8 ms·
Windows Hello bypassed using infrared image
- xaduha 5y agoCatchy umbrella names for a set of security-related products/services cause more harm than good, see Google Titan. When just one facet of that gets compromised it sows doubt about the whole thing due to clickbaity titles.
- gregmac 5y agoIt seems like it wouldn't be a stretch to make a USB webcam that presented an "animated" infrared image -- would that defeat this fix? What I'd really like is the system to consider every new USB device untrusted, and require specific approval before it's added as a device. This should apply to its capabilities too (eg: if a "keyboard" suddenly is presenting itself as storage, that causes a prompt). Think along the lines of "Acme WebCam XYZ wants to add a Camera and Microphone. Allow?" And while the computer is locked this should absolutely be impossible. I went looking for some commercial stuff, and there seems to be products aimed at businesses -- but seems these are centrally-managed, work by whitelisting specific devices ahead of time, and are more focused on data exfiltration than preventing a rogue keyboard, badusb or rubber ducky. Is there something that does this?
- noobermin 5y agoSeems like a recipe for severe headaches and cursing when devices fail while you're logged out and now you can't log in by just connecting a new keyboard.
- nitrogen 5y ago"Please press this key sequence, then type your password, on the newly attached keyboard to enable it for use."
- ivegotnoaccount 5y agoThen you will (probably) get malwares that open a window in fullscreen that imitates that prompt and sends data to a server. You probably could add some kind of fingerprint that allow identifying the legit prompts, but since it is not done with login screens...
- nitrogen 5y agoThis is why Windows used to ask for Ctrl-alt-del before login. And if you have malware already on your system, it's already too late.
- gregmac 5y agoAside from already having malware making this irrelevant, if you didn't just physically attach a new keyboard, the message about a new keyboard is also going to seem very suspicious.
- banana_giraffe 5y agoNow I'm curious if there's some device that presents itself as a keyboard, types some Powershell script and "copies" files off of the computer using numlock/capslock/scrolllock signals.
- nightfly 5y agoThat's a USB Rubber Ducky
- banana_giraffe 5y agoHah. Never played with one, but I just assumed it was a macro playback engine, not surprising, I suppose it would do more.
- schmorptron 5y agoYes! Look into BadUSB, there's some really cool, but also scary, stuff out there.
- tyingq 5y ago>if a "keyboard" suddenly is presenting itself as storage, that causes a prompt I'm not clear on how you would know it was the keyboard changing identities and not just a new device. Does the USB protocol provide anything where you would know, assuming devices can change Base Class, VID, PID, and so on? For that matter, I don't think it needs to change. It can just emulate a hub and present both.
- numpad0 5y agoCurrent USB host controllers aren’t built in the way they can distinguish between physical removal and electronic self reset. Maybe if you’re NSA you could roll your own USB xHCI and a USB A receptacle that could characterize and identify individual units down to a machine in China used to assemble it, but that will be lightyears ahead of commercial USB host controllers.
- gruez 5y agoWhat you'd described would require each USB device to cryptographically sign its communications with an unique key. AFAIK USB doesn't have this, but thunderbolt does (it's called "secure connect"). Even if it does get implemented though, it probably won't help much because most users can be social engineered into trusting the new device.
- ohazi 5y agoThe common USB device classes (video device, HID keyboard/mouse, etc.) don't have this, but anybody can define a new device class that does. It seems like maybe Microsoft should have required something like this for Windows Hello cameras, if they intended for people to use the hardware as a single factor authenticator. i.e. the camera generates internal crypto keys and tells Windows about them when you set up Windows Hello, then Windows does a challenge/response to make sure it's getting an image from the authentic camera during login attempts. Apple did something like this with the fingerprint reader home buttons on iPhones, which is why you had to replace the motherboard + home button as a single unit on damaged devices. They could have provided a reprovisioning tool, but it's Apple, so they didn't.
