Close Menu
Ztoog
    What's Hot
    Technology

    The Canadian border could become a flashpoint under Trump

    Mobile

    Vivo introduces a new tablet powered by Dimensity 9300 chipset, TWS 4 earbuds

    AI

    Researchers from the University of Washington and NVIDIA Propose Humanoid Agents: An Artificial Intelligence Platform for Human-like Simulations of Generative Agents

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      Can work-life balance tracking improve well-being?

      Any wall can be turned into a camera to see around corners

      JD Vance and President Trump’s Sons Hype Bitcoin at Las Vegas Conference

      AI may already be shrinking entry-level jobs in tech, new research suggests

      Today’s NYT Strands Hints, Answer and Help for May 26 #449

    • Technology

      Elon Musk tries to stick to spaceships

      A Replit employee details a critical security flaw in web apps created using AI-powered app builder Lovable that exposes API keys and personal info of app users (Reed Albergotti/Semafor)

      Gemini in Google Drive can now help you skip watching that painfully long Zoom meeting

      Apple iPhone exports from China to the US fall 76% as India output surges

      Today’s NYT Wordle Hints, Answer and Help for May 26, #1437

    • Gadgets

      Future-proof your career by mastering AI skills for just $20

      8 Best Vegan Meal Delivery Services and Kits (2025), Tested and Reviewed

      Google Home is getting deeper Gemini integration and a new widget

      Google Announces AI Ultra Subscription Plan With Premium Features

      Google shows off Android XR-based glasses, announces Warby Parker team-up

    • Mobile

      Deals: the Galaxy S25 series comes with a free tablet, Google Pixels heavily discounted

      Microsoft is done being subtle – this new tool screams “upgrade now”

      Wallpaper Wednesday: Android wallpapers 2025-05-28

      Google can make smart glasses accessible with Warby Parker, Gentle Monster deals

      vivo T4 Ultra specs leak

    • Science

      June skygazing: A strawberry moon, the summer solstice… and Asteroid Day!

      Analysts Say Trump Trade Wars Would Harm the Entire US Energy Sector, From Oil to Solar

      Do we have free will? Quantum experiments may soon reveal the answer

      Was Planet Nine exiled from the solar system as a baby?

      How farmers can help rescue water-loving birds

    • AI

      Rationale engineering generates a compact new tool for gene therapy | Ztoog

      The AI Hype Index: College students are hooked on ChatGPT

      Learning how to predict rare kinds of failures | Ztoog

      Anthropic’s new hybrid AI model can work on tasks autonomously for hours at a time

      AI learns how vision and sound are connected, without human intervention | Ztoog

    • Crypto

      Bitcoin Maxi Isn’t Buying Hype Around New Crypto Holding Firms

      GameStop bought $500 million of bitcoin

      CoinW Teams Up with Superteam Europe to Conclude Solana Hackathon and Accelerate Web3 Innovation in Europe

      Ethereum Net Flows Turn Negative As Bulls Push For $3,500

      Bitcoin’s Power Compared To Nuclear Reactor By Brazilian Business Leader

    Ztoog
    Home » Microsoft’s Windows Hello fingerprint authentication has been bypassed
    The Future

    Microsoft’s Windows Hello fingerprint authentication has been bypassed

    Facebook Twitter Pinterest WhatsApp
    Microsoft’s Windows Hello fingerprint authentication has been bypassed
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Microsoft’s Windows Hello fingerprint authentication has been bypassed on laptops from Dell, Lenovo, and even Microsoft. Security researchers at Blackwing Intelligence have found a number of vulnerabilities within the prime three fingerprint sensors which are embedded into laptops and used broadly by companies to safe laptops with Windows Hello fingerprint authentication.

    Microsoft’s Offensive Research and Security Engineering (MORSE) requested Blackwing Intelligence to guage the safety of fingerprint sensors, and the researchers supplied their findings in a presentation at Microsoft’s BlueHat convention in October. The staff recognized in style fingerprint sensors from Goodix, Synaptics, and ELAN as targets for his or her analysis, with a newly-published weblog put up detailing the in-depth technique of constructing a USB gadget that may carry out a man-in-the-middle (MitM) assault. Such an assault might present entry to a stolen laptop computer, and even an “evil maid” assault on an unattended gadget.

