Jump to content

Windows Hello critical vulnerability, defeated by pictures of people's faces.

ItsMitch

what did you expect, when has MS ever made something that just works?

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

Lets just face it. This tech will not be perfect for a while and we need more time I think before implementing this kinda stuff to find issues like this.

Use this guide to fix text problems in your postGo here and here for all your power supply needs

 

New Build Currently Under Construction! See here!!!! -----> 

 

Spoiler

Deathwatch:[CPU I7 4790K @ 4.5GHz][RAM TEAM VULCAN 16 GB 1600][MB ASRock Z97 Anniversary][GPU XFX Radeon RX 480 8GB][STORAGE 250GB SAMSUNG EVO SSD Samsung 2TB HDD 2TB WD External Drive][COOLER Cooler Master Hyper 212 Evo][PSU Cooler Master 650M][Case Thermaltake Core V31]

Spoiler

Cupid:[CPU Core 2 Duo E8600 3.33GHz][RAM 3 GB DDR2][750GB Samsung 2.5" HDD/HDD Seagate 80GB SATA/Samsung 80GB IDE/WD 325GB IDE][MB Acer M1641][CASE Antec][[PSU Altec 425 Watt][GPU Radeon HD 4890 1GB][TP-Link 54MBps Wireless Card]

Spoiler

Carlile: [CPU 2x Pentium 3 1.4GHz][MB ASUS TR-DLS][RAM 2x 512MB DDR ECC Registered][GPU Nvidia TNT2 Pro][PSU Enermax][HDD 1 IDE 160GB, 4 SCSI 70GB][RAID CARD Dell Perc 3]

Spoiler

Zeonnight [CPU AMD Athlon x2 4400][GPU Sapphire Radeon 4650 1GB][RAM 2GB DDR2]

Spoiler

Server [CPU 2x Xeon L5630][PSU Dell Poweredge 850w][HDD 1 SATA 160GB, 3 SAS 146GB][RAID CARD Dell Perc 6i]

Spoiler

Kero [CPU Pentium 1 133Mhz] [GPU Cirrus Logic LCD 1MB Graphics Controller] [Ram 48MB ][HDD 1.4GB Hitachi IDE]

Spoiler

Mining Rig: [CPU Athlon 64 X2 4400+][GPUS 9 RX 560s, 2 RX 570][HDD 160GB something][RAM 8GBs DDR3][PSUs 1 Thermaltake 700w, 2 Delta 900w 120v Server modded]

RAINBOWS!!!

 

 QUOTE ME SO I CAN SEE YOUR REPLYS!!!!

Link to comment
Share on other sites

Link to post
Share on other sites

As long as they don’t force it to be enabled then I’m happy. 

 

For backstory, Windows 10 devices enrolled into AzureAD businesses / enterprise) auto login to Office 365/Azure portal. Essentially if you can fool Hello with an IR picture of the IT dude, you can have unrestricted access to the companies IT system even if you have passwords and MFA in place. 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, suicidalfranco said:

what did you expect, when has MS ever made something that just works?

Uhm the Xbox 360 “just works”. ?

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

52 minutes ago, Windspeed36 said:

For backstory, Windows 10 devices enrolled into AzureAD businesses / enterprise) auto login to Office 365/Azure portal. Essentially if you can fool Hello with an IR picture of the IT dude, you can have unrestricted access to the companies IT system even if you have passwords and MFA in place

Sounds 100% secure and nothing could possibly go wrong at all. 

Link to comment
Share on other sites

Link to post
Share on other sites

13 hours ago, DrMacintosh said:

Looks back at all the shade people tried to throw on Apple

In short, seeing Face ID fooled by identical twins and kids that look like their parents is the lesser of two evils in comparison to Windows Hello being fooled by a low resolution photo which is an embarrassment. 

 

And it only proves that passwords/PIN is still the most secure way of authentication and biometrics is more about better accessibility with the expense of less security. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

58 minutes ago, Windspeed36 said:

As long as they don’t force it to be enabled then I’m happy. 

 

For backstory, Windows 10 devices enrolled into AzureAD businesses / enterprise) auto login to Office 365/Azure portal. Essentially if you can fool Hello with an IR picture of the IT dude, you can have unrestricted access to the companies IT system even if you have passwords and MFA in place. 

Lets hope that the IT guys that high up have more brain than r=1 users and avoid using this swiss cheese... (But i have my doubts since they using 10.)

