FB pixel

Microsoft misses own protocol, laptop fingerprint biometrics defeated in test

Microsoft misses own protocol, laptop fingerprint biometrics defeated in test
 

Microsoft’s Hello biometric authentication software has proven surprisingly fallible in a security test, requested by the software company, of three vendors’ laptops.

The challenge involved Microsoft’s Surface Pro Type Cover with an Elan fingerprint sensor, Lenovo’s ThinkPad T14s with a Synaptics sensor and Dell’s Inspiron 15 loaded with a Goodix. Each chip performs the biometric match in-sensor.

Blackwing Intelligence performed three months of testing that “resulted in three 100% reliable bypasses” of Hello authentication. Its researchers confessed surprise that of the three setups the Surface Pro fell easiest.

They have documented what they found in detail and say they will go even deeper with a follow-up report.

At the risk of oversimplification, it seems that the common element tied to each biometric hack is Microsoft’s Secure Device Connection Protocol. The protocol is standards and secure-communication rules.

In all three cases, the protocol was insufficiently enabled, or the system was architected in a way that it was sidelined. It was, in fact, not implemented in the Surface Pro – Microsoft’s Surface Pro.

Closing this hole is easy for vendors. Blackwing says they just have to enable the protocol. And for good measure, the researchers say, get an independent audit of the software implementation before a white hat firm starts digging around.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

The ‘Frontline’ of digital identity innovation spans the Global South

The ID4Africa community focussed on Frontline developments in digital identity from around the world Day 2 of the 2026 AGM…

 

Tech vendors urge PPP, decentralized digital ID models at ID4Africa

Ideas continued to flow in the main hall of the Parc des Expositions in Abidjan on May 13 as the…

 

Africa PKI Consortium builds the continent’s trust layer

“If the continent is to achieve its sovereignty it needs to have control over every ingredient that is used,” said…

 

Survey shows social media firms ignoring Australia’s minimum age law

More data has been released showing that Silicon Valley’s social media giants have no interest in complying in good faith…

 

Fingerprint Cards, Precise position merger as platform for biometrics consolidation

Fingerprint Cards CEO Adam Philpott says the Gothenburg-based company’s “merger of equals” with Precise Biometrics, which was approved on April…

 

ICE smart glasses plan adds to lawmaker concerns over Palantir, mobile biometric enforcement

The Department of Homeland Security’s (DHS) push to develop biometric smart glasses for immigration agents is intensifying concerns in Congress…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events