talk
A Touch of Pwn: Attacking Windows Hello Fingerprint Authentication
- Venue
- BlueHat USA 2023, Redmond, WA
- Speakers
- Jesse D'Aguanno, Timo Teräs
- Material
- slideswrite-up
- Published
- Findings published with Microsoft's permission; the engagement report itself is not public.
Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication
Microsoft engaged us to evaluate the security of the top fingerprint sensors used for Windows biometric authentication.
This presentation details our vulnerability research process, which entailed extensive reverse engineering of software and hardware, breaking cryptographic implementation flaws in a custom TLS, and deciphering and reimplementing proprietary protocols, to go from very little knowledge about biometric authentication to a full bypass of Windows Hello authentication on all three of our research targets.
themes: #hardware & firmware #applied cryptography
people: Jesse D'Aguanno Timo Teräs
