Researchers at the German IT Security company SySS GmbH successfully fooled the Windows 10 facial recognition system by using a printed photo of the user's face.
Their spoofing efforts were published on Busty Cops on Patrol (2009)the cybersecurity site Seclists on Dec. 18. The cybersecurity experts bypassed Windows Hello -- which is Microsoft's password-free security software -- on both a Dell and Microsoft laptop running different versions of Windows 10, which is cause for concern for anyone using this feature to log into their account.
SEE ALSO: This nasty Android malware caused a phone to overload and bulgeDeceiving Windows 10 didn't take too much effort. It just required "having access to a suitable photo of an authorized person" to "easily" bypass the system, wrote the experts. The photo required is the full image of someone's face -- so if someone really wants to attempt to deceive the facial recognition system, the barriers aren't too great.
Similar to Apple's Face ID, it might be wise to view Windows Hello as a convenience feature, not a security feature.
Similar to the iPhone X's Face ID camera, Hello Windows uses an infrared camera (either built-in the or added separately) to recognize the unique shape and contours of a face before granting or denying access to a Windows account. But a flaw was found, specifically "an insecure implementation of the biometric face recognition in some Windows 10 versions."
They show their work below:
Many -- but not all -- Windows versions are vulnerable. In 2016, Microsoft included a new feature called Enhanced Anti-Spoofing to limit this sort of picture trickery. But even if this feature is enabled in your Windows settings, the researchers found a way to bypass the facial recognition system that ran older Windows versions, such as a Microsoft Surface Pro 4 device running 2016's Windows 10 Anniversary update, for instance.
However, the SySS researchers found that two new Windows versions, 1703 and 1709, are not vulnerable to their most simple spoofing attacks (using a printed photograph) if Enhanced Anti-Spoofing is enabled.
Their ultimate recommendation: Updating to Windows 10 version 1709, enabling anti-spoofing, and then having Windows Hello reanalyze your face.
If this sounds unappealing or risky, you can always go back to using a (not dumb) password. Infrared facial recognition in consumer applications is still relatively new, so flaws should be expected.
Similar to Apple's Face ID, it might help to view Windows Hello as a convenience feature, not a security feature.
Mashable has contacted Microsoft for comment and will update this story upon hearing back.
Topics Cybersecurity Windows
Previous:Surveillance Valley
There's finally an easy way to see 'Retweets with Comments' on TwitterAll the outlandish things Trump said in his commencement speech for the Coast GuardInstagram introduces new features to help create a more positive spaceNew algorithm discovers hundreds of Android 'creepware' appsChihuahua in graduation cap and gown earns bachelor's degree in cutenessYour internet provider is full of it on net neutrality. Now with proof.Slack's redesigned mobile apps are less likely to make you bang your head against a wallPhotographer undertakes mission to document every species on EarthSenate gives law enforcement the OK to spy on your internet historyUse these five free Google Meet features to get the best video callsReddit's new Community Points could be huge for EthereumJustin Bieber singing about iced coffee is the 2017 Song of the SummerSomeone helpfully rearranged a bookstore's Ivanka Trump displayBarbie debuts #ThankYouHeroes program, honoring first respondersHBO partners with Scener to create coEpic 'Why I left BuzzFeed' video is straight out of a Marvel movieAll 201 episodes of 'The Office' will be recreated on SlackFacebook to acquire Giphy for $400 millionApple now lists 2013 MacBook Air and 2014 MacBook Pro as 'vintage products'Slack's redesigned mobile apps are less likely to make you bang your head against a wall Stunning Webb telescope photo shows an unbelievable number of galaxies Nvidia's DLSS Second Take: Metro Exodus Investigation Melania Trump welcomes you into the AI audiobook era with new memoir Raycon Everyday Earbuds deal: 20% off at Amazon Why the monarch butterfly in the U.S. will likely be officially endangered Astronomers cast doubt on 'runaway black hole' discovery From Yondr pouches to screen What is Crypto Mining? Best Garmin deal: Get $50 off the Garmin Forerunner 165 at Amazon The 4 best AI image generators of 2025 Knicks vs. Pacers 2025 livestream: Watch Game 2 of NBA playoffs for free TechSpot PC Buying Guide: 2H 2024 Halo Infinite PC Graphics Benchmark Nintendo Switch 2 supports USB mice, too Anatomy of a Monitor My first orgasm: In order to get off, I had to log off NYT Connections hints and answers for June 1: Tips to solve 'Connections' #722. Today's Hurdle hints and answers for June 2, 2025 The OLED Burn How to watch 'The Last Showgirl': Now streaming
1.9876s , 10130.6640625 kb
Copyright © 2025 Powered by 【Busty Cops on Patrol (2009)】,Inspiration Information Network