Research / Talks

talk

A Touch of Pwn: Attacking Windows Hello Fingerprint Authentication

BlueHat USA 2023 · Redmond, WA

Venue
BlueHat USA 2023, Redmond, WA
Speakers
Jesse D'Aguanno, Timo Teräs
Material
slideswrite-up
Published
Findings published with Microsoft's permission; the engagement report itself is not public.

Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication

Microsoft engaged us to evaluate the security of the top fingerprint sensors used for Windows biometric authentication.

This presentation details our vulnerability research process, which entailed extensive reverse engineering of software and hardware, breaking cryptographic implementation flaws in a custom TLS, and deciphering and reimplementing proprietary protocols, to go from very little knowledge about biometric authentication to a full bypass of Windows Hello authentication on all three of our research targets.

themes: #hardware & firmware #applied cryptography
people: Jesse D'Aguanno Timo Teräs

Related

post

A Touch of Pwn - Part I

TL;DR Microsoft’s Offensive Research and Security Engineering (MORSE) asked us to evaluate the security of the top three fingerprint sensors embedded in laptops and used for Windows Hello fingerprint …

Jesse D'Aguanno, Timo Teräs

tool

iBoot64Binja

Python

A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is …

source Jesse D'Aguanno

talk

NFC Hacking: The Easy Way

DEF CON 20 · Las Vegas, NV

Eddie Lee presents NFCProxy, a proof-of-concept tool that demonstrates insecurities in near field communication and contactless credit cards. The tool is also useful for NFC protocol analysis in …

slidestool Eddie Lee