Link to comment
Share on other sites

Link to post
Share on other sites

LOL what a turn of events 

i5 2400 | ASUS RTX 4090 TUF OC | Seasonic 1200W Prime Gold | WD Green 120gb | WD Blue 1tb | some ram | a random case

 

Link to comment
Share on other sites

Link to post
Share on other sites

Man, if it ever was Apple, this topic would be trending with die hard haters.

Coming back on topic, is this really a surprise? Microsoft has an amazing track record of screwing up things in a colossal way and this seems to be no different.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, hey_yo_ said:

Uhm the Xbox 360 “just works”. ?

until it starts cooking itself 

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, ravenshrike said:

Eh, if it's topographically mapped as well it's pretty unique. Course, that requires a hell of a lot more sophistication than Windows Hello.

9 hours ago, Commodus said:

Face security is fine when it's done well.  This is why Apple bent over backwards with its depth sensing approach to Face ID -- so you couldn't fool it with a photo. The problem is that Hello just isn't as sophisticated.

https://wccftech.com/apple-iphone-x-friend-unlock-not-once-twice/

Skepticism aside, this isn't the only time this was reported with Face ID.

It just still begs the question for me. Fingerprints are highly probable to be unique. Passwords/phrases as well. I get that it's convenient to look-unlock the phone, and I get for perhaps a home computer as well, but at what cost for a public computer or a phone you carry daily? At what point does it become a nuisance that this supposedly "secure" feature is being thwarted seemingly so easily?

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, HarryNyquist said:

Fingerprints are highly probable to be unique.

True. As a matter of fact, even identical twins don't have the same fingerprints.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, suicidalfranco said:

until it starts cooking itself 

At least that one can be fixed at home... :D

Link to comment
Share on other sites

Link to post
Share on other sites

*cough* use a password *cough*

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/21/2017 at 10:28 PM, DrMacintosh said:

Looks back at all the shade people tried to throw on Apple

which was fully deserved lol

as is any and all complaints about this failure

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

On 21/12/2017 at 4:44 PM, goodtofufriday said:

I dont understand? Where is the vulnerability here? its just bad software.

Im with u. 

Connection200mbps / 12mbps 5Ghz wifi

My baby: CPU - i7-4790, MB - Z97-A, RAM - Corsair Veng. LP 16gb, GPU - MSI GTX 1060, PSU - CXM 600, Storage - Evo 840 120gb, MX100 256gb, WD Blue 1TB, Cooler - Hyper Evo 212, Case - Corsair Carbide 200R, Monitor - Benq  XL2430T 144Hz, Mouse - FinalMouse, Keyboard -K70 RGB, OS - Win 10, Audio - DT990 Pro, Phone - iPhone SE

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/21/2017 at 12:17 PM, tjcater said:

Jokes on them, my laptop doesn't even support it :P But seriously, that has to be one poorly thought out algorithm if its defeated by low res pictures. (Wasn't Windows Hello supposed to have depth detection too?)

Edit: Another thought, they might need to disable supporting facial logins when lighting is poor

I have actually been able to login via hello in a completely dark room except for the light from my screen

Wii-U Wii-U Wii-U Wii-U Wii-U Wii-U Wii-U *insert firetruck picture* :) 

Link to comment
Share on other sites

Link to post
Share on other sites

On ‎2017‎-‎12‎-‎21 at 2:28 PM, DrMacintosh said:

Looks back at all the shade people tried to throw on Apple

It goes both ways. 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/23/2017 at 12:00 AM, RedRound2 said:

Man, if it ever was Apple, this topic would be trending with die hard haters.

Coming back on topic, is this really a surprise? Microsoft has an amazing track record of screwing up things in a colossal way and this seems to be no different.

 

I fully expect those who where defending apple to defend MS now,  seeing as it's the same people shitting on MS for this as it was for apple.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, mr moose said:

 

I fully expect those who where defending apple to defend MS now,  seeing as it's the same people shitting on MS for this as it was for apple.

ahahahah

Not happening.

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/21/2017 at 11:44 AM, goodtofufriday said:

I dont understand? Where is the vulnerability here? its just bad software.

"Windows 10" would be the vulnerability.

 

I'm no longer on Windows 7, but I do like some of the things about Windows 10. I just wish it would do what I tell it and only what I tell it. Every time there's an update I have to redo my settings.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×