Windows 10 Facial Recognition Feature Can Be Bypassed with a Photo (bleepingcomputer.com)
Windows Hello, the face scanning security feature in Windows 10, has been defeated with the use of a printed out picture. From a report: In a report published yesterday, German pen-testing company SySS GmbH says it discovered that Windows Hello is vulnerable to the simplest and most common attack against facial recognition biometrics software -- the doomsday scenario of using a printed photo of the device's owner. Researchers say that by using a laser color printout of a low-resolution (340x340 pixels) photo of the device owner's face, modified to the near IR spectrum, they were able to unlock several Windows devices where Windows Hello had been previously activated. The attack worked even if the "enhanced anti-spoofing" feature had been enabled in the Windows Hello settings panel, albeit for these attacks SySS researchers said they needed a photo of a higher resolution of 480x480 pixels (which in reality is still a low-resolution photo). [...] Microsoft released updates earlier this month to patch the vulnerability.
To start scratching real facial recognition
Sent as ripples into the electromagnetic field. No single photon has been harmed in the process.
What does "modified to the near infrared spectrum" mean?
My printer can't print "near infrared" or radio waves. It can't even print gamma rays.
Who comes up with such stupid ideas like using the camera and face detection as authentication method?
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
> spit into this tube to log into your computer
> you just know someone will try jack off into it
(oldie but goodie):
One day Bill complained to his friend that his elbow really hurt. His friend suggested that he go to a computer at the drug store that can diagnose anything quicker and cheaper than a doctor.
''Simply put in a sample of your urine and the computer will diagnose your problem and tell you what you can do about it. It only costs $10." Bill figured he had nothing to lose, so he filled a jar with a urine sample and went to the drug store. Finding the computer, he poured in the sample and deposited the $10. The computer started making some noise and various lights started flashing. After a brief pause out popped a small slip of paper on which was printed: "You have tennis elbow. Soak your arm in warm water. Avoid heavy lifting. It will be better in two weeks."
Later that evening while thinking how amazing this new technology was and how it would change medical science forever, he began to wonder if this machine could be fooled. He mixed together some tap water, a stool sample from his dog and urine samples from his wife and daughter. To top it off, he masturbated into the concoction. He went back to the drug store, located the machine, poured in the sample and deposited the $10. The computer again made the usual noise and printed out the following message:
"Your tap water is too hard. Get a water softener. Your dog has worms. Get him vitamins. Your daughter is using cocaine. Put her in a rehabilitation clinic. Your wife is pregnant with twin girls. They aren't yours. Get a lawyer. And if you don't stop jerking off, your tennis elbow will never get better."
Okay, it's not the first time simple ways have been found to circumvent so-called "biometrics" especially the poor man's version of these tools. The Windows 10 version is mostly likely a low end version with very limited pixel resolution recognition on the camera (to be compatible with the low end cameras that come in most laptops and cameras), plus an routine to distinguish a live face (with facial movements/ticks as supposed to a 100% static picture) was probably never even considered because it would add to cost and time to development. So when you think about it, it's really a TERRIBLE idea. even with that taken into account, a camera with a high enough resolution to recognize a video would add costs too.
We tried finger print recognition which is also terrible because it is too easy to lift a fingerprint from a victim (or even bypass the finger print scanner in many cases). Anything that is easy to lift/take from the user is inherently insecure: Finger prints (scotch tape/talcum powder will get that from any surface including keyboards and coffee cups), facial recognition (just lift a picture from facebook or any social media site where people often publish high resolution photos, even easier than getting a finger print). Voice print is a LITTLE better but voice patterns have been successfully simulated/recorded from everyday conversation or even YouTube lectures. (techies often love to give these).
There is absolutely NO substitute for a good old fashion typed passwords (even better, in combination with typing sampling for speed/patterns). Even voice passwords are potentially easy to copy with a long or even short range microphone The password is proven most secure because it requires you to look into someone's memory or stand over them and watch them type it, unless of course they use the same password across but that requires more time/research than getting a facial picture or even a fingerprint if you know or work with the victim. Perhaps these could be used IN ADDITION to a password, but should NEVER be a substitute. The key to secure is the remember this old axiom: Security comes at the price of convenience. Without exception. Of course common sense rules like password rotation on a regular basis are essential. It is possible to lift a password I imagine using the amount of body oil on each key or even thermal patterns on a keyboard to lift a password, but look at all the effort/equipment required to do that. It feels like every new biometric security toy is less secure than the last.
"Imagination is more important than knowledge" - Einstein
I remember the 1989 Game Space Quest III one of the final puzzles before the action sequences for the end game. Was to wonder the cubes of a software company, being a janitor, cleaning the garbage in each cube you walked by. Working your way to the CEO office taking his ID Card, and on the way back going to the photocopier taking his portrait and make a color copy of it. Using his ID Card and the portrait to gain access to the End Game area. As there was a super advance card reader with a face scanner on it.
There were two more puzzle actions, pushing a button to extend a bridge, and using your trash vaporizer to free some software developers from their lime gelatin imprisonment. But those were rather easy.
With this explanation it is easy to tell the game didn't take itself too seriously. And this spoof of a software company was a jab at Microsoft calling it Scumsoft. and the CEO being a kid CEO as Bill gates was considered at the time.
The Face ID Apple has while not perfect seems to have done it better then anyone else. Because they are a hardware company first, they took a hardware approach to the problem, by adding an IR dot projection of your face to aid in matching. Vs. Microsoft and Google who took a software approach using existing hardware try to get a match.
If something is so important that you feel the need to post it on the internet... It probably isn't that important.
I can deal with 3 year of Pence as president. While not my choice and I have political issues with him, at least he will work for the American public.
Ask all us Indianians about that...
Its good enough to use for targeted ads. Its good enough to use to guess who is in photos to suggest tags if you are into that.
Its not good enough to be secure. And on some level, it can't be. For logging in it should be used to pre-populate your user name... that's it. It shouldn't login based on that alone, it shouldn't give you full admin access to everything on your PC... that's idiotic.