TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Windows Hello fingerprint authentication has been bypassed

90 pointsby 0xedbover 1 year ago

4 comments

peteeover 1 year ago
Full writeup is a much better read: <a href="https:&#x2F;&#x2F;blackwinghq.com&#x2F;blog&#x2F;posts&#x2F;a-touch-of-pwn-part-i&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;blackwinghq.com&#x2F;blog&#x2F;posts&#x2F;a-touch-of-pwn-part-i&#x2F;</a><p><i>&quot;Microsoft did a good job designing SDCP to provide a secure channel between the host and biometric devices, but unfortunately device manufacturers seem to misunderstand some of the objectives. Additionally, SDCP only covers a very narrow scope of a typical device’s operation, while most devices have a sizable attack surface exposed that is not covered by SDCP at all.<p>Finally, we found that SDCP wasn’t even enabled on two out of three of the devices we targeted.&quot;</i> Oof.
评论 #38382808 未加载
WirelessGigabitover 1 year ago
How do I, as a consumer, validate that my fingerprint sensor uses SDCP?<p>Reading through all of this it seems that protecting myself by enabling cover tampering (which prevents a hacker from replacing the fingerprint reader without tripping the TPM) and only allow booting into Windows.
sonicanatidaeover 1 year ago
HEADLINE: MICROSOFT SECURITY BYPASSED<p>First sentence of this click bait horse shit: Security researchers have found flaws in the way laptop manufacturers are implementing fingerprint authentication.<p>So fucking sick of clickbait.
评论 #38380883 未加载
评论 #38381439 未加载
评论 #38382691 未加载
miohtamaover 1 year ago
And this, ladies and sirs, why we should prefer Macbooks and Linux in security critical productivity work. Microsoft Windows and its hardware partners, with their device drivers and lack of transparency, have been a dumpster fire for the last 30 years.
评论 #38380365 未加载
评论 #38380389 未加载
评论 #38381233 未加载
评论 #38380449 未加载
评论 #38381045 未加载