Liveness check in face unlock still not 100% secure - Samsung Galaxy Nexus

I recently had a theory that may have been tested before. While it isn't likely you'd let someone record your face blinking, it still made me wonder. I took a 6 second clip of myself blinking several times and played it in front of my face unlock screen and VOILÀ! My phone unlocked. Like I said it isn't likely, but possible.
I just wanted to share my findings with you guys and gals.
EDIT: I also thought it might be somewhat relevant to mention I recorded my face using the 3.2 MP camera on an old Samsung Moment.
Sent from my Galaxy Nexus using xda premium

Face unlock is not supposed to be secure (no one else can access your phone) but convenient (just look at your phone to unlock rather than punching in a PIN or pattern). It's been long accepted to be less secure than traditional protected lockscreens.

Pattern and PIN unlock is also not 100% secure because someone can peer over your shoulder when you type it.
Jokes aside, if it comes down to video recording the front of your face to gain access to your phone for an unlock method that isn't suppose to be a secure option anyways, then it's pretty darn good I'd say.

yep. If you are really worried about security you'll probably encrypt your device and then I don't think face unlock will even be an option.

My brother (not a twin) was able to unlock my phone with his face so it is definitely not secure..
Sent from my Galaxy Nexus using xda app-developers app

Who said it was supposed to be secure? It's just for showing it off to your friends and as the other guy said for convenience.
Sent from my Galaxy Nexus using xda app-developers app

Related

2nd Bad Phone

Got my first CDMA Nexus on the day released. Was running IMOSEYON's Kernel at 1.42ghz and phone suddenly rebooted. Nothing I did from that point on would write to memory. Tried 2 or 3 ways to restore factory image but it didn't clear sdcard (as it's supposed to). Tried to relock bootloader using fastboot and it would say it did so but was unlocked again upon a reboot. Finally returned it under insurance. Had to pay deductible since it was permenantely rooted even though I think there was an electrical problem in the memory write circuit.
Got new phone and all was well until I dropped the thing last weekend on tile and cracked the screen (first time in 4 years of smart phones). Everything still worked, but returned it under insurance after restoring factory images (successfully). Another $100 bucks down the drain.
Got new phone. Set everything up and it started random reboots - particularly when charging. Reloaded CMR recovery that had worked so well. Still randomly rebooting.
Insurance is sending me my 4th phone in a month and a half (free this time). I broke one, but two out of three appear to have been duds. Quality control issues???
Anybody else having this kinda problem? I've used (rooted and rom'ed) an HTC Incredible, Droid Charge, Asus Transformer and Kindle Fire with no (permanent) problems. This is, frankly, disappointing.
HAve you tried using your phone stock without messing around with ROMS or bootloaders and custom kernels?
The majority of problems I've had with these types of devices have been with non-stock units...
It's probably because you are over clocking. Charging and using the phone with an overclocked processor generates a lot of heat. The phone will reboot on its own to save it from frying.
Scan the forums, other than your cracked screen you are describing known or soon to be known issues with the SGN.
I'm also on my fourth SGN. First had a line under the screen that looked like a crack. The next two had the lock up reboot issue and the one I'm on now isn't showing all the virtual SD space that all the others I received had, it's two gigs short.
It appears that quality control at Samsung is not as comprehensive as it should be.
Sent from my Galaxy Nexus using xda premium
If you want to complain on the phone then you should have stock room, if not you should complain in the rom thread. It sounds as if you have not had problems with the phone itself(on any of the phones), it sounds as if you have tampered with it. If so you shouldn't complain about the phone.
QuadFather said:
Scan the forums, other than your cracked screen you are describing known or soon to be known issues with the SGN.
I'm also on my fourth SGN. First had a line under the screen that looked like a crack. The next two had the lock up reboot issue and the one I'm on now isn't showing all the virtual SD space that all the others I received had, it's two gigs short.
It appears that quality control at Samsung is not as comprehensive as it should be.
Sent from my Galaxy Nexus using xda premium
Click to expand...
Click to collapse
How much space shows? Mine is 13.3 gb.
Sdobron said:
How much space shows? Mine is 13.3 gb.
Click to expand...
Click to collapse
My total capacity shows 28 GB.
Sent from my Galaxy Nexus using xda premium
I'm also on my second defective Galaxy Nexus in a week. The first had horrible banding even at full brightness and a glitchy accelerometer or compass. You could open Google Sky Map and sit the phone on a table and watch it jump around the night sky. The new one has a creaky case, a green cluster of dead pixels in the center of the screen, and all of the greys are royal purple. Not cool. Samsung needs to work on their quality control.
If my third is a bum unit, I'm going either Razr MAXX or D4.
Sent from my Galaxy Nexus using Tapatalk
QuadFather said:
Scan the forums, other than your cracked screen you are describing known or soon to be known issues with the SGN.
I'm also on my fourth SGN. First had a line under the screen that looked like a crack. The next two had the lock up reboot issue and the one I'm on now isn't showing all the virtual SD space that all the others I received had, it's two gigs short.
It appears that quality control at Samsung is not as comprehensive as it should be.
Sent from my Galaxy Nexus using xda premium
Click to expand...
Click to collapse
Can you please explain what lock up reboot issue means?
I am on my second sgn after discover a hair like crackon the screen.
erkv said:
Can you please explain what lock up reboot issue means?
I am on my second sgn after discover a hair like crackon the screen.
Click to expand...
Click to collapse
The phone would become unresponsive and reboot itself. Sometimes it would say the headset was connected and I would lose the microphone and speakers which was terrible when I was on a call because the other party couldn't hear me any more and I couldn't hear them. It was terrible. Sometimes it would force reboot multiple times in the course of a few minutes. I even tried just running plain stock but it made no difference.
Sent from my Galaxy Nexus using xda premium

