PHOTO: APPLE

iPhone X Face ID May Risk User's Facial Data

The iPhone X releases today, and with it come more concerns about the privacy and security of its new Face ID feature.

The iPhone X releases today, and with it come more concerns about the privacy and security of its new Face ID feature.  While Apple has stated since it announced Face ID that the user’s facial data is encrypted and stored securely on the iPhone X, application developers may be allowed to take certain facial data from user’s phones.

Apple’s Face ID allows users to unlock their phone by simply making direct eye contact with it. Face ID works by taking the user’s image and a dot pattern created by projecting more than 30,000 invisible dots onto their face to make a mathematical model.

Apple says this biometric data never leaves the device itself and is stored in an encrypted form on the phone’s secure enclave. The data then cannot be accessed by the operation system or any applications on the phone.

However, parts of Apple’s contract allow app developers to take a rough map of a user’s face and a stream of more than 50 kinds of facial expressions off the phone. As long as these developers agree to seek “clear and conspicuous consent” from users, they can remove facial data and store it on their own servers. The data must be used for legitimate app purposes and not marketing or advertisement and cannot sold to third parties that may use it for those purposes.

Questions remain as to how Apple will enforce these terms and their ability to control what app developers do with facial data once it’s taken from the device itself. These reports come shortly after security researchers at Trend Micro’s Pwn2Own contest in Tokyo found exploits in Apple’s newly released iOS 11.1.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • Creating More Versatility

    Today, AI has become top of mind for most security professionals. It is the topic of conversation in the technology world and continues to transform the way data is used to make important business decisions. Read Now

  • Report: 78 Percent of CISOs Seeing Significant Impact from AI-Powered Cyber Threats

    Darktrace recently unveiled its 2025 State of AI Cybersecurity report. The findings reveal that 78% of Chief Information Security Officers (CISOs) surveyed say that AI-powered threats are having a significant impact on their organizations, a 5% increase1 from 2024. While an increasing number of CISOs report feeling a significant impact from AI threats, more than 60% now say that they are adequately prepared to defend against these threats, an increase of nearly 15% year-over-year. However, insufficient AI knowledge and skills and a shortage of personnel and talent continue to be listed as the two top inhibitors to a successful defense. Read Now

  • Teaching AI New Tricks

    You have probably heard that AI-enabled security cameras are evolving the role of traditional surveillance cameras, shifting the focus from passive monitoring to active problem-solving and operational insights. AI technology changes fast, so what is new can be considered only news in just a few months. Read Now

  • From the Most Visible to the Less Apparent

    The Cybersecurity and Infrastructure Security Agency (CISA) states “There are 16 critical infrastructure sectors whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, and national public health or safety or any combination thereof.” Read Now

New Products

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.