• GrindingGears@lemmy.ca
    link
    fedilink
    arrow-up
    2
    ·
    18 hours ago

    So what do we do about my evil twin brother who is a supervillain?

    I didn’t believe this was a problem until I watched my wife and her twin sister unlocking each others phones (they aren’t identical but they do look quite a lot alike)

  • nebirus@beehaw.org
    link
    fedilink
    arrow-up
    20
    ·
    1 day ago

    It is good practice to create a different password for each service. That way, if one service is compromised, your adversary cannot use that password to unlock everything else.

    That may sound onerous, but thanks to selfie-login technology, you can instead simply use a different face for each account.

  • Hirom@beehaw.org
    link
    fedilink
    arrow-up
    50
    ·
    edit-2
    2 days ago

    It might be possible to fool it.

    More important, it’s normalizing use of facial recognition in everyday situations. This is a very invasive tech and prime for abuse by increasingly totalitarian governments.

  • oats@beehaw.org
    link
    fedilink
    arrow-up
    22
    arrow-down
    1
    ·
    2 days ago

    Yeah, thanks but no thanks.

    The biggest thing I’ll use is fingerprint on my phone, caus its comfy, and quickly disabled should the need arise

    • smeg@feddit.uk
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      That’s unlocking your phone, this is unlocking your entire Google account (e.g. on a new device)

      • webghost0101@sopuli.xyz
        link
        fedilink
        arrow-up
        2
        arrow-down
        3
        ·
        1 day ago

        Is that really that different?

        The article doesn’t go into any length to explain the technology. But assuringly its just an encrypted passcode created with an algorithm using measured face data.

        Crafting a secure reliable personal id based on pure visual appearance has been tricky and when this came out i disliked it but it was clearly a feat.

        What is the story here?

        Google trusting this technology?

        Them adding age verification to it?

        I am just confused what makes this enough of something to write/post it.

        • TehPers@beehaw.org
          link
          fedilink
          English
          arrow-up
          3
          ·
          edit-2
          1 day ago

          Your phone stores the code on the device and does facial recognition locally. Apps on your phone only receive that data if they explicitly request your camera and perform the recognition themselves.

          This is vastly different than sending Google a video of your face that they save on their servers and use to analyze future selfie videos.

          But assuringly its just an encrypted passcode created with an algorithm using measured face data.

          From the article:

          Selfie videos can be used for login purposes, to verify your age for accessing certain account features, and to create an AI avatar.

          It’s not just an encrypted passcode.

        • Ooops@feddit.org
          link
          fedilink
          arrow-up
          8
          ·
          edit-2
          1 day ago

          Is that really that different?

          Conceptionally yes. You can refuse to unlock your phone with your face. You cannot refuse to allow Google to access your account (and thus your phone, too) with a picture of your face -no matter how bad the tech is- if Google implements this.

        • jansk@beehaw.org
          link
          fedilink
          arrow-up
          8
          ·
          1 day ago

          Very different, I would say. The security implication of authorising you on a new device is much more severe than logging you into a device you are already authorised against.

          • smeg@feddit.uk
            link
            fedilink
            English
            arrow-up
            7
            ·
            1 day ago

            Exactly, someone spoofing the biometrics to unlock my phone relies on them having physical access, whereas spoofing the biometrics on an account that can be accessed anywhere in the world is quite a bit bigger of a threat

    • oats@beehaw.org
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      Maybe its “unlocking” stuff on your desktop browser with your phone, like the new captchas where you have to scan a QR and receive a code via SMS (seriously google, what the heck)