Google’s Pixel 4 launches with face unlock security flaw

Android Authority‘s Pixel 4 content is brought to you by MNML Case, makers of the world’s thinnest phone case. Save 25% on your Pixel 4 or Pixel 4 XL case using the discount code AAPixel4.


Google’s Pixel 4 line launched only a couple of days ago, and a major issue with the devices’ face unlock feature has already been discovered. First spotted by BBC, users can unlock the Pixel 4 using the biometric face unlock even if their eyes are closed.

This is, for obvious reasons, a privacy concern. It allows attackers or authorities to more easily gain access to a person’s device without their permission. Whether the user is asleep or restrained, the Pixel 4 only needs to be raised toward their face for someone to gain access.

When BBC reached out to Google for comment, the company verified that this is how the Pixel 4’s face unlock security functionality works on its final software. Google’s face unlock support page also confirms this. The support page even warns users to keep their device in a safe place to avoid this type of attack and reminds them of Android’s lockdown functionality, which disables biometric unlocking so the device can only be unlocked with a PIN.

Google Pixel 4 Face UnlockNextrift

The fact that Google is allowing this type of security access through face unlock is surprising, especially since last month’s leaks from Nextrift revealed a “Require eyes to be open” toggle switch, pictured above. This, however, was likely pre-release software on a prototype device. Android Authority has confirmed that this toggle switch is not present on either of its review units.

Android 10‘s code even has built-in support for it, yet it isn’t in the final software. Google very well could release this functionality eventually, but for early adopters, the current state of the Pixel 4 face unlock remains a significant security issue.

When asked about the face unlock feature, Google told Android Authority:

Pixel 4 face unlock meets the security requirements as a strong biometric, and can be used for payments and app authentication, including banking apps. It is resilient against unlock attempts via other means, like with masks. If you want to temporarily disable face unlock, you can use lockdown mode to temporarily require a PIN/pattern/password.

We don’t have anything specific to announce regarding future capabilities, but like most of our products, this feature is designed to get better over time with software updates.

We will update this article as we learn more about the Pixel 4’s face unlock system.

More posts about the Pixel 4

Comments

Popular posts from this blog

Woman clawed by zoo jaguar while trying to take selfie, learns valuable lesson

The 12 best TV shows on Netflix you can binge right now

10 best adult apps for Android (NSFW)