[Q] Round up of BL Unlock Allowed: No Rumors, Theories and Experiences

Right, I have a R800i aka Xperia play from O2-UK
I have BL Unlock allowed: no (guessable from the title)
Before I take the plunge of paying $15 of my cash to some guy whom just happens to have bought the SETool box I want to 'verify' that all the Legends around the various myths are lies and that I coud'nt have avoided spending $15.
Firstly, a while ago I saw a guy post up that he also had a super-annoying-sony-carrier-love-locked-bootloader and he used S1Tool and unlocked it. Is this true? Any experiences? Here's the Original thread
Next, I came across several sites fastgsm and wotanserver, fonefunshop - both offered to do the service but required you to have 12W12 thing on the back. I have higher - 11W46 in fact.
Any other rumours? anyone?
I have it SIM UNLOCKED. And no matter how many times I talk to O2 the support is useless - they say check PC Companion and other stuff.
I'm ready to part with a maximum of $10. It's not like the $5 will kill me it's just I don't want to pay some random guy money cos you know - he'll run off with a joyful face and if it then turns out his hickary and ajigary did'nt work I'll be back at square one only with $15 less cash
Even if it say no, if you plug in the device when its off while holding the search, and the blue light turns on, then you maybe likely still be able to unlock it. If not, then you'll have to pay. Out side of those website which I haven't tried, there are only two person I am aware of that provide this unlocking server and they both are professional. Also I don't think they make any profit from it, though someone else will know better about this.
I used Wotan server and within 5 minutes of paying 7.99 EUR I had an unlocked boot loader
Quick easy and simple
Sent from my R800i using xda app-developers app
I have an r800i and was able to unlock its bootloader on my own without paying anything. I used the method wherein you'll stick a paper clip and wiring thing, just googled bootloader unlock and was able to get the 3 method to do so and did the best out of 3. Back then even if my bootloader is unlocked, it won't brick via OTA update. It was in youtube.
sent from Xperia PLAY™ via Tapatalk™
Should also mention my boot loader unlock status was no
Sent from my R800i using xda app-developers app
eksasol said:
Even if it say no, if you plug in the device when its off while holding the search, and the blue light turns on, then you maybe likely still be able to unlock it. If not, then you'll have to pay. Out side of those website which I haven't tried, there are only two person I am aware of that provide this unlocking server and they both are professional. Also I don't think they make any profit from it, though someone else will know better about this.
Click to expand...
Click to collapse
No blue light . I think I know the two people you're talking about
Xperia Unlock Service being one
and the other PhoneUnlockServer
As I said I'm prepared to pay it's just I would feel way more secure paying someone like wotanserver rather than a guy or girl (That I know literally nothing about other than he/she unlocks phones)
ILikeTheWayYouMove2 said:
I used Wotan server and within 5 minutes of paying 7.99 EUR I had an unlocked boot loader
Quick easy and simple
Sent from my R800i using xda app-developers app
Click to expand...
Click to collapse
What does your sticker under the battery say? I mean the **W** mine goes 11W46 (Meaning it was made in 2011 in the 46th week )
Wotan server says you need less than 12W12 for their trick to work. SO am I right in assuming it will work for me? Any experiences with 11W46? 12W12 should mean it was made in the year 2012 and in the 12th week. That should mean mine is earlier right?
nanoadmin said:
