6 ms·
Windows Hello face recognition is vulnerable to the Jedi mind trick
- damianknz 10y agoI have Windows Hello enabled on my phone (a 950) and it scans my iris with an infra-red camera/light. This means it still works in the dark and cant be fooled by a photo (or a 3d model I guess!)
- kylemuir 10y agoStill wouldn't stop Wesley Snipes in Demolition Man :)
- kevinherron 10y agoI've had a SP4 since they were released. It's got some faults, but Windows Hello has worked flawlessly for me. It sounded like such a gimmick before I used it but it's actually pretty neat.
- zyxley 10y agoThe main thing that worries me about it is that "what your face looks like" is superbly easy to copy. I mean, fingerprints aren't that much more secure in a technical sense, but at least a lot of people don't actively post images of their fingerprints to all their social media accounts.
- fintler 10y agoI don't think the threat model for this cares about that. This is designed for home users who don't have security requirements that make them carry around OTP devices just to see their desktop. I mean, you can argue that passwords are pretty easy to copy as well -- you just need a video camera facing at the keyboard for a day or three.
- shliachtx 10y agoIf I'm not mistaken Windows Hello will only do facial recognition on a depth-sensing camera, so you would need to create a 3D model of my face to fool it.
- deleted 10y ago[deleted]
- AaronFriel 10y agoI understand it not only uses depth sensing, but also infrared, and it can distinguish between twins. That last item is the most interesting and perplexing to me.
- qq66 10y agoTwins are easily distinguishable if you know them -- I went to high school with three pairs and they were easy to tell apart. Almost everyone has some pockmark etc. on their face, and Identical twins often have these in mirror image.
- underwater 10y agoThat doesn't explain how software can distinguish them.
- JohnTHaller 10y agoWindows Hello only works with newer cameras that support depth/3d sensing. Only a handful of laptops and a couple external cameras have this functionality. Windows Hello doesn't work with standard cameras as it would be easier to bypass.
- Mahn 10y agoSP4 user here too, Windows Hello failed exactly once for me: when I was setting it up. Ever since then it's worked flawlessly. It's so insanely good it's almost hard to believe Microsoft built it. When Android first came up with face recognition it was a gimmick; half of the time it didn't work, it took too long, you needed the right amount of light, etc etc. But I can confidently say that Microsoft's implementation is nothing like it, they've actually made it work.
- deleted 10y ago[deleted]
- mtgx 10y agoMicrosoft should fix its 4-digit PIN/no limiter app authentication first. https://www.cnil.fr/en/windows-10-cnil-publicly-serves-formal-notice-microsoft-corporation-comply-french-data-protection https://www.cnil.fr/en/windows-10-cnil-publicly-serves-forma...
- fintler 10y ago> The company allows users to choose a four characters PIN to authenticate themselves for all its on-line services, notably to access to their Microsoft account What pin is this talking about? The only pin I see related to my account is a 6-digit one that the Google authenticator app generates. Is this some kind of enterprise feature?
- AaronFriel 10y agoWindows 10 allows PIN sign in, but it's done with the TPM to ensure a limited number of accesses.
- NeutronBoy 10y agoAnd IIRC it's tied to a single machine, so you need physical access for it to be any use.
- mtgx 10y agoThat's how PINs typically work. The main threat for a PIN password without any attempt limiter is local bruteforce.
- WorldMaker 10y agoAs someone who has accidentally locked himself out of his own Windows device before, there is definitely an attempt limiter on PINs in Windows. You have to resign in with your full password and must reset the PIN.
- ctpide 10y agoJedi: "These are not the faces you are looking for." Windows: "Are you sure? [Yes] [No] [Cancel]"
- deleted 10y ago[deleted]
- balls187 10y agoWindows: "Are you sure? [Yes] [No] [Cancel] [Upgrade to Windows 10]"
- kenjackson 10y agoActually should prompt: Retry, abort, or fail
- pookeh 10y agoWow pretty desperate marketing for a design flaw.
- algorithmsRcool 10y agoI highly doubt that Raymond Chen, a 24 year veteran of Microsoft and WinAPI / NT kernel expert, is shilling for marketing kudos. He probably just thought it was a neat side effect.
- Piskvorrr 10y agoIt's not a bug - it's a feature! https://geekwhisperin.files.wordpress.com/2009/09/bug-vs-feature.jpg https://geekwhisperin.files.wordpress.com/2009/09/bug-vs-fea...
- sandworm101 10y agoFree advice: Do not use biometrics to unlock devices. Face/fingerprint recognition is subject to different, lesser, protections than memorized passwords. Criminal defense 101: Don't talk to the police. Don't admit anything, including any sort admission of owning a phone. If they can use your face/finger to unlock a phone, that proves it is your phone. Even if you one day want to admit owning that phone, do not allow them to unlock it without your permission. The unlocking of any device should only happen after negotiations with the assistance of counsel, not at 2am in a parking lot. Use some sort of memorized password/pattern.
- justratsinacoat 10y agoThe clickbait 'title' makes some claim to vulnerability, except that's the wrong word entirely. The described "vulnerability" is logically equivalent to briefly removing one's face from the frame, because that's what this is. The article actually suggests that as the usual alternative! There's nothing else going on here beyond "think about Windows Hello, please". Is this really what we want HN to be about?
- accatyyc 10y agoIt is the title of the blog post though, which is a Microsoft blog. I don't think clickbaiting was the intention of the poster.
- WorldMaker 10y agoGiven it's from Old New Thing, I'm willing to bet clickbaiting was indeed the intention of the poster (Mr. Chen), as this title and the article itself seem to follow his sense of humor.
- deleted 10y ago[deleted]
- blowski 10y agoIt's tech-related fun, and yes, it made me chuckle so I'm fine with it being on HN. I might even say it's a 'hack'.
- justratsinacoat 10y ago>I might even say it's a 'hack' I guess it is an appropriate submission for Hac-- er I mean "Left-Facebook-Logged-In"-er News
- Sylos 10y agoWho gives a fuck?