project
A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication
- People
- Jesse D'Aguanno, Timo Teräs
- Contents
- 1 talk1 post
Microsoft’s Offensive Research and Security Engineering team engaged us to evaluate the security of the top three fingerprint sensors embedded in laptops and used for Windows Hello. Extensive reverse engineering of the sensors and their firmware, a broken custom TLS, and a reimplementation of Microsoft’s Secure Device Connection Protocol got us from very little knowledge of biometric authentication to a full bypass on all three targets.
The findings are published with Microsoft’s permission. The talk from BlueHat 2023 and the write-up are below.
Talk
talk
A Touch of Pwn: Attacking Windows Hello Fingerprint Authentication
Microsoft engaged us to evaluate the security of the top fingerprint sensors used for Windows biometric authentication. This presentation details our vulnerability research process, which entailed …
Posts, in order
- Part 1 A Touch of Pwn - Part I
themes: #hardware & firmware #applied cryptography
people: Jesse D'Aguanno Timo Teräs
