TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Windows Hello bypassed using infrared image

138 点作者 iou将近 4 年前

8 条评论

gregmac将近 4 年前
It seems like it wouldn&#x27;t be a stretch to make a USB webcam that presented an &quot;animated&quot; infrared image -- would that defeat this fix?<p>What I&#x27;d really like is the system to consider every new USB device untrusted, and require specific approval before it&#x27;s added as a device. This should apply to its capabilities too (eg: if a &quot;keyboard&quot; suddenly is presenting itself as storage, that causes a prompt). Think along the lines of &quot;Acme WebCam XYZ wants to add a Camera and Microphone. Allow?&quot;<p>And while the computer is locked this should absolutely be impossible.<p>I went looking for some commercial stuff, and there seems to be products aimed at businesses -- but seems these are centrally-managed, work by whitelisting specific devices ahead of time, and are more focused on data exfiltration than preventing a rogue keyboard, badusb or rubber ducky. Is there something that does this?
评论 #27892571 未加载
评论 #27889419 未加载
评论 #27892322 未加载
评论 #27889094 未加载
评论 #27889336 未加载
chmod775将近 4 年前
If you&#x27;re using that as your sole authentication mechanism, then you&#x27;re not encrypting your data with a password. It&#x27;s already game over.<p>These kinds of things of &#x27;security&#x27;* features can&#x27;t be considered protection for the valuable data on your computer, or the e-commerce account you&#x27;re currently signed in on.<p>This stuff is for preventing Steven from making a funny Facebook post in your name (he&#x27;ll find a way anyways).<p>*roughly the same level of &#x27;security&#x27; a &quot;beware fluffy the furry menace&quot; sign on your garden fence provides.
评论 #27889830 未加载
评论 #27889570 未加载
评论 #27889648 未加载
评论 #27891039 未加载
cpuguy83将近 4 年前
All I know is my 6 year old daughter was able to login to my admin account because of Windows Hello on multiple occasions.<p>There is certainly <i>some</i> resemblance, particularly what I looked like when I was 6, but not a huge one.
xaduha将近 4 年前
Catchy umbrella names for a set of security-related products&#x2F;services cause more harm than good, see Google Titan. When just one facet of that gets compromised it sows doubt about the whole thing due to clickbaity titles.
cwyptocuwency将近 4 年前
Out of curiosity, why would showing a printed image of the user&#x27;s face not have worked as well? Or, say, playing a video of the user&#x27;s face from another device in front of the webcam? Does the biometric software look for glint or other characteristics of a replicating medium?
评论 #27889615 未加载
andrewmcwatters将近 4 年前
Interesting. I thought Windows Hello was implemented with dot matrix hardware like on iPhone, but clearly it isn&#x27;t. It&#x27;s illuminated infrared camera tech.
mrjin将近 4 年前
The problem is really how can we be sure that a device claimed to be a camera is really a camera and can be trusted? But yeah, as the device is already physically compromised, there is not much can be done in OS&#x27; perspective.
评论 #27892017 未加载
smoldesu将近 4 年前
cool