Privacy Advocates and Devs Raise Concerns About Third-Party App Access to TrueDepth Camera

Apple goes into great detail about the security of the Face ID facial recognition system built into the iPhone X in a security white paper and a support document, but relatively little has been said about the access that developers have to facial data captured by the TrueDepth camera, which has led privacy advocates and developers to express concerns about what apps can glean about you from your face.

A new piece from The Washington Post that includes commentary from both privacy experts and Apple itself explores the data third-party apps can access, echoing concerns previously brought up earlier this month.

iphonextruedepthcamera 1
Apps have no access to the facial map that Face ID uses to unlock your device, but developers are able to use the TrueDepth camera to scan a user's face for the purpose of creating more realistic augmented reality apps. As described by Apple:

Using the TrueDepth camera, your app can detect the position, topology, and expression of the user's face, all with high accuracy and in real time, making it easy to apply live selfie effects or use facial expressions to drive a 3D character.

Apps are able to see a full 3D face map along with a "live read-out" of 52 micro-movements in the eyelids, mouth, and other features. MeasureKit, a free app developed by Rinat Khanov, has a face mesh tool built in that displays the facial data the TrueDepth camera can capture along with a list of the facial expressions it tracks.

measurekitappdata
Apple has a privacy policy that's been in place since before the iPhone X launched requiring apps that use the TrueDepth camera to have a privacy policy, secure user consent option, and a clear outline of what data is being collected and how it's used, but The Washington Post's Geoffrey Fowler worries about the future implications of the TrueDepth camera, where such facial data could perhaps be used to determine gender, race, sexuality, or track facial expressions to determine medical conditions like depression.

"We take privacy and security very seriously," Apple spokesman Tom Neumayr said. "This commitment is reflected in the strong protections we have built around Face ID data--protecting it with the Secure Enclave in iPhone X--as well as many other technical safeguards we have built into iOS."

Khanov, the developer behind the aforementioned MeasureKit app, says Apple's policies may not be enough. Khanov didn't initially have a privacy policy in place in his app, and it was approved anyway. Apple said it was an oversight and asked Khanov to implement a privacy policy right away.

"There were no additional terms or contracts. The app review process is quite regular as well--or at least it appears to be, on our end," Khanov said. When I noticed his app didn't have a privacy policy, Khanov said Apple didn't require it because he wasn't taking face data off the phone.

As Fowler points out, apps that are using the TrueDepth camera are not currently providing enough information to customers. The popup to access the TrueDepth camera is the same generic popup that is required for the standard front and rear-facing cameras, and it does not mention that additional data is being collected.

Whether Apple will put stricter policies in place remains to be seen, as does how this kind of facial recognition data will be used in the future, but customers should be made aware of what's being provided to app developers. For those concerned, it's worth downloading the MeasureKit app or a similar app to see what's potentially being collected when an app accesses the camera on your iPhone X.

Related Forum: iPhone

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
New MacBook Pros Launching Tomorrow With These 4 New Features 2

M5 MacBook Models to Use New Compact Camera Module in 2025

Wednesday July 17, 2024 2:58 am PDT by
Apple in 2025 will take on a new compact camera module (CCM) supplier for future MacBook models powered by its next-generation M5 chip, according to Apple analyst Ming-Chi Kuo. Writing in his latest investor note on unny-opticals-2025-business-momentum-to-benefit-509819818c2a">Medium, Kuo said Apple will turn to Sunny Optical for the CCM in its M5 MacBooks. The Chinese optical lens company...

Top Rated Comments

djcerla Avatar
87 months ago
In the meanwhile, silently, Facebook and Google store informations about billions of users down to the disposition of their pubic hair.
Score: 28 Votes (Like | Disagree)
scaramoosh Avatar
87 months ago
As soon as they require you to look at the phone to continue playing an ad.... my iPhone X goes on eBay.
Score: 15 Votes (Like | Disagree)
whichweather Avatar
87 months ago
As the de facto industry leader, it will be interesting to see how Apple deals with these questions. Insurance and marketing companies love learning more about how we behave and what we look like (color of skin, attractiveness, propensity to smile, state of teeth etc). Unfortunately, the consequences likely won't be good for the large majority of people out there who will be profiled and sorted into risk classes.
Score: 15 Votes (Like | Disagree)
calzon65 Avatar
87 months ago
"We take privacy and security very seriously," Apple spokesman Tom Neumayr said. "This commitment is reflected in the strong protections we have built around Face ID data--protecting it with the Secure Enclave in iPhone X--as well as many other technical safeguards we have built into iOS."

What a bunch of legal double talk. I'm sure when Equifax was hacked they also said they took security seriously while over 100 million people's sensitive financial information was released into the dark web.

Bottom line, more and more companies today have our personal data and when they are hacked, they just say we are sorry, but we did take security seriously.
Score: 12 Votes (Like | Disagree)
btrach144 Avatar
87 months ago
I'm sure in 5 years we'll be reading some report that X company got special API access to FaceID APIs directly from Apple and X company stored user face scans on their servers.

Just like how Apple gave special API access to Uber for the Apple Watch, which allowed Uber to infringe upon user privacy.
Score: 11 Votes (Like | Disagree)
Porco Avatar
87 months ago
Don't like it buy another phone. I am tired of privacy advocates (otherwise known as tech averse idiots) dictating what I can and cannot do.
Hey, you can be a tech lover and a privacy lover too. The two things are not mutally exclusive. Have you heard of something called encryption for example? :rolleyes:

What exactly have these so-called ‘idiots’ stopped you doing exactly? I don’t think anyone really wants to stop letting you trade your privacy to people/apps/companies if you want to, this is about consent and choice. If an app wants to gather and keep data from a user, the user should be aware of that, the reasons why, and be able to make an informed choice as to whether they want to go ahead or not.

It’s about enabling choice for users, not stopping you doing anything. And it’s about users being able to decide where they want the balance to be drawn between privacy and certain kinds of functionality that require giving up some of that privacy. It isn’t a black and white ‘total privacy vs zero privacy’ zero-sum game.
Score: 9 Votes (Like | Disagree)