kyu
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
misk@sopuli.xyz to Technology@lemmy.worldEnglish · 2 years ago

Microsoft’s Windows Hello fingerprint authentication has been bypassed

www.theverge.com

external-link
message-square
109
link
fedilink
  • cross-posted to:
  • technology@lemmy.ml
499
external-link

Microsoft’s Windows Hello fingerprint authentication has been bypassed

www.theverge.com

misk@sopuli.xyz to Technology@lemmy.worldEnglish · 2 years ago
message-square
109
link
fedilink
  • cross-posted to:
  • technology@lemmy.ml
Windows laptop manufacturers will likely need to fix this one.
  • stom@lemmy.world
    link
    fedilink
    English
    arrow-up
    463
    arrow-down
    10
    ·
    2 years ago

    This is why I use Linux, the fingerprint device wouldn’t be supported so this wouldn’t be an issue /s

    • Gork@lemm.ee
      link
      fedilink
      English
      arrow-up
      147
      arrow-down
      2
      ·
      2 years ago

      Mmm yes security by non-functionality. A pillar of the modern cybersecurity framework.

      • SpaceNoodle@lemmy.world
        link
        fedilink
        English
        arrow-up
        99
        arrow-down
        1
        ·
        2 years ago

        Can’t hack a brick 🤷

        • AbidanYre@lemmy.world
          link
          fedilink
          English
          arrow-up
          73
          arrow-down
          1
          ·
          2 years ago

          But you can use a brick to hack windows.

          • fmstrat@lemmy.nowsci.com
            link
            fedilink
            English
            arrow-up
            6
            ·
            2 years ago

            When you could have said crack, but instead said hack.

          • demonsword@lemmy.world
            link
            fedilink
            English
            arrow-up
            5
            ·
            2 years ago

            But you can use a brick to hack windows

            yes indeed, the good ol’ broken windows fallacy!

          • FourPacketsOfPeanuts@lemmy.world
            link
            fedilink
            English
            arrow-up
            6
            arrow-down
            1
            ·
            2 years ago

            Something something Soviet Russia…

        • agent_flounder@lemmy.world
          link
          fedilink
          English
          arrow-up
          17
          ·
          2 years ago

          And this is why I am typing this on a 1921 Royal No. 10 typewriter.

          • AbidanYre@lemmy.world
            link
            fedilink
            English
            arrow-up
            9
            ·
            2 years ago

            Found Tom Hanks’s Lemmy account.

      • Kusimulkku@lemm.ee
        link
        fedilink
        English
        arrow-up
        40
        ·
        2 years ago

        Works for my webcam. Tbh I’d like someone to hack it, would mean they would’ve written drivers for it

      • Zeth0s@lemmy.world
        link
        fedilink
        English
        arrow-up
        17
        ·
        2 years ago

        It is called zero trust, killing functionalities is zscaler core business

    • Cethin@lemmy.zip
      link
      fedilink
      English
      arrow-up
      28
      arrow-down
      2
      ·
      2 years ago

      The fun thing about Linux is your realize physical control is ownership. You can just throw a Bootable Linux image with some utilities and remove the password from a Windows account in a second. If you really need to keep something safe, it has to be encrypted.

      • kadu@lemmy.world
        link
        fedilink
        English
        arrow-up
        13
        ·
        2 years ago

        deleted by creator

        • jonne@infosec.pub
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          10
          ·
          2 years ago

          Regardless, you can just read what’s on the disk anyway, so you don’t need to be able to log in.

          • randombullet@feddit.de
            link
            fedilink
            English
            arrow-up
            5
            arrow-down
            10
            ·
            edit-2
            2 years ago

            Unless bitlocker is enabled by default, which is becoming more and more common unfortunately…

            • kadu@lemmy.world
              link
              fedilink
              English
              arrow-up
              21
              ·
              2 years ago

              deleted by creator

    • Hubi@feddit.de
      link
      fedilink
      English
      arrow-up
      25
      arrow-down
      3
      ·
      2 years ago

      The one on my Thinkpad works just fine :)

      • smoothbrain coldtakes@lemmy.ca
        link
        fedilink
        English
        arrow-up
        8
        ·
        edit-2
        2 years ago

        I got a T80s and the sensor doesn’t work. It’s an 8th gen Intel machine, that’s like four or five generations behind.

