Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Where exactly in that document is the accuracy rates? It's not easy to find.


It’s under System Security, in the Touch ID and Face ID sections:

> The probability that a random person in the population could unlock your iPhone is 1 in 50,000 with Touch ID or 1 in 1,000,000 with Face ID. This probability increases with multiple enrolled fingerprints (up to 1 in 10,000 with five fingerprints) or appearances (up to 1 in 500,000 with two appearances).


Note that this is _much_ less useful than it appears for the same reason as misleading stats often offered to courts when evidence partially links a suspect to a crime.

The problem is that it says random people, but people aren't random. We don't periodically just stir all the people in the entire world and redistribute them across the globe.

In courts you'd get a situation where a jury is told there's only 1-in-10-million chance this evidence would match a random person. Only a few hundred people in the whole world could have been the one, and yet this suspect matches. And what they may not get told unless a defence lawyer brings it up is oh, by the way, six of those few hundred people were in the place where it happened and four more lived in the same street as the suspect.

Bob's Face ID may only match 1 in a million people. But if one of those "1 in a million" people is Bob's twin brother Dave who is always pranking him, and another is Bob's cousin Barry who doesn't look that similar to a person, but mathematically it turns out Bob and Barry's faces look identical to a computer vision system due to their bone structure, then Bob won't find "Face ID" much use.


Your argument is correct for FaceID, but it does not transfer to TouchID. The fingerprints of twins are not more similar to one another than that of two random people.


> The fingerprints of twins are not more similar to one another than that of two random people.

That’s not accurate. Family members have more similarity in their prints than among random people, twins even more similarity, and identical yet more.

I can’t immediately find authoritative references for family and fraternal twins, but here’s a reference for identical twins:

“Identical twins have the same chromosomes and similar physical characteristics and, therefore, they have a high class/type similarity in their fingerprints.” https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3338710/


"Class/type similarity" means that twins are likely to, say, both have whorls on their right index fingers, but doesn't mean they'll have the same pattern of ridges. So for the sake of biometrics, that doesn't make them more similar than two random people.


I stand corrected!

Time to switch to a good old PIN if you have an (evil) twin, then!


The fact that the math here is wrong is quite concerning. Probabilities are not additive - 1 in 6 dice rolls will produce a 5, it doesn't mean if I roll 6 times I am guaranteed a 5.


For small probabilities, approximating

  (1-p)^n
by

  1 - n × x
is absolutely fine. For example

  (1-0.00002)^5 = 0.999900004
Rounding gives you that “one in 10,000”


Adding the probabilities is a good enough approximation when the probabilities and number of trials are very low, though - as in this case. The true value for at least one failure in 5 trials with an individual 1/50000 probability of failure is 1/10000.4 rather than 1/10000, but it seems clear that the original 1/50000 isn't that precise anyway.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: