FB pixel

Microsoft misses own protocol, laptop fingerprint biometrics defeated in test

Microsoft misses own protocol, laptop fingerprint biometrics defeated in test
 

Microsoft’s Hello biometric authentication software has proven surprisingly fallible in a security test, requested by the software company, of three vendors’ laptops.

The challenge involved Microsoft’s Surface Pro Type Cover with an Elan fingerprint sensor, Lenovo’s ThinkPad T14s with a Synaptics sensor and Dell’s Inspiron 15 loaded with a Goodix. Each chip performs the biometric match in-sensor.

Blackwing Intelligence performed three months of testing that “resulted in three 100% reliable bypasses” of Hello authentication. Its researchers confessed surprise that of the three setups the Surface Pro fell easiest.

They have documented what they found in detail and say they will go even deeper with a follow-up report.

At the risk of oversimplification, it seems that the common element tied to each biometric hack is Microsoft’s Secure Device Connection Protocol. The protocol is standards and secure-communication rules.

In all three cases, the protocol was insufficiently enabled, or the system was architected in a way that it was sidelined. It was, in fact, not implemented in the Surface Pro – Microsoft’s Surface Pro.

Closing this hole is easy for vendors. Blackwing says they just have to enable the protocol. And for good measure, the researchers say, get an independent audit of the software implementation before a white hat firm starts digging around.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

UK tucks biometric bias reports deep into police facial recognition plan

The UK government pledged on Thursday to increase its use of facial recognition and biometrics to identify wanted suspects. The…

 

Pandemic surveillance – how AI will police the next global health crisis

By Professor Fraser Sampson, former UK Biometrics & Surveillance Camera Commissioner Fears about AI-enabled biometric tools like facial recognition are often…

 

Behavioral Signals brings novel approach to audio deepfake detection

Deepfakes have advanced beyond the capability of leading software tools using vocal biomarkers to detect them. Fortunately, behavioral biometrics and…

 

NEC takes a stake in PopID, Tencent and Wink biometrics integrated with POS terminals

Major technology firms and payment providers are racing to replace cards and phones with face, palm and voice biometrics. Payments…

 

Firms dive head first into agentic AI governance frameworks, dashboard options

ServiceNow has announced its intent to acquire identity security company Veza, in a move that a release says will extend…

 

SecuGen biometric devices advance toward Aadhaar L1 certification, MOSIP launch

The fingerprint biometric scanners SecuGen is building robust biometric liveness detection into through its partnership with Precise Biometrics are advancing…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events