Face Unlock feature in Galaxy Nexus seen as novelty, not security
Analysts and Google suggest PIN or password alternate for smartphone
Computerworld - Face Unlock, the facial recognition software offered in Android 4.0 on the Galaxy Nexus, is being promoted by Google as an alternative to using a PIN to unlock a phone.
But early reviewers have noticed that Face Unlock sometimes can be spoofed by a photograph of the owner of the phone, posing a security risk.
A Google official wouldn't comment on various reports about the issue. Google calls Face Unlock "state-of-the-art facial recognition technology [that] lets you switch on your phone and look at it to get past the lock screen -- no passwords to remember, nothing to type or swipe."
Early users and reviewers, including Computerworld blogger JR Raphael, have noted that the Face Unlock feature in Android 4.0, Ice Cream Sandwich, is introduced on the Galaxy Nexus at set-up with a disclaimer. It describes the technology as less secure than other methods such as a password or PIN.
Raphael said he tried several times to spoof the phone with his own photo, but it never unlocked with the photograph, just his actual face.
At set-up, users are also asked to enter a backup security protection, such as a pattern or PIN, to Face Unlock. The backup obviously would come into play if lighting is poor and the facial recognition feature could not work.
Analysts took note that Google never said Face Unlock was a highly secure approach to unlocking a phone, and suggested that users not consider it so.
"I expect Face Unlock is a fairly rudimentary system that only looks at a few facial points to come to the conclusion that's it's you," said Jack Gold, an analyst at J. Gold Associates.
While some facial recognition systems can be highly secure and safe, they require much higher resolution cameras, and high processing power. "Would I want to use Face Unlock for doing monetary transactions? Not a chance," Gold said.
While the Google approach may be rudimentary, it's probably intended to be a convenience or even a "conversation piece," Gold added. As Google has required at set-up, a good second factor authentication is needed.
"Even a good password, with sufficient length and different characters, would be more secure than this low-end option, in my opinion," he said.
Matt Hamblen covers mobile and wireless, smartphones and other handhelds, and wireless networking for Computerworld. Follow Matt on Twitter at
@matthamblen or subscribe to
Matt's RSS feed. His e-mail address is mhamblen@computerworld.com.
Read more about Mobile Apps and Services in Computerworld's Mobile Apps and Services Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Mobile Middleware Strategies
- Learn why a mobile development platform is critical to be able to support today's complex enterprise mobility strategies. Learn what to look for...
- The Evolution of Enterprise Mobile App Development
- Driven by explosive growth in smartphone and tablet sales, enterprise mobility has become an essential part of business. Organizations across industries are developing...
- Native & HTML5 Mobile Apps: Not an either or, but a where and when
- Learn how developers are using HTML5 and native development methods to build mobile apps. Get practical insights on how these tools are being...
- Bank Improves Crisis Management Communications with Help from BlackBerry Solution
- With a staff of more than 60,000 people dispersed across the United States, U.S. Bank needed a robust and intuitive program that would...
- Why Centralized Cloud Identity Management is Crucial for the Enterprise
- Now that employees are leaving the relative safety of the firewall to use online SaaS applications, enterprises need to adjust the way they... All Mobile Apps and Services White Papers
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Apps that add business value
- BlackBerry® has all that you need to leverage mobile applications for BlackBerry® smartphones and BlackBerry® PlayBook™ tablets. You will see some simple applications...
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Mobile Apps and Services Webcasts