    A Dell Inspiron 15, Lenovo ThinkPad T14, and Microsoft Surface Pro X all fell sufferer to fingerprint reader assaults, permitting the researchers to bypass the Windows Hello safety so long as somebody was beforehand utilizing fingerprint authentication on a tool. Blackwing Intelligence researchers reverse engineered each software program and {hardware}, and found cryptographic implementation flaws in a customized TLS on the Synaptics sensor. The sophisticated course of to bypass Windows Hello additionally concerned decoding and reimplementing proprietary protocols.

    Fingerprint sensors are actually broadly utilized by Windows laptop computer customers, because of Microsoft’s push in direction of Windows Hello and a password-less future. Microsoft revealed three years in the past that almost 85 p.c of shoppers had been utilizing Windows Hello to signal into Windows 10 gadgets as a substitute of utilizing a password (Microsoft does rely a easy PIN as utilizing Windows Hello, although).

    This isn’t the primary time that Windows Hello biometrics-based authentication has been defeated. Microsoft was pressured to repair a Windows Hello authentication bypass vulnerability in 2021, following a proof-of-concept that concerned capturing an infrared picture of a sufferer to spoof Windows Hello’s facial recognition characteristic.

    It’s not clear if Microsoft will be capable to repair these newest flaws alone, although. “Microsoft did a good job designing Secure Device Connection Protocol (SDCP) to provide a secure channel between the host and biometric devices, but unfortunately device manufacturers seem to misunderstand some of the objectives,” writes Jesse D’Aguanno and Timo Teräs, Blackwing Intelligence researchers, of their in-depth report on the failings. “Additionally, SDCP only covers a very narrow scope of a typical device’s operation, while most devices have a sizable attack surface exposed that is not covered by SDCP at all.”

    The researchers discovered that Microsoft’s SDCP safety wasn’t enabled on two of the three gadgets they focused. Blackwing Intelligence now recommends that OEMs ensure that SDCP is enabled and make sure the fingerprint sensor implementation is audited by a professional knowledgeable. Blackwing Intelligence can also be exploring reminiscence corruption assaults on the sensor firmware and even fingerprint sensor safety on Linux, Android, and Apple gadgets.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    The Future

    Can work-life balance tracking improve well-being?

    The Future

    Any wall can be turned into a camera to see around corners

    The Future

    JD Vance and President Trump’s Sons Hype Bitcoin at Las Vegas Conference

    The Future

    AI may already be shrinking entry-level jobs in tech, new research suggests

    The Future

    Today’s NYT Strands Hints, Answer and Help for May 26 #449

    The Future

    LiberNovo Omni: The World’s First Dynamic Ergonomic Chair

    The Future

    Common Security Mistakes Made By Businesses and How to Avoid Them

    The Future

    What time tracking metrics should you track and why?

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    Crypto

    Cryptocurrency Reigns Supreme In Canada’s Fintech Realm

    Despite a yr marked by turbulence within the fintech funding panorama, blockchain and cryptocurrency have…

    Technology

    Researchers say X removed the ability for users to report election misinformation, a feature launched in the US, Australia, and some other countries in 2021 (Byron Kaye/Reuters)

    Byron Kaye / Reuters: Researchers say X removed the ability for users to report election…

    Technology

    2024 Porsche 911 S/T review: Threading the needle

    Enlarge / I would not blame you when you misplaced observe of all the completely…

    AI

    A step toward safe and reliable autopilots for flying | Ztoog

    In the movie “Top Gun: Maverick,” Maverick, performed by Tom Cruise, is charged with coaching…

    Science

    Smart Pillows: Sweet Dreams Are Made of This

    The World Health Organization estimates that as much as 40 % of the inhabitants suffers…

    Our Picks
    Science

    This bioelectronic device lets scientists map electrical signals of the Venus flytrap

    Mobile

    Banking malware uses a simple trick to sneak into your life and turn it upside down

    Gadgets

    Windows Notepad’s midlife renaissance continues with spellcheck and autocorrect

    Categories
    • AI (1,493)
    • Crypto (1,754)
    • Gadgets (1,805)
    • Mobile (1,851)
    • Science (1,867)
    • Technology (1,803)
    • The Future (1,649)
    Most Popular
    AI

    Meet AnyGPT: Bridging Modalities in AI with a Unified Multimodal Language Model

    Gadgets

    Boost your productivity with this 13.3-inch portable monitor, on sale for $108

    Mobile

    The “gorgeous” OnePlus Pad just scored a major discount — get 17% off at Amazon today

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2025 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.