Research / Projects

project

A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication

2 items

People
Jesse D'Aguanno, Timo Teräs
Contents
1 talk1 post

Microsoft’s Offensive Research and Security Engineering team engaged us to evaluate the security of the top three fingerprint sensors embedded in laptops and used for Windows Hello. Extensive reverse engineering of the sensors and their firmware, a broken custom TLS, and a reimplementation of Microsoft’s Secure Device Connection Protocol got us from very little knowledge of biometric authentication to a full bypass on all three targets.

The findings are published with Microsoft’s permission. The talk from BlueHat 2023 and the write-up are below.

Talk

Posts, in order

  1. Part 1 A Touch of Pwn - Part I

themes: #hardware & firmware #applied cryptography
people: Jesse D'Aguanno Timo Teräs

Related

tool

iBoot64Binja

Python

A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is …

source Jesse D'Aguanno

talk

NFC Hacking: The Easy Way

DEF CON 20 · Las Vegas, NV

Eddie Lee presents NFCProxy, a proof-of-concept tool that demonstrates insecurities in near field communication and contactless credit cards. The tool is also useful for NFC protocol analysis in …

slidestool Eddie Lee

tool

NFCProxy

Java (Android) · archived

An Android app that proxies NFC transactions between a contactless card and a reader, for demonstrating relay attacks and analysing NFC protocols. Presented at DEF CON 20.

sourcetalk Eddie Lee