Biometric technologies such as fingerprints and face recognition, which have been used on smartphones for many years, are becoming more and more common in laptops and even desktop computers. Everyone is accustomed to using these security mechanisms to protect their data and privacy. However, any mechanism has loopholes. Security researchers have discovered that the convenient Windows Hello also has loopholes that can be bypassed. Fortunately, it is not that simple to actually use this problem to cause trouble.

Security study finds Windows Hello security mechanism can be bypassed with fake USB camera
Microsoft’s Windows Hello facial recognition technology works very well in most situations, and it is convenient and quickly used by many people.CyberArk Security researchers have found a flaw in it that allows unscrupulous people to use specially crafted USB devices to bypass the security mechanism and successfully enter your computer. During the entire testing process, security personnel found that the process of bypassing the facial recognition system was not as difficult as imagined. The difficulty was in obtaining the IR image of the target’s face.

Windows Hello facial recognition technology requires computer hardware to be equipped with a camera with RGB and IR sensors. It turns out that the key to the entire mechanism lies in IR sensor data, which is crucial to how to bypass Windows security mechanisms. Researchers found that the problem is that Windows Hello can accept any lens that uses IR as a Windows Hello recognition device, allowing hackers to shoot with a special remote IR camera or a camera secretly placed in the target environment. During the recognition process, the hacker only needs to send a frame of infrared scanning and a blank black frame to the PC. The latter is used to deceive Windows Hello’s real-time test.

This vulnerability numbered CVE-2021-34466 has been affected byMicrosoft’s confirmation, and Microsoft provides Windows Hello enhanced login security as a remedial measure, but this only allows trusted OEM manufacturers to release relevant drivers and firmware for the corresponding hardware, and not every device can use it.
◎Data source:CyberArk
Source: KOCPC Chinese