Jump to content

Windows Hello is Microsoft attempt at the password killer

AlexGoesHigh

windowshellopc1_1020.0.jpg

 

yep, Microsoft, just like Intel and many others are getting on the password killer hype train, their implementation is called windows hello.

 

windows hello can use cameras, infrared sensors and fingerprint scanners to scan the user face, iris or finger to unlock a device or sign in into services, depending on which piece of hardware is used, current fingerprint readers can work with hello, but current cameras can not, Microsoft specifies that for camera base recognition Intel's RealSense 3D cameras or similar are required, MS says that W10 devices are in the works that uses Intel technology.

 

on the software side hello is developed with security first and foremost to offer enterprise grade security, not just user convenience, but that is also one of the goals of hello. finger, faces and iris scan will never leave the hardware they are stored on in order to authenticate, it will use asymmetric encryption keys and it will be powerful enough to prevent tampering with the hardware to break in, like differentiating a photo from a true face and similar

 

hello is also much more that just unlocking the device, an API will be available so developers can integrate into its apps and software raging from private enterprise solution from login to web services like your email

 

besides Windows hello Microsoft is also revealing Passport (not to be confused with another MS product with the same name) a method of authentication through the use of personal devices like smartphone or wearables, think of it like an android phone being unlocked when is close to an android wear device, but like hello, it works for services and software, so you can enter a short PIN number or a hello scan on the phone and it will send an encrypted key to the service to validate

 

Microsoft is a member of the FIDO alliance, and has pledge support to make products compatible with the FIDO specification, so it is expected many services will support hello and Passport through the FIDO spec

 

windows hello and passport will be available in the many different types of devices that can run a form of windows 10

 

Source: The Verge, Neowin

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

I could get behind this if I had a windows phone. 

Daily Driver:

Case: Red Prodigy CPU: i5 3570K @ 4.3 GHZ GPU: Powercolor PCS+ 290x @1100 mhz MOBO: Asus P8Z77-I CPU Cooler: NZXT x40 RAM: 8GB 2133mhz AMD Gamer series Storage: A 1TB WD Blue, a 500GB WD Blue, a Samsung 840 EVO 250GB

Link to comment
Share on other sites

Link to post
Share on other sites

Enterprise security my ass, when rainbow tables no longer work I'll maybe start to even consider believing them.

Mein Führer... I CAN WALK !!

Link to comment
Share on other sites

Link to post
Share on other sites

My first thought is it have my front door hooked up to this so it unlocks with an eyescan.

Link to comment
Share on other sites

Link to post
Share on other sites

Eh, i'm okay with this, as long as it actually can be disabled so it's not constantly scanning my face and surroundings...

Specs: 4790k | Asus Z-97 Pro Wifi | MX100 512GB SSD | NZXT H440 Plastidipped Black | Dark Rock 3 CPU Cooler | MSI 290x Lightning | EVGA 850 G2 | 3x Noctua Industrial NF-F12's

Bought a powermac G5, expect a mod log sometime in 2015

Corsair is overrated, and Anime is ruined by the people who watch it

Link to comment
Share on other sites

Link to post
Share on other sites

Enterprise security my ass, when rainbow tables no longer work I'll maybe start to even consider believing them.

I'm probably missing something here but is the point of this not to take passwords out of use therefore rendering rainbow tables useless? 

Link to comment
Share on other sites

Link to post
Share on other sites

I'm probably missing something here but is the point of this not to take passwords out of use therefore rendering rainbow tables useless? 

Correct but the fact is that some people (a vast majority) don't want to use facial recognition because it's usually buggy or in the habit of passwords and so on. Also your almost likely guarantee to have a backup password/pin so in case facial recognition fails or the camera brakes you can still access your computer so it doesn't matter whether your using it or not.

Mein Führer... I CAN WALK !!

Link to comment
Share on other sites

Link to post
Share on other sites

Biometrics don't seem secure enough..

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

Neat but the idea of never ever being able to change my password scares me, so I am against things like fingerprint scanners.

I am willing to use it as my account name, but not as my password.

Link to comment
Share on other sites

Link to post
Share on other sites

Correct but the fact is that some people (a vast majority) don't want to use facial recognition because it's usually buggy or in the habit of passwords and so on. Also your almost likely guarantee to have a backup password/pin so in case facial recognition fails or the camera brakes you can still access your computer so it doesn't matter whether your using it or not.

Yeah I agree with you on some points but at the same time the change to password-less security has to start somewhere. I get the feeling that the facial recognition here isn't going to be the buggy - completely bypass security by using a freakin photo - bullshit that we're used to, whether this is true or not remains to be seen but I somehow get the feeling that it will actually be very robust using IR. I do completely agree with you that if there's a backup password/pin then the entire thing is kinda rendered useless cause rainbow tables etc. will not be affected in any way but I think that this will just be the starting point, I reckon in the near future there will be a switch to entirely biometric sign in with no backup passwords, they would have to implement a system to allow users to sign in if they do break their biometric reader or whatever but this is surely fairly simple, something like the code sent to your phone during two-step verification.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×