- lrvick 5y ago> What I'd really like is the system to consider every new USB device untrusted, and require specific approval before it's added as a device. QubesOS does this by quarantining your USB controllers in a dedicated virtual machine. https://www.qubes-os.org/doc/usb-qubes/ https://www.qubes-os.org/doc/usb-qubes/ Usb-guard for Linux also uses kernel features to accomplish similar. I dont know of any methods to do this on MacOS or Windows though.
- vladvasiliu 5y ago> What I'd really like is the system to consider every new USB device untrusted, and require specific approval before it's added as a device. This should apply to its capabilities too (eg: if a "keyboard" suddenly is presenting itself as storage, that causes a prompt). Think along the lines of "Acme WebCam XYZ wants to add a Camera and Microphone. Allow?" There's USBGuard on Linux that seems to do some of this. Can't vouch for it, as I've never used it, though. https://wiki.archlinux.org/title/USBGuard https://wiki.archlinux.org/title/USBGuard https://github.com/USBGuard/usbguard https://github.com/USBGuard/usbguard
- smoldesu 5y agocool
- chmod775 5y agoIf you're using that as your sole authentication mechanism, then you're not encrypting your data with a password. It's already game over. These kinds of things of 'security'* features can't be considered protection for the valuable data on your computer, or the e-commerce account you're currently signed in on. This stuff is for preventing Steven from making a funny Facebook post in your name (he'll find a way anyways). *roughly the same level of 'security' a "beware fluffy the furry menace" sign on your garden fence provides.
- dchest 5y agoFacial and fingerprint authentication is the most successful and practical security feature protecting billions of computers which would have been unprotected otherwise. It should not be dismissed like that, and I’m glad the work is being done to find and fix vulnerabilities.
- wonnage 5y agoI can think of many major security breaches related to poor or leaked passwords and honestly none come to mind with faked biometrics. Not to say that there aren't any, but passwords have a terrible security history and everyone should be glad that they're slowly becoming just another factor rather than the sole gatekeeper.
- SilverRed 5y agoThe problem is that Apple does facial recognition and does it in a semi secure way which builds trust in the technology. Then microsoft and samsung jam in the feature without any of the security considerations and ride off the trust Apple built in it. It's completely outrageous that MS thought it was acceptable to do facial recognition using a basic webcam.
- cwyptocuwency 5y agoOut of curiosity, why would showing a printed image of the user's face not have worked as well? Or, say, playing a video of the user's face from another device in front of the webcam? Does the biometric software look for glint or other characteristics of a replicating medium?
- code_duck 5y agoFrom what I read the infrared version was defeated because it accepted a static image while the other requires video. It sounds to me like either one could be fooled by an appropriate video?
- andrewmcwatters 5y agoInteresting. I thought Windows Hello was implemented with dot matrix hardware like on iPhone, but clearly it isn't. It's illuminated infrared camera tech.
- mrjin 5y agoThe problem is really how can we be sure that a device claimed to be a camera is really a camera and can be trusted? But yeah, as the device is already physically compromised, there is not much can be done in OS' perspective.
- user-the-name 5y agoA "physically compromised" iPhone will still not let you in, no matter what devices you plug into it, including removing the camera module and replacing it.
- djrogers 5y agoI think this comment is being downvoted unfairly - yes, there are mechanisms to get into an iPhone with physical access (see greykey) - but those rely on leveraging a vulnerability to allow brute forcing the PIN, they do not break FaceID.
- rasz 5y agohttps://appleinsider.com/articles/17/11/28/apples-face-id-with-attention-detection-fooled-by-200-mask https://appleinsider.com/articles/17/11/28/apples-face-id-wi... https://www.macrumors.com/2019/08/08/face-id-bypassed-glasses-tape/ https://www.macrumors.com/2019/08/08/face-id-bypassed-glasse...
- cpuguy83 5y agoAll I know is my 6 year old daughter was able to login to my admin account because of Windows Hello on multiple occasions. There is certainly some resemblance, particularly what I looked like when I was 6, but not a huge one.