If your face is your password, every selfie you post is like giving away the md5 hash of your master passphrase.
Think about it. Facial recognition systems turn an image into a number and then decide if that number is a close enough resemblance to the number it has been told to trust.
That’s it! No magic. That’s (basically) all there is to it.
That’s it! No magic. That’s (basically) all there is to it.
Which means the only thing preventing a bad guy from authenticating as you with facial recognition is two things:
1. Can they send “attempted numbers” to the authentication system as if coming from your cam?
2. Can they guess a close-enough-resemblance number to trick the system?
1. Can they send “attempted numbers” to the authentication system as if coming from your cam?
2. Can they guess a close-enough-resemblance number to trick the system?
#1 is roughly equal to relying on security through obscurity- meaning that it’s only a matter of time and technical knowledge before the capability to send such an attempt is had by widespread bad actor populations.
The security provided by aspect #2 is decreased with every picture of you posted to the internet.
Facial recognition is inherently flawed as an authentication method and is degrading daily in reliability. Peak facial has passed.
Facial recognition is inherently flawed as an authentication method and is degrading daily in reliability. Peak facial has passed.