No blue light . I think I know the two people you're talking about
Xperia Unlock Service being one
and the other PhoneUnlockServer
As I said I'm prepared to pay it's just I would feel way more secure paying someone like wotanserver rather than a guy or girl (That I know literally nothing about other than he/she unlocks phones)
What does your sticker under the battery say? I mean the **W** mine goes 11W46 (Meaning it was made in 2011 in the 46th week )
Wotan server says you need less than 12W12 for their trick to work. SO am I right in assuming it will work for me? Any experiences with 11W46? 12W12 should mean it was made in the year 2012 and in the 12th week. That should mean mine is earlier right?
Click to expand...
Click to collapse
Yeh you should be good mine was like 11w11 or something like that but its so easy using wotan and cheaper and they have a good customer service
Sent from my R800i using xda app-developers app
ILikeTheWayYouMove2 said:
Yeh you should be good mine was like 11w11 or something like that but its so easy using wotan and cheaper and they have a good customer service
Sent from my R800i using xda app-developers app
Click to expand...
Click to collapse
Hey, did you use Testpoint or was it software based? I'll probably try it this week sometime anyway but just curious.
Was test point but there's a video tutorial showing you what to do its pretty fool proof
Sent from my R800i using xda app-developers app
ILikeTheWayYouMove2 said:
Was test point but there's a video tutorial showing you what to do its pretty fool proof
Sent from my R800i using xda app-developers app
Click to expand...
Click to collapse
YEs if you download the unlock tool for the xperia play on wotanserver.com it has an embedded video detailing what to do.
There! Thats what i used to unlock my BL the test point, look for bootloader unlock xperia play on youtube, theres a link on where to download software so you can do it on your own and without paying service wherein you have to be in teamview. Anyone confident enough can unlock thier own device using this method.
sent from Xperia PLAY™ via Tapatalk™
Took the plunge of wotanserver.
So i paid Wotanserver €8 (£7 (or equivalent in local currency))
PayPal immediately messaged me saying that "You sent a payment of €7.99 EUR to WahWai Electronic Technology Limited ([email protected])" FastGSM hmmmmmm........ Doesn't it ring a bell.
Anyway the setup was painless, literally open the setup file. All the drivers will be installed along the way of the install procedure. Handy.
Then you open up the thing and tell it your phone model it goes OK, shows you a little video how to connect the testpoints (Calls it TP to GND Connection presumably pronounced TiiPe too GRRRRRnd) Anyway, connect the phone as shown, it goes oh yeah, phone detected checks your account balance and does the BL unlocking.
The monetary transfer literally took no time at all (Excl the time I spent typing in my PayPal details)and the actuall process took less than 10s (no joke)
If you consider using wotanserver though try to do the whole process without credits so you know if your phone works to avoid disappointment after you paid - Select model and connect it the softwre will say 'checking account' and then say not enough credits if it can unlock the phone but won't due to insufficient money. Try it first, pay it and do it again later.
Overall it worked! My phone is now unlocked the bootloder has a version of r9******* (not censored just can't remember) and even the little BL unlock allowed status has been set to yes :laugh:
Now just need to get CWM on there and flash a decent ROM. But that's a different issue.
Thanks for all your help guys (and girls)

[Q] HTC Warranty repairs & htcdev unlock, my experience so far and a question..

