3D Printed Mask Fools iPhone X Face ID

Unmasking the iPhone X Face ID: How a $150 3D Printed Mask Challenged Apple’s Security Promises

The launch of the iPhone X in September marked a significant milestone for Apple, celebrating a decade of its iconic smartphone series. More than just an incremental upgrade, the iPhone X introduced a suite of revolutionary features, chief among them the innovative Face ID facial recognition system. Heralded by Apple as a secure and seamless way to unlock the device, authenticate payments, and access sensitive data, Face ID was presented as a pinnacle of biometric security. Apple’s marketing emphasized the system’s accuracy and robustness, assuring users that their faces were the ultimate key to their digital lives. However, this confidence was swiftly challenged, as merely days after its global release, a cybersecurity firm named Bkav demonstrated a startling vulnerability, bypassing Face ID using nothing more than a meticulously crafted 3D printed mask.

Priced at a premium, starting at $999 in the USA and £995 in the UK, the iPhone X was positioned as Apple’s most sophisticated and secure smartphone to date. Beyond Face ID, it boasted an array of cutting-edge technologies designed to redefine the smartphone experience. These included the vibrant and immersive OLED (Organic Light Emitting Diode) screen, which delivered stunning visuals with true blacks and exceptional contrast; wireless battery charging capabilities, offering unparalleled convenience; and seamless compatibility with the ARKit, Apple’s augmented reality development platform, which promised transformative interactive experiences. Yet, amidst this technological marvel, the central pillar of its security, Face ID, became the subject of intense scrutiny following Bkav’s audacious demonstration.

bkav

The mask which cracked the iPhone X’s Face ID

Apple’s Bold Claims: The TrueDepth Camera and Unmatched Security

At the heart of Face ID lies Apple’s sophisticated TrueDepth camera system. This advanced technology projects over 30,000 invisible infrared dots onto the user’s face, creating a unique, detailed 3D map. This map is then analyzed by a neural network, a form of artificial intelligence, to match against the enrolled facial data. Apple proudly asserted that the probability of someone else unlocking a user’s iPhone X with Face ID was approximately one in a million, a significant improvement over Touch ID’s one in 50,000 chance. This statistic was intended to instill a profound sense of security in users, especially concerning sensitive operations like Apple Pay and unlocking the device.

To bolster these claims, Apple’s VP of Marketing, Phil Schiller, revealed that the company had collaborated extensively with Hollywood special effects artists and mask experts. The purpose of this collaboration was to rigorously test Face ID against various forms of imitation, including highly realistic masks. The implication was clear: Face ID was designed to be virtually unhackable by conventional means, sophisticated enough to differentiate between a live human face and even the most convincing replica. This proactive approach by Apple aimed to preemptively address security concerns and reinforce the perception of Face ID as a truly secure and reliable biometric authentication method for the modern age. The industry and consumers alike largely accepted these assurances, eager to embrace the convenience of facial unlock technology.

Fooled by a $150 Mask: Bkav’s Groundbreaking Exploit

Despite Apple’s robust assertions and extensive testing, a mere week after the iPhone X’s official release, the cybersecurity world was shaken by an announcement from the Vietnamese firm Bkav. They declared that they had successfully bypassed Face ID using a custom-made 3D printed mask. This revelation directly contradicted Apple’s claims of invulnerability and sent ripples of concern through the tech community and among iPhone X owners. The exploit was not the result of a highly secretive, multi-million dollar government project, but rather a relatively accessible, low-cost endeavor, highlighting a potential Achilles’ heel in Apple’s much-touted security system.

Bkav’s demonstration video, while not providing a step-by-step tutorial on the mask’s creation, clearly showcased its effectiveness, depicting the mask effortlessly unlocking the iPhone X. The company detailed that the mask, costing roughly $150 (€127) to produce, was a composite creation. It utilized a 3D printed base to replicate the contours and dimensions of the phone owner’s face, providing the foundational structure. This base was then enhanced with materials like silicone and plastic for realistic texture and flexibility, paper for specific details, and makeup to achieve accurate color and subtle facial features. Crucially, Bkav claimed that this could be achieved with a popular consumer-grade 3D printer, emphasizing the alarming accessibility of such an attack.

