<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Blackwing Intelligence: tls</title><link>https://blackwinghq.com/tags/tls/</link><description>Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations</description><language>en</language><lastBuildDate>Tue, 21 Nov 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://blackwinghq.com/tags/tls/index.xml" rel="self" type="application/rss+xml"/><item><title>[project] A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication</title><link>https://blackwinghq.com/research/projects/a-touch-of-pwn/</link><pubDate>Tue, 21 Nov 2023 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/projects/a-touch-of-pwn/</guid><description>Microsoft's Offensive Research and Security Engineering team asked us to evaluate the top three fingerprint sensors used for Windows Hello. We bypassed fingerprint authentication on all three laptops. The BlueHat talk and the write-up.</description></item><item><title>[talk] A Touch of Pwn: Attacking Windows Hello Fingerprint Authentication</title><link>https://blackwinghq.com/research/talks/a-touch-of-pwn/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/talks/a-touch-of-pwn/</guid><description>Microsoft engaged us to evaluate the security of the top fingerprint sensors used for Windows biometric authentication.
This presentation details our vulnerability research process, which entailed extensive reverse engineering of software and hardware, breaking cryptographic implementation flaws in a custom TLS, and deciphering and reimplementing proprietary protocols, to go from very little knowledge about biometric authentication to a full bypass of Windows Hello authentication on all three of our research targets.</description></item></channel></rss>