10-Year-Old Unlocks Face ID on His Mother's iPhone X as Questionable Mask Spoofing Surfaces

A new video has surfaced of a 10-year-old child unlocking his mother's iPhone X with his face even though Face ID was set up with her face.


The parents, Attaullah Malik and Sana Sherwani, said their fifth-grade son Ammar Malik simply picked up his mother's new iPhone X without permission and, to their surprise, unlocked the device with his very first glance.

We are seeing a flood of videos on YouTube from iPhone users who have gotten their hands on the new iPhone X and are trying to trick the Face ID. When my wife and I received our iPhone X, we had no such intention. However, things changed right after we were done setting up our new iPhones on November 3rd. We were sitting down in our bedroom and were just done setting up the Face IDs, our 10-year-old son walked in anxious to get his hands on the new iPhone X. Right away my wife declared that he was not going to access her phone. Acting exactly as a kid would do when asked to not do something, he picked up her phone and with just a glance got right in.

The younger Malik was then consistently able to unlock his mother's iPhone X, according to his parents. He was even able to unlock his father's iPhone X, but only on one attempt, which he has since been unable to replicate.

iphone x face id
WIRED reporter Andy Greenberg suggested that Sherwani re-register her face to see what would happen. Upon doing so, the iPhone X no longer allowed Ammar access. Interestingly, after Sherwani tried registering her face again a few hours later in the same indoor, nighttime lighting conditions in which she first set up her iPhone X, the son was able to regain access with his face.

The parents clarified that no one ever entered the iPhone X's passcode after any of the failed unlocking attempts. That's important, since when Face ID fails to recognize you beyond a certain threshold, and you immediately enter a passcode, the TrueDepth camera takes another capture to improve its reliability.

Apple explains in its Face ID security paper:

Conversely, if Face ID fails to recognize you, but the match quality is higher than a certain threshold and you immediately follow the failure by entering your passcode, Face ID takes another capture and augments its enrolled Face ID data with the newly calculated mathematical representation. This new Face ID data is discarded after a finite number of unlocks and if you stop matching against it. These augmentation processes allow Face ID to keep up with dramatic changes in your facial hair or makeup use, while minimizing false acceptance.

Given no passcode was ever entered, we can assume that Face ID never learned and adjusted for the son's face.

The same Face ID security paper states that the probability of a false match is higher among children under the age of 13, because their distinct facial features may not have fully developed. Given the child is only 10 years old, and Apple's information, what's shown in the video isn't a surprising flaw.

Nevertheless, the video is further evidence that Face ID isn't 100 percent foolproof given just the right circumstances. If you are concerned about this, Apple merely recommends using only a passcode to authenticate.

In related news, Vietnamese security firm Bkav recently shared a video in which it was able to spoof Face ID with a mask. The video is generating headlines since Apple said Face ID uses sophisticated anti-spoofing neural networks to minimize its chances of being spoofed, including with a mask.


The mask was supposedly crafted by combining 3D printing with makeup and 2D images, with some special processing done on the cheeks and around the face. Bkav said the supplies to make it cost roughly $150.

We're skeptical about the video given the lack of accompanying details. For instance, Bkav hasn't specified whether it disabled Face ID's default "Require Attention" feature, which provides an additional layer of security by verifying that you are looking at the iPhone before authentication is granted.

Even if the video is legitimate, it's hardly something that the average person should be concerned about. The chances of someone creating such a sophisticated mask of your facial features would seem extremely slim.

Apple so far has not responded to the videos, beyond pointing reporters to its existing Face ID security paper we linked to above.

Related Forum: iPhone

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
Apple Watch Series 9

2024 Apple Watch Lineup: Key Changes We're Expecting

Tuesday July 16, 2024 7:59 am PDT by
Apple is seemingly planning a rework of the Apple Watch lineup for 2024, according to a range of reports from over the past year. Here's everything we know so far. Apple is expected to continue to offer three different Apple Watch models in five casing sizes, but the various display sizes will allegedly grow by up to 12% and the casings will get taller. Based on all of the latest rumors,...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...

Top Rated Comments

OldSchoolMacGuy Avatar
87 months ago
If you fear for your security, FaceID AND TouchID are poor choices. Go with a very long, secure password. Quit crying.
Score: 94 Votes (Like | Disagree)
miniyou64 Avatar
87 months ago
Regardless if true or not, in practical real world usuage, Face ID is not more secure than Touch ID. Facts.
Score: 86 Votes (Like | Disagree)
ThomasJL Avatar
87 months ago
Fail ID
Score: 64 Votes (Like | Disagree)
mi7chy Avatar
87 months ago
Apple and apologists could positive spin it as a 'family emergency access' feature. ;)
Score: 57 Votes (Like | Disagree)
840quadra Avatar
87 months ago
Do we know how the phone was trained, and how much time it was used before it given to her son? If the password was ever entered just before the device saw his face for the first time?

Like the mask, it lacks full context.
Score: 56 Votes (Like | Disagree)
NCKLS Avatar
87 months ago
Regardless if true or not, in practical real world usuage, Face ID is not more secure than Touch ID. Facts.
Facts? How bout some sources?
Of course people can trick Face ID into failing by training it to work on similar faces of two separate people. How is that real world practical usage?
Score: 41 Votes (Like | Disagree)