Near-infrared image trickery can allow an attacker to bypass Window 10 Hello face authentication.
Security researchers are urging Windows 10 users to update their systems to prevent attackers from using a printed headshot to bypass Windows Hello facial authentication.
Researchers from German pen-testing firm SYSS reported that Windows 10 systems that have not yet received the recent Fall Creators Update are vulnerable to a "simple spoofing attack using a modified printed photo of an authorized person". The attack works against multiple versions of Windows 10 and different hardware.The researchers tested the spoofing attack against a Dell Latitude with a LilBit USB camera and against a Surface Pro 4 running various versions of Windows 10, going back to the one of the first releases, version 1511.
SYSS claims the spoofing attack was successful on a Surface Pro 4 running version 1607 of Windows 10, the Anniversary Update rolled out in summer 2016, even with Microsoft's enhanced anti-spoofing enabled. However, the attack was only successful on version 1703, the Creators Update rolled out in Spring 2017, and 1709, the Fall Creators Update currently being rolled out, when anti-spoofing was disabled.
However, just applying the Fall Creators Update is not enough to block the spoofing attack, according to SYSS. To prevent a successful attack, users need to also setup Windows Hello face authentication from scratch after the update, as well as enabling anti-spoofing.
SYSS provided twovideos demonstrating its proof of concept attacks. A third video shows the attack on a Surface Pro that was updated to version 1709 without reconfiguring Hello face authentication.
A key element of the attack appears to be taking a headshot of the authenticated user with the near-infrared (IR) camera. Windows Hello uses near-IR imaging to unlock Windows devices. Microsoft chose near-IR imaging for authentication because it worked in poor lighting and offered some protection against spoofing attacks, since IR images aren't typically displayed in photos or on a screen.
SYSS printed out a modified version of the near-IR captured headshot in various resolutions and colors. Holding the printout up to a locked device's camera successfully unlocked it. Another method involved placing opaque sticky tape over the RGB camera lens and then holding the same printout up.
As far as the fix goes, SYSS notes that in its test only the Surface Pro 4 supported enhanced anti-spoofing while the LilBit USB IR camera did not.
The company plans to reveal further variations of its attack in spring 2018.
"According to our test results, the newer Windows 10 branches 1703 and 1709 are not vulnerable to the described spoofing attack by using a paper printout if the "enhanced anti-spoofing" feature is used with respective compatible hardware," SYSS wrote.
"Thus, concerning the use of Windows Hello face authentication, SYSS recommend updating the Windows 10 operating system to the latest revision of branch 1709, enabling the "enhanced anti-spoofing" feature, and reconfiguring Windows Hello face authentication afterwards."
Microsoft had not responded to a request for comment at the time of publication.
Simple spoofing attack works against multiple versions of Windows 10.Image: SYSS
Two vulnerabilities discovered and patched over the summer expose Jenkins servers to mass exploitation. Thousands, if not more, Jenkins servers are vulnerable to data theft, takeover, and cryptocurrency mining attacks. This is because hackers can exploit two vulnerabilities to gain admin rights or log in using invalid credentials on these servers. Both vulnerabilities were discovered by security researchers from CyberArk , were privately reported to the Jenkins team, and received fixes over the summer. But despite patches for both issues, there are still thousands of Jenkins servers available online Jenkins is a web application for continuous integration built in Java that allows development teams to run automated tests and commands on code repositories based on test results, and even automate the process of deploying new code to production servers. Jenkins is a popular component in many companies' IT infrastructure and these servers are very popular with both f...
Summary: The secretive system uses data and other techniques to ferret out cops and root out anyone who may do the service harm. An internal program used by Uber for years to dance around the police in areas where the ride-hailing service was frowned upon has been exposed. In cities such as Boston, Las Vegas, and Paris, alongside countries including China and South Korea, Greyball is used as part of the violation of terms of service (VTOS) program which Uber created in 2014 to ferret out and black-mark anyone that may be a threat to the firm.Dubbed Greyball, Uber's program uses data analytics and a myriad of other tactics to avoid the authorities in places where the service is resisted by law enforcement or banned outright, according to the New York Times . Predominantly used in the US, Greyball first came to light in the same year when investigators began to hail rides using the Uber app to build a case against the company. One such investigator, Erich England from ...
Biometric smartphones to become mainstream in 2014, Ericsson says Summary: Following the release of the fingerprint sensor-enabled iPhone 5s, more smartphone makers could soon jump on the bandwagon, if Ericsson's predictions prove true. By the end of 2014, a wealth of new smartphones could come with biometric technology, such as fingerprint recognition hardware. In September, Apple released the iPhone 5s, which included a fingerprint reader , in the hope of bolstering security and improving usability. And other mobile makers, keen to jump on the biometric bandwagon, could soon embed the technology in their own devices. According to new research by mobile network maker Ericsson, which polled 100,000 people over 40 countries, about 74 percent of respondents said they believe biometric smartphones "will become mainstream" during 2014. More than half at 52 percent want to use their fingerprints instead of a complex alphanumeric combination of letters...
Comments
Post a Comment