{"id":54667,"date":"2025-08-08T14:17:09","date_gmt":"2025-08-08T14:17:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/54667\/"},"modified":"2025-08-08T14:17:09","modified_gmt":"2025-08-08T14:17:09","slug":"windows-hello-security-bypassed-using-other-peoples-faces","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/54667\/","title":{"rendered":"Windows Hello Security Bypassed Using Other People\u2019s Faces"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2025\/08\/1754662629_663_960x0.jpg\" alt=\"A man and woman are seen holding photos of each others faces in front of their own. \" data-height=\"1864\" data-width=\"2802\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Windows Hello face recognition bypassed.<\/p>\n<p>getty<\/p>\n<p>Hacking has never been in the news more than it is right now, what with the confirmation that <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/google-confirms-it-has-been-hacked---user-data-stolen\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/google-confirms-it-has-been-hacked---user-data-stolen\/\" target=\"_self\" aria-label=\"Google has been hacked\" rel=\"nofollow noopener\">Google has been hacked<\/a> and user information stolen, further <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/airline-data-breach-warning---air-france-and-klm-confirm-cyber-attack\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/airline-data-breach-warning---air-france-and-klm-confirm-cyber-attack\/\" target=\"_self\" aria-label=\"airline data breaches\" rel=\"nofollow noopener\">airline data breaches<\/a>, and, of course, Windows users being warned about new <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/04\/microsoft-windows-is-being-hacked-if-you-see-these-jpeg-images\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/04\/microsoft-windows-is-being-hacked-if-you-see-these-jpeg-images\/\" target=\"_self\" aria-label=\"cyberattacks employing JPEG images\" rel=\"nofollow noopener\">cyberattacks employing JPEG images<\/a>. And talking of hackers and Windows, both came together rather splendidly in Las Vegas at the Black Hat hacking conference where it was demonstrated how the Windows Hello facial recognition sign-in security could be bypassed by a threat actor injecting their own images into the process. Here\u2019s what you need to know.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/google-confirms-it-has-been-hacked---user-data-stolen\/\" target=\"_blank\" aria-label=\"Confirmed: Google Has Been Hacked \u2014 User Data Compromised\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/google-confirms-it-has-been-hacked---user-data-stolen\/\" rel=\"nofollow noopener\">ForbesConfirmed: Google Has Been Hacked \u2014 User Data CompromisedBy Davey Winder<\/a><br \/>\nThe Windows Hello Security Sign-In Bypass<\/p>\n<p>The security researchers who demonstrated a Windows Hello security bypass at Black Hat in Las Vegas this week didn\u2019t need to use a <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" target=\"_self\" aria-label=\"known camera vulnerability\" rel=\"nofollow noopener\">known camera vulnerability<\/a> or a cleverly constructed <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/03\/as-face-swap-attacks-surge-300-take-this-spot-a-deepfake-test-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/03\/as-face-swap-attacks-surge-300-take-this-spot-a-deepfake-test-now\/\" target=\"_self\" aria-label=\"deep fake image\" rel=\"nofollow noopener\">deep fake image<\/a>, in order to convince the computer in question to accept a totally different face from the registered user during the sign-in process.<\/p>\n<p>Instead, Dr Baptiste David and Tillmann Osswald from <a class=\"color-link\" href=\"https:\/\/ernw-research.de\/en\/services.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/ernw-research.de\/en\/services.html\" aria-label=\"ERNW Research\">ERNW Research<\/a>, showed how, as The Register <a class=\"color-link\" href=\"https:\/\/www.theregister.com\/2025\/08\/07\/windows_hello_hell_no\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.theregister.com\/2025\/08\/07\/windows_hello_hell_no\/\" aria-label=\"reported\">reported<\/a>, the business version of Windows Hello can be compromised by someone with access to local admin credentials injecting \u201cbiometric information into a computer that would allow it to recognize any face or fingerprint.\u201d<\/p>\n<p>The problem, it would appear, sits with the way that Windows Hello uses a cryptographic key stored in a database linked to the Windows Biometric Service, allowing corporate users to connect Entra ID, for example, to provide server access. So, a key pairing is generated during provisioning, which is registered with Entra ID, or whatever identity provider is being employed by the organization.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/07\/cisa-issues-urgent-microsoft-cve-2025-53786-security-warning\/\" target=\"_blank\" aria-label=\"CISA Issues Urgent Microsoft CVE-2025-53786 Security Warning\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/07\/cisa-issues-urgent-microsoft-cve-2025-53786-security-warning\/\" rel=\"nofollow noopener\">ForbesCISA Issues Urgent Microsoft CVE-2025-53786 Security WarningBy Davey Winder<\/a><\/p>\n<p>So far, so good. Until security researchers come along and find that they can break the encryption used to protect this database entry, providing they have local admin privileges, by whatever means. Microsoft\u2019s Enhanced Sign-in Security would stop this kind of attack, but for many users it isn\u2019t enabled, not least thanks to the hardware requirements needed.<\/p>\n<p>The hacking duo said that to fix the issue would take \u201ca significant code rewrite\u201d on the part of Microsoft, and so recommended disabling biometrics and using an old-fashioned PIN if you are running Hello for Business without employing Enhanced Sign-in Security.<\/p>\n<p>I have reached out to Microsoft for a statement regarding the latest Windows Hello security bypass issue and will update this article if any is forthcoming. <\/p>\n","protected":false},"excerpt":{"rendered":"Windows Hello face recognition bypassed. getty Hacking has never been in the news more than it is right&hellip;\n","protected":false},"author":2,"featured_media":54668,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[36573,36570,49,48,36572,15142,32137,36574,61,36575,36569,36571],"class_list":["post-54667","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-biometric-security-warning","tag-blackhat","tag-ca","tag-canada","tag-face-swap","tag-facial-recognition","tag-hackers","tag-microsoft-security-bypass","tag-technology","tag-windows-enhanced-sign-in-security","tag-windows-hello","tag-windows-hello-bypass"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/54667","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=54667"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/54667\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/54668"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=54667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=54667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=54667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}