Security researchers fake fingerprints with Raspberry Pi 4 to bypass Windows Hello

  • 27 November 2023
  • 5 comments
  • 62 views

Userlevel 7
Badge +9

Security researchers discovered vulnerabilities in the fingerprint sensors of some Windows PCs that could be exploited to bypass Windows Hello's biometric fingerprint login. The affected sensors, manufactured by Elan, Googix, and Synaptics, all use a match-on-chip (MoC) design, where the biometric test occurs within a shielded microprocessor on the chip itself.

 

Kindly refer to the YouTube video for more information as demonstrated at the BlueHat conference in October 2023 by the security researchers.



Note: The Secure Device Connection Protocol (SDCP) protection mechanism has been implemented by Microsoft to prevent unauthorized access.

 

Therefore, the researchers suggest that fingerprint sensor manufacturers enable SDCP and undergo third-party security audits for their implementations. But it remains unclear whether the identified security issues can be entirely addressed through software updates.


5 comments

Userlevel 7
Badge +20

Yeah, saw this reported earlier and even for some specific laptop brands too.  I have a fingerprint sensor but don’t use it.

Userlevel 7
Badge +17

I wonder if this somehow affects MAC devices too… 🤔

Thanks for the share Christian!

Userlevel 7
Badge +9

I wonder if this somehow affects MAC devices too… 🤔

Thanks for the share Christian!

Hi @coolsport00, Windows Hello is specific to the Windows operating system! it is a feature developed by Microsoft for Windows 10 and later versions that allows users to sign in to their devices using various biometric methods, such as facial recognition, fingerprint scanning etc. I would recommend implementing Windows Hello for Business for your users. You can read more here: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/passwordless-strategy  or visit my blog for various deployment scenarios

Userlevel 7
Badge +17

Thanks Christian!

Userlevel 7
Badge +9

Thanks Christian!

Thanks Christian!

You are welcome

Comment