.

385_4.jpg
 
The twin/doppelgänger part is of interest to me. I wonder how similar the two people need to look to fool FaceID? Even identical twins don't have the same fingerprints, yet TouchID is less reliable than FaceID. Just seems odd to me.

Your comment made me think... The chances of having identical twins is much higher than one in a million, so either Apple's quoted security stats for FaceID are total crap or the system is so precise the small difference between most twins would still be spotted.
 
  • Like
Reactions: tardman91
Your comment made me think... The chances of having identical twins is much higher than one in a million, so either Apple's quoted security stats for FaceID are total crap or the system is so precise the small difference between most twins would still be spotted.

actually they were pretty clear about the stats. they say the chance is one in a million... UNLESS you have an identical twin or you are a child and with similar looking siblings. ;)

but they don't talk about the chances with twins at all. so it will be interesting to see the results of twins trying this out.

but let's be honest: one in a million does not sound like a number that came out of a real calculation... must have been heavily rounded for marketing
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.