OK, So here's my situation with HTC Warranty repairs: (Long explanation of my back-story, scroll down to bold type if you just want to read the question)
My Verizon HTC one, I purchased the first day it was available, and promptly unlocked through htcdev.com. Following that I installed a custom recovery and rooted. I remained on stock ROM, but did get rid of some bloat as well as installed wifi tether.
So, while charging it one day. It got extremely hot and I smelled that "magic smoke" that all electronic devices seem to run on. I quickly unplugged the charger, and saw that the usb plug had started melting slightly, and there were black "charred" marks around the phone's USB port. After this my bottom speaker failed to work, making only a clicking noise anytime audio was played. The top speaker was unaffected. More importantly, the usb port failed to sync properly to my computer. The computer would not recognize my phone. Yikes!
Due to 2 drops of my DNA and cracked screens, I had no insurance on my HTC ONE. Figured I had to contact HTC and see what could be done. They had me do some diagnostics (*#*#3424#*#*), etc... and determined it needed to be sent in for repair. Knowing I had unlocked and tampered flags displayed on my phone, this is where I thought to myself, ugh, I think I may be screwed. Worse yet, when I tried to do a wipe, I must've hit the wrong option, and the phone was soft-bricked. Would not go past the green HTC screen. I could boot into fastboot, and recovery, but could not access fastboot USB mode. Since my phone would not connect to the computer properly, I could not fix it. OK, cross my fingers and sent it in this past Monday 9/30, they received it on Wednesday 10/2.
At this point, I'm thinking I'm certainly going to have to pay for repairs, knowing I made the matters much worse when I did the wipe. But to my surprise, it seems that they have repaired my phone and it's on it's way back to me. So either they did not and will not fix it and sent it back as -is (unlikely) or they fixed it under warranty with no charges.
SO HERE'S MY QUESTION:
Knowing they must have loaded factory fresh software making it locked again, can I use the same unlock code from htcdev? If they had to replace the mainboard, would this mean my unlock code may no longer work? (Does the IMEI change, or anything?)
They shipped it out Friday 10/4 and I will get it back on Wednesday 10/9. I will post updates with what I find, but was just curious. I also wanted to share my experience with HTC Warranty Repair.
Thanks,
Flip
I really have no idea if you can use the same token from htcdev, but I recall that it only cost me a small amount of time (no money) to get a code from htcdev, so why screw around experimenting? Just get a new unlock code.
Flip_5 said:
OK, So here's my situation with HTC Warranty repairs: (Long explanation of my back-story, scroll down to bold type if you just want to read the question)
My Verizon HTC one, I purchased the first day it was available, and promptly unlocked through htcdev.com. Following that I installed a custom recovery and rooted. I remained on stock ROM, but did get rid of some bloat as well as installed wifi tether.
So, while charging it one day. It got extremely hot and I smelled that "magic smoke" that all electronic devices seem to run on. I quickly unplugged the charger, and saw that the usb plug had started melting slightly, and there were black "charred" marks around the phone's USB port. After this my bottom speaker failed to work, making only a clicking noise anytime audio was played. The top speaker was unaffected. More importantly, the usb port failed to sync properly to my computer. The computer would not recognize my phone. Yikes!
Due to 2 drops of my DNA and cracked screens, I had no insurance on my HTC ONE. Figured I had to contact HTC and see what could be done. They had me do some diagnostics (*#*#3424#*#*), etc... and determined it needed to be sent in for repair. Knowing I had unlocked and tampered flags displayed on my phone, this is where I thought to myself, ugh, I think I may be screwed. Worse yet, when I tried to do a wipe, I must've hit the wrong option, and the phone was soft-bricked. Would not go past the green HTC screen. I could boot into fastboot, and recovery, but could not access fastboot USB mode. Since my phone would not connect to the computer properly, I could not fix it. OK, cross my fingers and sent it in this past Monday 9/30, they received it on Wednesday 10/2.