Ngo Tuan Anh, Vice President of Bkav, elaborated on the intricate process behind their success: “The mask was made by combining 3D printing, makeup, and 2D images, as well as a special treatment on the cheeks and the rest of the face. Especially the large areas of skin, to deceive the artificial intelligence of Face ID.” This “special treatment” likely involved careful attention to how different materials reflect infrared light, mimicking the texture and depth data that the TrueDepth camera system relies on. By meticulously recreating not just the visible appearance but also the underlying structural and reflective properties of a human face, Bkav was able to trick the neural network, bypassing the very intelligence Apple had designed to prevent such exploits.

The demonstration video made by Bkav served as undeniable proof of their findings:

 

Bkav: A History of Exposing Cybersecurity Flaws

Bkav is not a newcomer to the realm of cybersecurity research and vulnerability disclosure. With a reputation built on years of demonstrating critical flaws in prominent systems, the company has established itself as a leading authority in digital security. Their track record includes significant exploits, such as uncovering a major vulnerability in Google Chrome within days of its initial release in 2008. This swift identification of a critical flaw underscored their technical prowess and dedication to proactive security research. Furthermore, Bkav also successfully traced the origins of an unprecedented Distributed Denial of Service (DDoS) attack to servers located in the United States, showcasing their capabilities in digital forensics and attribution.

These past achievements lend considerable credibility to their iPhone X Face ID hack. It wasn’t a random opportunistic act but rather part of a focused and systematic effort. In recent years, Bkav has explicitly set out to highlight the inherent insecurities in facial recognition technologies adopted by various major tech companies. Their research has targeted systems from manufacturers such as Toshiba, Lenovo, and Asus, in addition to Apple, demonstrating a broader concern about the efficacy and reliability of biometric authentication across the industry. Their consistent goal has been to prove that despite their convenience and perceived sophistication, many current facial recognition solutions are simply not robust enough to withstand determined attacks, urging companies and users alike to adopt a more cautious and critical perspective on these technologies.

Implications for Biometric Security and the Future of Authentication

The successful bypass of Face ID by Bkav carries profound implications for the entire landscape of biometric security. For the average iPhone X user, it raises legitimate concerns about the security of their personal data, financial transactions, and overall privacy. If a relatively inexpensive and accessible method can defeat a system touted as “one in a million” secure, it forces a re-evaluation of trust in biometric authentication as a standalone security measure. This event highlighted the critical importance of “liveness detection” – the ability of a biometric system to confirm that the presented sample is from a living person, not a static representation. While Face ID does incorporate some liveness detection features, Bkav’s mask demonstrated that these were not foolproof against sophisticated physical replicas.

Beyond individual device security, the incident sparked a wider debate about the future of authentication. It underscored the potential for 3D printing technology, a tool with immense potential for innovation and creation, to also be leveraged for malicious purposes. The ease with which a “consumer 3D printer” could be involved in such an exploit means that the barriers to entry for advanced security bypass techniques are significantly lowered. This event serves as a crucial reminder to security professionals and developers that while biometrics offer convenience, they must be continuously strengthened with multi-factor authentication and improved liveness detection algorithms. The challenge now lies in developing systems that can adapt to ever-evolving threats, ensuring that convenience does not come at the cost of genuine security in an increasingly digital world.

Having second thoughts about using your iPhone’s facial recognition? Share your perspective and join the conversation by leaving a comment below or engaging with us on our Facebook and Twitter pages! Don’t miss out on the latest advancements and news in the exciting world of 3D printing; make sure to sign up for our free weekly Newsletter, delivered straight to your inbox!

Sources and photos: Bkav and Reuters (Mai Nguyen, Jeremy Wagstaff, Ian Geoghegan)