Fool Windows Hello with a fake camera
CyberArk security researchers have found a way to fool the Windows Hello facial recognition system on Windows. They found that Windows Hello's authentication system only focused on processing the image data collected by the infrared sensor.
CyberArk experimented by creating a custom USB camera. They then loaded the infrared image of the user and the RGB image of the Spongebob cartoon character into a data stream that passed from the USB camera to the Windows Hello authentication system.
The system accepts this custom USB camera and even unlocks Windows computers based on infrared images alone, ignoring irrelevant RGB images. The researchers even found that Windows Hello's authentication system only needed an IR frame and a black image to accept the unlock.
To exploit this vulnerability, the hacker must have at hand an infrared image of the user's face. This is a difficult thing but not impossible. Hackers can break into surveillance camera systems that are installed everywhere to get images of the person they want to attack.
Obviously this is a weak point in Microsoft's security system. Software giants need to make sure their authentication technology is secure as users increasingly rely on biometric security instead of passwords.
Microsoft has admitted this is a vulnerability in the Windows Hello security feature. This vulnerability is assigned the code CVE-2021-34466 and is being researched by Microsoft to find a fix. In the meantime, Microsoft recommends users to use Windows Hello Enhanced Sign-in Security to ensure safety.
However, CyberArk cautions users that not all devices support Windows Hello Enhanced Sign-in Security.
You should read it
- 12 signs that your computer is hacked
- Just one page access, Windows PC can also be hacked
- NoxPlayer emulator was hacked and malicious code inserted
- 5 signs that your family's surveillance camera has been hacked
- You can hack Mazda cars with USB Flash Drive
- How to know if Facebook, Instagram, Google and other social networks have been hacked
- How to turn on anti-malware protection on Windows
- Computers that are not connected to the internet can still be hacked
May be interested
- Earth-shattering hoaxes in the history of April Fool's Daythe history of april fool's day has witnessed earth-shattering hoaxes that made millions of people believe, and many major mass media agencies also participated.
- Top 7 most easily counterfeited foods todayjoin tipsmake.com to consult the top 7 most easily counterfeited foods today!
- 4 virus fake troll friends extremely happytroll friends and family members are happy if they are harmless jokes. today, with the development technology we always plug in the laptop, tablet pc to the smart phones. so there's nothing more fun than troll friends doing like destroying their hard drive with a fake virus.
- How to use Idea VPN fake IP on Windowsidea vpn is a virtual private network vpn application on windows 10 that helps you access the internet anonymously, access blocked websites, protect user personal information.
- 5 simple and effective Chrome fake ip applications todaythe following chrome ip fake apps will help you easily access any blocked websites.
- The best camera app for Androidandroid device users can choose the following photography applications with rich features, professional shooting mode and integrated advanced editing tools with many special effects.
- 10 fake call apps on Androidfake call application helps you create calls from your own phone to avoid awkward, unwanted situations.
- How to use X-VPN to surf the web anonymously on Windows - Safer when surfing the webx-vpn is a virtual private network application on windows that helps you surf the web anonymously and access blocked websites.
- How to fake ipyou want to find a way to fake ip to use virtual ip to access facebook, get blocked website quickly and safely. there are many ways to help you fake ip, here are 3 ways to help you fake ip quickly, you can refer.
- Hackers fake Windows 11 download page to spread malicious codehackers are luring naive users into downloading fake windows 11 containing malicious code that steals browser data and cryptocurrency wallets.