Skip to main content

New York’s MTA wants safer COVID-19 iPhone unlocking, and so should you

Image Credit: Apple

When Apple introduced its flagship iPhone X three years ago, the company replaced fingerprints with facial recognition, pitching “Face ID” as even more secure than “Touch ID.” Within a year, the face-mapping tech had arrived on additional iPhones and iPads, helping Apple ditch its finger-scanning Home buttons while following the industry-wide trend of shrinking phone and tablet bezels.

Face ID worked quite well in late 2017, and thanks to subtle hardware and software improvements, it now unlocks devices nearly as quickly as Touch ID — when it works. On the software side, Face ID matches any prospective user against a 3D map made from two initial face scans and whatever subsequently scanned modifications (such as hair changes) it associates with the registered owner. It now also allows for a second facial map based on an “alternate appearance” and supports a wider array of device angles and orientations than before.

But when confronted with a user’s face mask, Face ID typically refuses to unlock. Apple was made aware of the issue well before COVID-19 but apparently chose not to address it, perhaps because complaints were only coming from a handful of regions where masks were being used. Once the pandemic hit, Apple was forced to respond and ultimately offered a workaround: Face ID now gives up as soon as it detects a face mask, quickly giving the user a keypad to manually enter the device’s passcode.

I’ve been living with this workaround system since it debuted in iOS, and it’s not great. Whether I’m trying to glance at a shopping list or answer an incoming text message while wearing a mask in my suburban neighborhood, using my iPhone in public has become a hassle. In denser urban environments, users are apparently feeling compelled to remove their masks just to keep moving through public places at an acceptable pace.

VB Event

The AI Impact Tour – Atlanta

Continuing our tour, we’re headed to Atlanta for the AI Impact Tour stop on April 10th. This exclusive, invite-only event, in partnership with Microsoft, will feature discussions on how generative AI is transforming the security workforce. Space is limited, so request an invite today.
Request an invite

It would be easy for Apple to try to pin this on people using their devices too much, but Apple pushed smartphones toward ubiquity in public spaces, made them critical for navigation and public transportation, and enabled them to serve as payment conduits and transit access devices. People now rely on quick and safe access to their iPhones, an expectation Apple is responsible for addressing.

New York City’s Metropolitan Transportation Authority (MTA) has publicly appealed to Apple to improve Face ID’s performance during the pandemic. In an open letter to Apple, MTA chair Patrick Foye noted that passengers have been removing their masks to unlock their phones — an issue that obviously exposes their faces to the subway’s shared air, and vice versa. As an interim solution, Foye asked Apple to collaborate with the MTA to publicize the iOS passcode workaround. But he also urged Apple “to accelerate the deployment of new technologies and solutions that further protect customers in the era of COVID-19.”

When I reached out to the MTA to see if was recommending any specific solutions to Apple, a spokesperson deferred to Apple for the details. But it’s clear something needs to change, and the MTA wants Apple to explore “additional technological changes that can be made to make signing onto the phones faster and more efficient for everyone.”

There are at least a few near-term solutions that make sense, as well as a “correct” option for next-generation devices. I’ll underscore that time is of the essence here — waiting until next year or requiring the purchase of a new or different phone simply isn’t viable.

  1. Adjust Face ID to do half-face scanning. Ideally, Apple could use the iPhone’s TrueDepth camera system to analyze twice as much detail in the upper half of a face. If not, offering an optional setting to permit unlocking with an upper half match at current fidelity doesn’t seem unreasonable.
  2. Offer a different unlocking solution for public transport. Apple could leverage its Maps database to geofence public transportation hubs and — with user permission — automatically switch to a special protocol when riders enter stations. The protocol might let a user open a single, less secure app with a single button tap or never attempt to access Face ID at all in favor of a quicker passcode.
  3. Use another form of biometric security besides Face ID. Even if Apple’s not prepared to add Touch ID back into iPhones — a step that many have speculated would be possible due to advances in in-screen fingerprint scanning — the company could let an Apple Watch user automatically unlock their iPhone without Face ID while the Watch is in close proximity to the device. Apple already allows the iPhone to unlock the Watch in this way after a Face ID scan, and the Watch can unlock a proximate Mac, so adding the iPhone to this list wouldn’t be difficult.

I have zero doubt that Apple engineers have already been working on alternatives such as these, and probably well in advance of the COVID-19 outbreak. But the company may be tempted to hold off on simpler solutions in the name of even higher device security or wait for the release of a device with both Face ID and next-generation Touch ID using an in-screen fingerprint scanner. Many users, myself included, would consider that an ideal alternative to Apple’s current hardware.

But in the midst of a pandemic, Apple shouldn’t let perfection be the enemy of a good solution, nor should it force users to consider replacing their devices just to feel comfortable unlocking them in public. Just as the company rushed to get a COVID-19 exposure notification/contact tracing system in place by partnering with Google, a software-based alternative to the Face ID system needs to be a priority.

The pandemic has broadly revealed that relying on facial recognition for biometric authentication — and other purposes — can be problematic. Going forward, Apple (and others) need to embrace solutions that take public health into account, rather than unnecessarily creating health risks every time people unlock their phones.

VB Daily - get the latest in your inbox

Thanks for subscribing. Check out more VB newsletters here.

An error occured.