3D Printed Head Cracks Smartphone Facial Recognition

How a 3D Printed Head Exposed Major Flaws in Smartphone Facial Recognition Security

In an age where smartphone security is paramount, and facial recognition has become a ubiquitous feature, the claims of impenetrability often go unchallenged. However, a groundbreaking investigation by renowned Forbes reporter Thomas Brewster not long ago starkly demonstrated that the facial recognition systems of even the most well-known smartphone brands are not always as secure as advertised. To decisively prove his point, Brewster commissioned and successfully utilized a highly detailed 3D printed replica of his own head, revealing surprising vulnerabilities in popular devices.

The meticulous development of this lifelike 3D printed head was entrusted to Backface, a specialized company based in Birmingham, United Kingdom. Their sophisticated process involved the use of an advanced scanning setup, employing no fewer than 50 cameras to capture every minute detail of Thomas Brewster’s face. This comprehensive scan allowed them to generate an extraordinarily accurate 3D digital model, encompassing all the intricate contours and features of his physiognomy. Within just a few days, and at a cost of approximately £300, the physical replica was manufactured using cutting-edge powder binding technology. This rapid and relatively affordable process yielded a life-size, remarkably realistic replica of the reporter’s head, ready for its critical security tests.

The Experiment Unveiled: How a 3D Printed Head Fooled Leading Operating Systems

Once Thomas Brewster had his meticulously crafted 3D printed head in hand, he embarked on a series of rigorous tests targeting some of the most popular and supposedly secure smartphones on the market. These devices are widely considered to feature state-of-the-art facial recognition systems, integral to their user authentication and data protection. The lineup of phones chosen for the experiment included prominent models such as the Samsung Galaxy S9, OnePlus 6, Galaxy Note 8, and LG G7 ThinQ, alongside the Apple iPhone X. The results were immediate and strikingly clear: the phones operating on the Android system were easily fooled by the 3D printed head. The iPhone X, notably, was the only device that demonstrated truly impenetrable potential throughout the entire testing process, consistently resisting the spoofing attempt.

3D printed head

An impression of the journalist’s face, replicated with astonishing accuracy. Source: Forbes

Delving Deeper: The Core Differences in Facial Recognition Technology

The fundamental reason behind the disparate results – why the 3D printed head could unlock some devices but not others – lies in the underlying quality, sophistication, and speed of their respective facial recognition systems. Apple’s Face ID, for instance, utilizes a highly advanced system that goes far beyond a simple 2D scan. It employs a TrueDepth camera system to project over 30,000 invisible infrared dots onto the user’s face, creating a precise and unique depth map. This detailed 3D map, combined with infrared image analysis, makes it exceptionally difficult to fool with a flat image or even a sophisticated 3D replica, as it checks for genuine depth and three-dimensionality.

In stark contrast, many other smartphones, particularly those running the Android operating system, often depend primarily on the device’s standard selfie camera for facial recognition. These systems typically perform a faster, more superficial scan that largely relies on 2D image analysis. While this approach offers convenience and speed, it inherently compromises on actual scanning security. A 2D-based system can struggle to differentiate between a live human face and a high-quality, three-dimensional replica, as it lacks the depth-sensing capabilities necessary to detect the subtle nuances and genuine three-dimensionality of a living person. This reliance on less robust technology renders these devices susceptible to “spoofing” attempts, as demonstrated by Brewster’s experiment.

The Alarming Implications: Security Warnings and Expert Opinions

Thomas Brewster’s investigation unequivocally revealed that none of the Android phone manufacturers achieved the same rigorous level of security and accuracy as Apple’s Face ID. More critically, he highlighted that companies like LG and Samsung even include explicit warning messages within their device settings. These disclaimers caution users that facial recognition on their devices may not be as secure as traditional methods like using a PIN, password, or pattern. This vital information, often overlooked by users prioritizing convenience, underscores a critical vulnerability in many biometric systems.

For Android users who prioritize their digital security and personal data protection, the clear takeaway is a strong recommendation to either avoid using facial recognition altogether or, at the very least, to rely on a robust password or PIN lock as their primary security measure. This ensures a more resilient defense against potential unauthorized access, even from sophisticated spoofing attempts like those employing 3D printed replicas.

3D printed head

The recognition test in progress. Source: Forbes

Adding further weight to these findings, Matt Lewis, a research director at the cybersecurity contractor NCC Group, provided a crucial expert perspective. He advised users to “Focus on the secret aspect, which is the PIN and the password.” Lewis further elaborated on the inherent limitations of biometric authentication: “The reality with any biometrics is that they can be copied. Anyone with enough time, resource and objective will invest to try and spoof these biometrics.” This statement serves as a stark reminder that while biometrics offer convenience, they are not infallible. Unlike a password, which is a secret piece of knowledge, a biometric is a physical attribute that, with sufficient effort and technology, can potentially be replicated or spoofed. This highlights the ongoing cat-and-mouse game between security measures and those attempting to circumvent them.

Safeguarding Your Data: Best Practices in a Biometric World

Given these compelling revelations, it is imperative for users to adopt a more cautious approach to smartphone security. To mitigate the risk of someone potentially 3D printing your head and gaining unauthorized access to your sensitive data, it is always prudent to employ a strong, unique password or PIN in addition to, or even in place of, facial recognition. A complex alphanumeric password or a lengthy, non-obvious PIN offers a robust layer of security that relies on knowledge rather than a physical attribute, making it significantly harder to compromise through physical replication.

Beyond simply choosing a password, adopting a holistic approach to cybersecurity is crucial. This includes enabling multi-factor authentication (MFA) wherever possible, especially for critical accounts like banking, email, and social media. MFA adds an extra layer of security by requiring two or more verification factors to gain access, such as a password combined with a code sent to your phone. Regularly updating your device’s operating system and applications is also vital, as these updates often include critical security patches that address newly discovered vulnerabilities.

Furthermore, users should exercise caution with the information they share online and be aware of potential social engineering tactics. While the technology for 3D printing a head is becoming more accessible, it still requires detailed scans or images. By being mindful of your digital footprint and the visual data you expose, you can further reduce the risk of becoming a target for such sophisticated spoofing attacks. Ultimately, the balance between convenience and security is a personal choice, but being informed about the limitations of biometric systems empowers users to make smarter, more secure decisions about their digital lives.

For those interested in the full scope of Thomas Brewster’s fascinating investigation and the detailed test methodology, the complete article is available on the official Forbes website. You can find it HERE.

What are your thoughts on the alarming possibility of infiltrating a phone with a 3D printed head? Does this revelation change how you perceive or use facial recognition on your devices? We encourage you to share your insights and opinions in a comment below or join the conversation on our Facebook and Twitter pages! Don’t forget to sign up for our free weekly Newsletter to stay updated with all the latest news, innovations, and security insights in the world of 3D printing, delivered straight to your inbox!