Register Free Newsletter Plus Membership
  • Home
    • Newsletters/Alerts
    • Forums
    • About
    • MS-DEFCON System
    • Master Patch List
    • Register
    • Login
Microsoft Patch Defense Condition level 2 Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it.
SIGN IN Not a member? REGISTER PLUS MEMBERSHIP
  • Microsoft’s Windows Hello fingerprint authentication has been bypassed

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Microsoft’s Windows Hello fingerprint authentication has been bypassed

    • This topic has 4 replies, 2 voices, and was last updated 1 year, 5 months ago.
    Author
    Topic
    New Reply
    Alex5723
    AskWoody Plus
    November 22, 2023 at 10:39 am #2604706

    https://www.theverge.com/2023/11/22/23972220/microsoft-windows-hello-fingerprint-authentication-bypass-security-vulnerability

    Security researchers have found flaws in the way laptop manufacturers are implementing fingerprint authentication.

    Microsoft’s Windows Hello fingerprint authentication has been bypassed on laptops from Dell, Lenovo, and even Microsoft. Security researchers at Blackwing Intelligence have discovered multiple vulnerabilities in the top three fingerprint sensors that are embedded into laptops and used widely by businesses to secure laptops with Windows Hello fingerprint authentication…

    Microsoft’s Offensive Research and Security Engineering (MORSE) asked Blackwing Intelligence to evaluate the security of fingerprint sensors, and the researchers provided their findings in a presentation at Microsoft’s BlueHat conference in October..

    Blackwing Intelligence researchers reverse engineered both software and hardware, and discovered cryptographic implementation flaws in a custom TLS on the Synaptics sensor. ..

    * Would you rely on Hello fingerprint in use as passkeys ?

    3 users thanked author for this post.
    NaNoNyMouse, Sueska, windbg
    Reply | Quote
    Viewing 2 reply threads
    Author
    Replies
    • b
      AskWoody_MVP
      November 23, 2023 at 5:46 am #2604896

      One of the researchers told us: “It’s my understanding from Microsoft that the issues were addressed by the vendors.

      https://www.theregister.com/2023/11/22/windows_hello_fingerprint_bypass/?utm_source=daily&utm_medium=newsletter&utm_content=top-article#:~:text=One%20of%20the%20researchers%20told%20us%3A%20%22It%27s%20my%20understanding%20from%20Microsoft%20that%20the%20issues%20were%20addressed%20by%20the%20vendors.

       

      Alex5723 wrote:

      Would you rely on Hello fingerprint in use as passkeys ?

      Bitlocker protects against this attack (if the computer is switched off):

      As to what happens if the stolen machine is powered off completely, and has a BIOS password, full-disk encryption, or some other pre-boot authentication, exploitation isn’t as straight forward or perhaps even possible:

      https://www.theregister.com/2023/11/22/windows_hello_fingerprint_bypass/?utm_source=daily&utm_medium=newsletter&utm_content=top-article#:~:text=As%20to%20what%20happens%20if%20the%20stolen%20machine%20is%20powered%20off%20completely%2C%20and%20has%20a%20BIOS%20password%2C%20full%2Ddisk%20encryption%2C%20or%20some%20other%20pre%2Dboot%20authentication%2C%20exploitation%20isn%27t%20as%20straight%20forward%20or%20perhaps%20even%20possible%3A

      1 user thanked author for this post.
      Alex5723
      Reply | Quote
    • Alex5723
      AskWoody Plus
      November 23, 2023 at 10:55 am #2604926
      b wrote:

      “It’s my understanding from Microsoft that the issues were addressed by the vendors.

      He would wish it to be true.

      I use Lenovo laptops since the first XP. They never release firmware for PCs older than 2-3 years.

      I use Lenovo Y530 purchased on Aug. 2018. Last BIOS/Firmware update Mar. 2021

      Reply | Quote
      • b
        AskWoody_MVP
        November 23, 2023 at 4:22 pm #2604959

        But that one was only 18 months old?

        Reply | Quote
    • Alex5723
      AskWoody Plus
      November 24, 2023 at 12:26 am #2605007
      b wrote:

      But that one was only 18 months old?

      Hello fingerprint system is 18 months old ?

      Reply | Quote
    Viewing 2 reply threads
    Reply To: Microsoft’s Windows Hello fingerprint authentication has been bypassed

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information:




     
    Cancel
DON'T MISS OUT!
Subscribe to the Free Newsletter
We promise not to spam you. Unsubscribe at any time.
Invalid email address
Thanks for subscribing!

Register
Lost your password?

Plus Membership

Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.

AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.


Get Plus!

Welcome to our unique respite from the madness.

It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.