At this point, I'm thinking I'm certainly going to have to pay for repairs, knowing I made the matters much worse when I did the wipe. But to my surprise, it seems that they have repaired my phone and it's on it's way back to me. So either they did not and will not fix it and sent it back as -is (unlikely) or they fixed it under warranty with no charges.
SO HERE'S MY QUESTION:
Knowing they must have loaded factory fresh software making it locked again, can I use the same unlock code from htcdev? If they had to replace the mainboard, would this mean my unlock code may no longer work? (Does the IMEI change, or anything?)
They shipped it out Friday 10/4 and I will get it back on Wednesday 10/9. I will post updates with what I find, but was just curious. I also wanted to share my experience with HTC Warranty Repair.
Thanks,
Flip
Click to expand...
Click to collapse
Yes your unlock code will stop working but the exploit is coming soon so it's okay
Sent from my HTC6500LVW using xda app-developers app
jpradley said:
I really have no idea if you can use the same token from htcdev, but I recall that it only cost me a small amount of time (no money) to get a code from htcdev, so why screw around experimenting? Just get a new unlock code.
Click to expand...
Click to collapse
You must be thinking of another phone because right now on vzw the only way to unlock is s-off
Sent from my HTC6500LVW using Tapatalk now Free
dottat said:
You must be thinking of another phone because right now on vzw the only way to unlock is s-off
Sent from my HTC6500LVW using Tapatalk now Free
Click to expand...
Click to collapse
Oops -- I did forget to note that before htcdev can do anything (old code or new) the phone has to first be in S-OFF mode, which at the moment means availing oneself of Sonic's service.
I am guessing he got htc dev unlock day 1 like me.
but it's a different phone so, ... no.. it wont work..
Based on your description, there's gotta be a 0% chance you're getting the same device back. Shouldn't you be getting a replacement?
If the return report says "repaired" I'm betting that's a communication error from a lazy/sloppy tech.
-Matt
We really gotta work on finding that special secret tool they (HTC) has to pop these phones apart easy
Sent from my Nexus 7 using Tapatalk 4
dottat said:
We really gotta work on finding that special secret tool they (HTC) has to pop these phones apart easy
Sent from my Nexus 7 using Tapatalk 4
Click to expand...
Click to collapse
I'd venture a guess that the aluminum body isn't really something HTC cares about; the innards are the expensive bits. HTC probably just peels back the case, makes sure the components are in working order (and a complete reflash), and then just throw everything in a new outer case. Simple, fast, and doesn't require slow-and-careful disassembly. Again, this is just a complete guess, though it seems logical.
Rain724 said:
I'd venture a guess that the aluminum body isn't really something HTC cares about; the innards are the expensive bits. HTC probably just peels back the case, makes sure the components are in working order (and a complete reflash), and then just throw everything in a new outer case. Simple, fast, and doesn't require slow-and-careful disassembly. Again, this is just a complete guess, though it seems logical.
Click to expand...
Click to collapse
would be sick if the backs came off easy(er)
I'd def purchase the blue and red and black, and switch.
andybones said:
would be sick if the backs came off easy(er)
I'd def purchase the blue and red and black, and switch.
Click to expand...
Click to collapse
That's would be awesome... I really wanted blue.,.
Sent from my HTC6500LVW using xda app-developers app
HTC has been quoted as saying they have such a tool...we just gotta find out who has such a tool.
http://www.engadget.com/2013/07/10/htc-one-repair-justin-huang/
Sent from my Nexus 7 using Tapatalk 4
Rain724 said:
I'd venture a guess that the aluminum body isn't really something HTC cares about; the innards are the expensive bits. HTC probably just peels back the case, makes sure the components are in working order (and a complete reflash), and then just throw everything in a new outer case. Simple, fast, and doesn't require slow-and-careful disassembly. Again, this is just a complete guess, though it seems logical.
Click to expand...
Click to collapse
While I agree that the body is probably not that expensive, most of the tear down videos I have seen also destroy the glass and some times the screen. So your general theory does not hold up... the "innards" get broken too. I hope the posts about the "magic" tool to open the back are true, and really, it only makes sense. You have to be able to service and refurbish the phone otherwise the costs would sky rocket.