        • Hubi@feddit.de
          link
          fedilink
          English
          arrow-up
          6
          ·
          2 years ago

          I’ve got a T440p and I just set it up through the menu in the KDE settings, it worked right out of the box.

          • smoothbrain coldtakes@lemmy.ca
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            1
            ·
            edit-2
            2 years ago

            Mine’s not in libfprint, libfprint-tod, or libfprint-goodix. Running GNOME because I heard fprintd was easier to implement instead of KDE, which is usually my pref DE.

    • /home/pineapplelover@lemm.ee
      link
      fedilink
      English
      arrow-up
      24
      arrow-down
      2
      ·
      2 years ago

      Nah I use fprint on my arch laptop so there is fingerprint login technology. Hopefully that doesn’t have security vulnerabilities.

      • locuester@lemmy.zip
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        2 years ago

        It has vulnerabilities for sure. But they haven’t been found because no one cares about hacking you or the 1 other person on earth that use Arch and fingerprint security.

        • /home/pineapplelover@lemm.ee
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 years ago

          Security by obscurity lol

    • RFBurns@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      1
      ·
      2 years ago

      Correct answer.

      Using any form of biometric ‘login’ under the US’s “justice” system is supremely ill-advised.

    • loutr@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 years ago

      That’s funny, on my XPS Windows crashed when I tried adding a fingerprint. Works flawlessly under Arch.

    • PeWu@lemmy.ml
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 years ago

      Today I was fucking around with this shit. I can’t even update my distro, otherwise ecryptfs will go adios, and fingerprinting will be broken.

    • WindowsEnjoyer@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      2
      ·
      2 years ago

      wouldn’t be supported so this wouldn’t be an issue

      I did not expect that 😅

    • ultranaut@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      7
      ·
      2 years ago

      One of the major reasons I gave up on trying to run Linux on my laptop was lack of fingerprint reader support.

      • elbarto777@lemmy.world
        link
        fedilink
        English
        arrow-up
        18
        arrow-down
        2
        ·
        edit-2
        3 months ago

        deleted by creator

        • Treczoks@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          2 years ago

          So YES, from someone who was asked to do fingerprint authentication in a sensitive environment (and had to refuse, even to the salespeople pested me)

        • regbin_@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          You can choose not to use it even if Linux supports it.

          • elbarto777@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            3 months ago

            deleted by creator

            • regbin_@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 years ago

              Then I really don’t see how it’s a plus. Smaller kernel size? lol

              • elbarto777@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                3 months ago

                deleted by creator

        • robotica@lemmy.world
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          13
          ·
          2 years ago

          How is not having support for something a plus for you? I swear to god, some Linux users are so stuck up.

          • elbarto777@lemmy.world
            link
            fedilink
            English
            arrow-up
            15
            arrow-down
            5
            ·
            edit-2
            3 months ago

            deleted by creator

            • smort@lemmy.world
              link
              fedilink
              English
              arrow-up
              4
              arrow-down
              1
              ·
              2 years ago

              What TV did you get that doesn’t have smart features?

              I looked, but all the ones I could find were 1080p, no HDR, and either tiny or made for commercial/industrial installation.

              • elbarto777@lemmy.world
                link
                fedilink
                English
                arrow-up
                5
                ·
                edit-2
                3 months ago

                deleted by creator

          • wildginger@lemmy.myserv.one
            link
            fedilink
            English
            arrow-up
            4
            ·
            2 years ago

            “what, you dont want to use the new door lock made from soggy white bread? You deadbolt losers are so stuck up”

          • gohixo9650@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            6
            arrow-down
            3
            ·
            2 years ago

            fingerprint login is not secure. period. Being stuck in using a password login is a plus

            • Alex@feddit.ro
              link
              fedilink
              English
              arrow-up
              4
              arrow-down
              1
              ·
              2 years ago

              You could just disable fingerprint login, though.

              • elbarto777@lemmy.world
                link
                fedilink
                English
                arrow-up
                4
                arrow-down
                1
                ·
                edit-2
                3 months ago

                deleted by creator

    • ☂️-@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      3
      ·
      edit-2
      11 months ago

      deleted by creator

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3.12K users / day
  • 8.38K users / week
  • 15.4K users / month
  • 29.7K users / 6 months
  • 1 local subscriber
  • 83.9K subscribers
  • 18.4K Posts
  • 797K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org