Search Newsletters

Search Forums

Advanced Search

View the Forum

  • Recent Replies
  • My Replies
  • My Active Topics
  • New Posts in the Last day
  • Private Messages
  • Knowledge Base
  • How to use the Forums
  • All Forums
  • Search for Topics

    • Most popular topics
    • Topics with no replies
    • Recently active topics
    • New posts: Last day
    • New posts: Last three days
    • New posts: Last week
    • New posts: Last month
    • Topics with most replies
    • Latest topics

    Recent Topics

    • Xfinity home internet by MrJimPhelps
      4 hours, 16 minutes ago
    • Convert PowerPoint presentation to Impress by RetiredGeek
      6 hours, 16 minutes ago
    • Debian 12.11 released by Alex5723
      14 hours, 42 minutes ago
    • Microsoft: Troubleshoot problems updating Windows by Alex5723
      18 hours, 23 minutes ago
    • Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup by Alex5723
      9 minutes ago
    • Moving fwd, Win 11 Pro,, which is best? Lenovo refurb by Deo
      14 hours, 51 minutes ago
    • DBOS Advanced Network Analysis by Kathy Stevens
      1 day, 11 hours ago
    • Microsoft Edge Launching Automatically? by healeyinpa
      1 day, 1 hour ago
    • Google Chrome to block admin-level browser launches for better security by Alex5723
      1 day, 13 hours ago
    • iPhone SE2 Stolen Device Protection by Rick Corbett
      1 day, 6 hours ago
    • Some advice for managing my wireless internet gateway by LHiggins
      13 hours, 47 minutes ago
    • NO POWER IN KEYBOARD OR MOUSE by HE48AEEXX77WEN4Edbtm
      6 hours, 39 minutes ago
    • A CVE-MITRE-CISA-CNA Extravaganza by Nibbled To Death By Ducks
      1 day, 23 hours ago
    • Sometimes I wonder about these bots by Susan Bradley
      1 day, 19 hours ago
    • Does windows update component store “self heal”? by Mike Cross
      1 day, 9 hours ago
    • Windows 11 Insider Preview build 27858 released to Canary by joep517
      2 days, 13 hours ago
    • Pwn2Own Berlin 2025: Day One Results by Alex5723
      21 hours, 22 minutes ago
    • Windows 10 might repeatedly display the BitLocker recovery screen at startup by Susan Bradley
      10 hours, 1 minute ago
    • Windows 11 Insider Preview Build 22631.5409 (23H2) released to Release Preview by joep517
      2 days, 16 hours ago
    • Windows 10 Build 19045.5912 (22H2) to Release Preview Channel by joep517
      2 days, 16 hours ago
    • Kevin Beaumont on Microsoft Recall by Susan Bradley
      2 days, 4 hours ago
    • The Surface Laptop Studio 2 is no longer being manufactured by Alex5723
      3 days ago
    • 0Patch, where to begin by cassel23
      2 days, 18 hours ago
    • CFPB Quietly Kills Rule to Shield Americans From Data Brokers by Alex5723
      3 days, 13 hours ago
    • 89 million Steam account details just got leaked, by Alex5723
      3 days, 1 hour ago
    • KB5058405: Linux – Windows dual boot SBAT bug, resolved with May 2025 update by Alex5723
      3 days, 22 hours ago
    • A Validation (were one needed) of Prudent Patching by Nibbled To Death By Ducks
      3 days, 13 hours ago
    • Master Patch Listing for May 13, 2025 by Susan Bradley
      15 hours, 37 minutes ago
    • Installer program can’t read my registry by Peobody
      7 hours, 31 minutes ago
    • How to keep Outlook (new) in off position for Windows 11 by EspressoWillie
      3 days, 11 hours ago

    Recent blog posts

    • Kevin Beaumont on Microsoft Recall
    • Master Patch Listing for May 13, 2025
    • AutoSave is for Microsoft, not for you
    • May 2025 updates are out
    • Apple releases 18.5
    • Which antivirus apps and VPNs are the most secure in 2025?
    • Stay connected anywhere
    • Copilot, under the table

    My Profile

    Login and Registration

    • Log In
    • Register

    Key Links

    • > Computerworld's The Microsoft Patch Lady
    • > Computerworld's Woody on Windows
    • AskWoody Knowledge Base index
    • BlockaPatch tools
    • Gift subscription for Ask Woody Newsletter
    • Microsoft Answers Forum
    • Tasks for the Weekend YouTube Channel
    May 2025
    S M T W T F S
     123
    45678910
    11121314151617
    18192021222324
    25262728293031
    « Apr    

    Remembering Woody

     

    Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.

    Mastodon profile for DefConPatch
    Mastodon profile for AskWoody

     

    Home • About • FAQ • Posts & Privacy • Forums • My Account
    Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts

    Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.

    Insert/edit link

    Enter the destination URL

    Or link to existing content

      No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.

        Notifications

        #