A face match answers one question: does the face in the selfie look like the face on the ID? It does not answer whether anyone was there.
That gap is the whole attack. Someone holding a stolen Resident ID and a photograph of its owner can present a face that matches the card perfectly — because it is the owner's face. A face match that passes that presentation is working exactly as designed, and the verification has still failed. Liveness detection is the check that closes it.
A matching face is not a present face
The attacks a face match cannot see
These are called presentation attacks: something other than a live person is put in front of the camera. Each of them can match the ID photograph, which is precisely why matching is not enough.
| Attack | What it is | What a liveness check can look for |
|---|---|---|
| Printed photo | A photograph of the cardholder held up to the camera | A flat surface where a face has depth, and no natural movement |
| Video replay | A recording of the cardholder played back | The texture, refresh patterns and reflections of a screen rather than skin |
| Screen display | A still or live image shown on another device | Device edges, glare and pixel structure inside the frame |
ekyciq's liveness detection is designed to detect real human presence and block photos, videos and screen attacks of exactly these kinds.
Two checks, four outcomes
Face match and liveness answer different questions, so they have to be read together. The combination matters more than either score.
| Face match | Liveness | What it means |
|---|---|---|
| Pass | Pass | A live person who resembles the card. Proceed, subject to the other checks |
| Pass | Fail | The dangerous one. The right face, but not a present person — the signature of a presentation attack |
| Fail | Pass | A real person who does not resemble the card: a mismatch to review, not an attack to assume |
| Fail | Fail | Neither present nor matching. Reject or review, per policy |
The second row is the reason liveness exists. A system that reports only the match score would pass it.
Ask for the error rates that matter to you
Every face and liveness system trades wrongly accepting an attacker against wrongly rejecting a genuine customer. A single accuracy percentage hides both. Ask how each rate was measured, on which population, and in which conditions — the questions in judging a face recognition accuracy claim apply here in full — and then test on your own customers, in the lighting and on the phones they actually use.
Liveness is still biometric processing
Adding liveness does not change the legal position of the face check it protects. Under Article 5 of Oman's Personal Data Protection Law, processing biometric data is prohibited except after obtaining a permit from the Ministry, and a face comparison is biometric processing. The permit comes before real faces are processed, as the same rule applied to facial attendance sets out, and eKYC under the PDPL covers for onboarding.
ekyciq pairs face match with liveness detection in a single capture. See how ekyciq works, or talk to us about testing it against your own onboarding.
Related posts
-
On-Premise or Cloud Video Analytics: What Actually Changes
Footage that never leaves the site removes a compliance question rather than answering it.
05 May 2026 -
The False Alarm Budget: Why Noise Is the Real Failure Mode
A system nobody trusts is worse than no system: you are paying for coverage you have already lost.
02 December 2025 -
QR and OTP Check-In: The Entrance Is Not a Usability Lab
It works for the visitor who has signal, a charged phone and the right language.
18 November 2025


