Skip to main content

Security researchers fake fingerprints with Raspberry Pi 4 to bypass Windows Hello


Iams3le
Forum|alt.badge.img+11

Security researchers discovered vulnerabilities in the fingerprint sensors of some Windows PCs that could be exploited to bypass Windows Hello's biometric fingerprint login. The affected sensors, manufactured by Elan, Googix, and Synaptics, all use a match-on-chip (MoC) design, where the biometric test occurs within a shielded microprocessor on the chip itself.

 

Kindly refer to the YouTube video for more information as demonstrated at the BlueHat conference in October 2023 by the security researchers.



Note: The Secure Device Connection Protocol (SDCP) protection mechanism has been implemented by Microsoft to prevent unauthorized access.

 

Therefore, the researchers suggest that fingerprint sensor manufacturers enable SDCP and undergo third-party security audits for their implementations. But it remains unclear whether the identified security issues can be entirely addressed through software updates.

5 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8506 comments
  • November 27, 2023

Yeah, saw this reported earlier and even for some specific laptop brands too.  I have a fingerprint sensor but don’t use it.


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4146 comments
  • November 27, 2023

I wonder if this somehow affects MAC devices too… ðŸ¤”

Thanks for the share Christian!


Iams3le
Forum|alt.badge.img+11
  • Author
  • Veeam Legend
  • 1394 comments
  • November 27, 2023
coolsport00 wrote:

I wonder if this somehow affects MAC devices too… ðŸ¤”

Thanks for the share Christian!

Hi @coolsport00, Windows Hello is specific to the Windows operating system! it is a feature developed by Microsoft for Windows 10 and later versions that allows users to sign in to their devices using various biometric methods, such as facial recognition, fingerprint scanning etc. I would recommend implementing Windows Hello for Business for your users. You can read more here: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/passwordless-strategy  or visit my blog for various deployment scenarios


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4146 comments
  • November 27, 2023

Thanks Christian!


Iams3le
Forum|alt.badge.img+11
  • Author
  • Veeam Legend
  • 1394 comments
  • November 27, 2023
coolsport00 wrote:

Thanks Christian!

coolsport00 wrote:

Thanks Christian!

You are welcome