Windows 10 Facial Recognition – Bypassed with a Photo[source: bleepingcomputer]
by CIRT Team
Microsoft has released updates earlier this month to patch a vulnerability in the Windows 10 Hello facial recognition system that allows an attacker to bypass the facial scan with a printed photo.
Windows Hello is a Windows 10-only feature that uses near infrared (IR) imaging to authenticate and unlock Windows devices, such as desktops, laptops, and tablets that use compatible cameras equipped with a near IR sensor.
The feature is not that widespread since not many devices with the necessary hardware, yet when present, it is often used since it’s quite useful at unlocking computers without having users type in long passwords.
You can bypass Windows Hello with a low-res printed photo
In a report published yesterday, German pen-testing company SySS GmbH says it discovered that Windows Hello is vulnerable to the simplest and most common attack against facial recognition biometrics software — the doomsday scenario of using a printed photo of the device’s owner.
Researchers say that by using a laser color printout of a low-resolution (340×340 pixels) photo of the device owner’s face, modified to the near IR spectrum, they were able to unlock several Windows devices where Windows Hello had been previously activated.
The attack worked even if the “enhanced anti-spoofing” feature had been enabled in the Windows Hello settings panel, albeit for these attacks SySS researchers said they needed a photo of a higher resolution of 480×480 pixels (which in reality is still a low-resolution photo).
For more, click here.