Researchers at the German IT Security company SySS GmbH successfully fooled the Windows 10 facial recognition system by using a printed photo of the user's face.
Their spoofing efforts were published on eroticism esteher perelthe cybersecurity site Seclists on Dec. 18. The cybersecurity experts bypassed Windows Hello -- which is Microsoft's password-free security software -- on both a Dell and Microsoft laptop running different versions of Windows 10, which is cause for concern for anyone using this feature to log into their account.
SEE ALSO: This nasty Android malware caused a phone to overload and bulgeDeceiving Windows 10 didn't take too much effort. It just required "having access to a suitable photo of an authorized person" to "easily" bypass the system, wrote the experts. The photo required is the full image of someone's face -- so if someone really wants to attempt to deceive the facial recognition system, the barriers aren't too great.
Similar to Apple's Face ID, it might be wise to view Windows Hello as a convenience feature, not a security feature.
Similar to the iPhone X's Face ID camera, Hello Windows uses an infrared camera (either built-in the or added separately) to recognize the unique shape and contours of a face before granting or denying access to a Windows account. But a flaw was found, specifically "an insecure implementation of the biometric face recognition in some Windows 10 versions."
They show their work below:
Many -- but not all -- Windows versions are vulnerable. In 2016, Microsoft included a new feature called Enhanced Anti-Spoofing to limit this sort of picture trickery. But even if this feature is enabled in your Windows settings, the researchers found a way to bypass the facial recognition system that ran older Windows versions, such as a Microsoft Surface Pro 4 device running 2016's Windows 10 Anniversary update, for instance.
However, the SySS researchers found that two new Windows versions, 1703 and 1709, are not vulnerable to their most simple spoofing attacks (using a printed photograph) if Enhanced Anti-Spoofing is enabled.
Their ultimate recommendation: Updating to Windows 10 version 1709, enabling anti-spoofing, and then having Windows Hello reanalyze your face.
If this sounds unappealing or risky, you can always go back to using a (not dumb) password. Infrared facial recognition in consumer applications is still relatively new, so flaws should be expected.
Similar to Apple's Face ID, it might help to view Windows Hello as a convenience feature, not a security feature.
Mashable has contacted Microsoft for comment and will update this story upon hearing back.
Topics Cybersecurity Windows
Where to buy sex toys online: 17 places to help you get offPro wrestling stars are dunking on fellow wrestler, Kane, for his tweet on Roe v. WadeUniversity of Kansas Digitizes 1,000 ZinesNintendo Switch Best Buy saleNintendo Switch Best Buy saleHow to stream 'Lessons in Chemistry' with Brie Larson on Apple TV+ for freeWin Free Tickets: Nathaniel Mackey and Cathy Park HongUniversity of Kansas Digitizes 1,000 ZinesTime Diptychs and Mirrored Rooms: Art by Eric GreenThe History of Underwear Is a Dirty HistoryExotic Pets of the Twenties and ThirtiesPoem: Nin Andrews, “The Artichoke”Teffi: My First Visit to an Editorial OfficeNintendo Switch Best Buy saleWatch: Christine Schutt Remembers Writing Her First Stories“Be Bold with Bananas” and Other Awful Library BooksYour Google homepage may look different on desktop soonApple reveals iPhone Easter egg: An oldAstrology for beginners: what the common terms on your FYP meanApple reveals iPhone Easter egg: An old Roku backtracks, says it's pulling Infowars from its platform Steve Carell set for Netflix comedy based on Trump's 'Space Force’ This police officer is going viral for his slightly unfortunate name Snap's new problem: disappearing executives Donald Trump is not deleting tweets, despite claims to the contrary Apple announces $129 Smart Battery Case for iPhone XR, XS, XS Max A $1500 foldable smartphone Razr is coming in February, report says Hillary Clinton turned her website into a fact checker for the debate Clinton was interrupted constantly by Trump and shimmied her way through it all Someone turned Cardi B's government shutdown rant into a song and it slaps The Face ID ruling is a big win for digital rights. Here's what needs to happen next. 19 times the Hillary shimmy GIF perfectly describes what you're going through Let people do whatever they want with their dang books, sheesh 60% of the planet's wild coffee species face extinction, study says Karen Minty may have survived 'You,' but she still got shafted The Hillary shimmy GIF that's perfect for when you're winning at life Verizon extends free Apple Music subscription for some Unlimited plans indefinitely DuckDuckGo's private searches will pull up Apple Maps results #UnlikelyDebateGuests highlights people we only wish could be at the presidential debate Elon Musk does the math on another massive tunnel
1.2854s , 10196.671875 kb
Copyright © 2025 Powered by 【eroticism esteher perel】,Steady Information Network