I was wondering the same. I think it might be quite easy to capture the IR video for replay attack, but it's quite hard to reproduce. Capturing would require just a device that replicates iPhones camera setup, and storing the IR image. Or just use iPhone if you can somehow access the raw IR image data.
If the identification requires just image, it could be printed on a black paper with IR ink (or just white?). Apparently they also look for life signals, so it might require video. In that case, it can't be produced with normal display, but maybe with some sort of old-school analog film and IR light.
This kind of attack (if it works) could be mitigated by adding random IR dots, which would be different each time.
If the identification requires just image, it could be printed on a black paper with IR ink (or just white?). Apparently they also look for life signals, so it might require video. In that case, it can't be produced with normal display, but maybe with some sort of old-school analog film and IR light.
This kind of attack (if it works) could be mitigated by adding random IR dots, which would be different each time.