Question about Imprint sensor

Hello xda,
I've been using my 5X for a few months and I'm happy with the device. Hovewer, there is one thing that annoys me, the fingerprint sensor, which is trying to read my fingers, when the phone is hidden into pocket, and when I want to unlock phone using my finger, it warns me about "too many tries, please try again later" (screen in attachment). Is it possible to make Imprint work only if the screen is on?
Thanks in advance.
Face your phone with the screen towards your leg. Issue solved. Your screen is less likely to break in that position if something accidentally hit it.
Sent from my SM-G930V using Tapatalk
Yep, that's what I'm doing since I observed the problem, but then I don't see the notfication LED
PS partially solved, because I'm asking for a software hack
przemcio510 said:
Yep, that's what I'm doing since I observed the problem, but then I don't see the notfication LED
PS partially solved, because I'm asking for a software hack
Click to expand...
Click to collapse
You can see the LED through your pants when it's facing out? Are they made from saran wrap?
Sent from my SM-G930V using Tapatalk
PiousInquisitor said:
You can see the LED through your pants when it's facing out? Are they made from saran wrap?
Sent from my SM-G930V using Tapatalk
Click to expand...
Click to collapse
No, but I'm pulling out the phone a little bit to make sure I got a new notification.
And this is going offtopic.
przemcio510 said:
No, but I'm pulling out the phone a little bit to make sure I got a new notification.
And this is going offtopic.
Click to expand...
Click to collapse
Anyway, it's currently not possible to make the sensor only work when the phone is on. That would require first and foremost an unlocked bootloader. Then you would need to download the kernel source (I'm pretty sure that's what controls the sensor) and modify it to do what you want. Then you would need to flash it to your device. Good luck.

note 10 face unlock

here is the link of the other thread . i tried it on note 10+ 5g too . i can unlock my cousin's phone with face unlock . i remove the face unlock on my phone just because of my cousins can unlock it . we not even looks same
https://forum.xda-developers.com/s10-plus/how-to/galaxy-s10-recognition-hack-t4004345 check my thread
https://www.youtube.com/watch?v=nuCwoeofx9o
Face unlock in android phones isn't secure and it's not something new.
jahanzaiblohani said:
here is the link of the other thread . i tried it on note 10+ 5g too . i can unlock my cousin's phone with face unlock . i remove the face unlock on my phone just because of my cousins can unlock it . we not even looks same
https://forum.xda-developers.com/s10-plus/how-to/galaxy-s10-recognition-hack-t4004345 check my thread
https://www.youtube.com/watch?v=nuCwoeofx9o
Click to expand...
Click to collapse
You shouldn't have made another thread to talk about the same issue.
To be honest Samsung has clearly said this method of unlock is less secure. That is, anyone who looks like you (doesn't matter if you don't think they do) can unlock the phone. It's also reported on the internet that Samsung has said face unlock is primarily a way to expedite access to the phone. In other words it's a convinience feature. Here's one link to an article on the subject.
https://www.techradar.com/news/sams...rprint-scanner-not-face-unlock-to-stay-secure
Basically this isn't face ID, the phone cannot perform 3D mapping of your face... The note 10+ has a 2D front facing camera that takes a 2D image of your face and compares it with the 2D images of whoever's face it sees when someone tries to unlock it.
You can try a few things and see if it helps. Try removing your face from your phone and re-register again... But this time make sure that your doing it in a brighter place (with more ambient lighting) and try again. Registering in poor lighting can cause accuracy issues. Facial hair, glasses, and etc can also cause accuracy issues.. so you might run into problems no matter what you do.
Also turn off Faster Recognition, you have it enabled on the phone. While it will increase the speed of facial recognition it comes at the price of reduced security/accuracy of said recognition.
For me I don't like face unlock on android. Only Huawei Mate 20 Pro has 3D face recognation as Apple iPhone's. Fingerprint works perfect on my note. I gave to arround many prople in work to unlock my phone and result was unsucessful for other people. So I trust fingerprint. I want Samsung add killswitch as on iPhones. If you have stolen iPhone you are 100% out of luck to bypass icloud. Why Samsung can't make like this, independent from Android self. Integrate own secure killswitch. Sure on rooted phone you can put some software which gonna work even after flash firmware. But I don't want to root phone.
Sent from my SM-N976B using Tapatalk
samsung: its not secure , we've told u this
pakistani: hacckermann
Who really cares.. Honestly.. It's been said a million times its not secure, so if you use it.. Oh well.. For Samsung, they should have stuck with the iris scanners.. But they are idiot's when it comes to"keeping" good tech on their devices..
Sent from my Note 10+ using Tapatalk

Categories

Resources