Security researchers were able to bypass authentication on three popular laptops by testing the fingerprint sensors used for Windows Hello. The research was done by Blackwing Intelligence and Microsoft’s MORSE.
Target devices include a Dell Inspiron 15 with a Goodix fingerprint sensor, a Lenovo ThinkPad T14s with a Synaptics sensor, and a Microsoft Surface Pro X with an ELAN sensor. The embedded fingerprint sensors and the host were targeted with software and hardware attacks.
By infosecbulletin
/ Thursday , September 5 2024
CISCO released security updates for two critical security flaws impacting its smart Licensing Utility that could allow unauthenticated, remote attackers...
Read More
By infosecbulletin
/ Wednesday , September 4 2024
OpenBAS is a platform that helps organizations to plan, schedule, and conduct crisis exercises, adversary simulations, and breach simulations. OpenBAS...
Read More
By infosecbulletin
/ Wednesday , September 4 2024
Zyxel has released software updates to fix a serious security issue in certain access point (AP) and security router versions....
Read More
By infosecbulletin
/ Tuesday , September 3 2024
VMware released a security advisory for a major vulnerability in the VMware Fusion product. This vulnerability could be exploited by...
Read More
By infosecbulletin
/ Tuesday , September 3 2024
Indian Computer Emergency Response Team (CERT-IN) issued advisories about multiple vulnerabilities in various Palo Alto Networks applications. Attackers could exploit...
Read More
By infosecbulletin
/ Tuesday , September 3 2024
Malaysia is quickly becoming a leading choice for investing in data centers. It aims to generate RM3.6 billion (US$781 million)...
Read More
By infosecbulletin
/ Tuesday , September 3 2024
US authorities have issued a cybersecurity advisory about a ransomware group called RansomHub. The group is thought to have stolen data...
Read More
By infosecbulletin
/ Tuesday , September 3 2024
There is a new way to attack Atlassian Confluence using the vulnerability CVE-2023-22527. The Confluence Data Center and Server products...
Read More
By infosecbulletin
/ Tuesday , September 3 2024
The Cicada3301 ransomware is made in Rust and attacks Windows and Linux/ESXi hosts. Truesec researchers examined a version that targets...
Read More
By infosecbulletin
/ Tuesday , September 3 2024
Lloyds Bank and Virgin Money's internet banking services were down on Monday, causing trouble for users to access and view...
Read More
AlSO READ:
By 2025, Domestic cloud market expected $46.3 million; MD “DataHub Asia”
The sensors that were tested are Match-on-Chip, meaning the chip has a microprocessor and memory, and the fingerprint data always stays within the sensor. To bypass authentication, one would need to physically attack the chip itself.
To carry out the attack, the attacker needs to physically get hold of the device. This means they would have to either steal the device or use the evil maid method.
The researchers showed how to carry out attacks by connecting a hacking device to a laptop using USB or by connecting a specially crafted rig to the fingerprint sensor.
For Dell and Lenovo laptops, the Windows Hello fingerprint authentication was bypassed by manipulating valid user fingerprint ID numbers and enrolling the attacker’s fingerprint by imitating a legitimate user’s ID.
To hack the Surface device, the attacker must disconnect the Type Cover, which is the keyboard and fingerprint sensor, and connect a USB device that tricks the fingerprint sensor into thinking it’s an authorized user logging in.
Blackwing published a blog post on Tuesday about their findings. Microsoft also released a video of the Blackwing researchers presenting their findings at the BlueHat conference in October.