Cybersecurity (opens in new tab) experts have shared a proof-of-concept to bypass the Windows Hello (opens in new tab) biometric authentication system.
Threat actors can exploit the bypass, demonstrated by identity and access management (IAM) (opens in new tab) vendor CyberArk, to access an organization’s sensitive data by impersonating a privileged account.
Leaning on official figures (opens in new tab) from Microsoft that suggest that over 84% of Windows 10 (opens in new tab) users sign-in to their devices using Windows Hello, CyberArk argues that the bypass poses a grave security risk for businesses transitioning to password-less authentication.
- Here’s our list of the best password managers (opens in new tab)
- These are the best business password managers (opens in new tab)
- We’ve also rounded up the best identity management software (opens in new tab)
“While our research was specific to Windows Hello and more so the enterprise offering, Windows Hello for Business, it’s important to note that potentially any authentication system that allows a pluggable third-party USB camera (opens in new tab) to act as biometric sensor could be susceptible to this attack without proper mitigation,” writes (opens in new tab) CyberArk’s Security Researcher, Omer Tsarfati.
Targeted attacks
The exploit, which CyberArk likens to the one used by Tom Cruise in hit film Minority Report, involves using a custom USB device to steal an infrared image of the target’s face they want to impersonate.
The criminal can then use this image to compromise any facial recognition product which relies on a USB camera, such as Windows Hello.
CyberArk responsibly disclosed the issue to Microsoft, who fixed it as part of its July Patch Tuesday update.
However, based on preliminary testing, CyberArk researchers believe that while the mitigation does limit the attack surface, it relies on users having specific cameras.
“Inherent to system design, implicit trust of input from peripheral devices remains. To mitigate this inherent trust issue more comprehensively, the host should validate the integrity of the biometric authentication device before trusting it,“ says Tsarfati.
- Shield yourself with these best identity theft protection services (opens in new tab)