Questions tagged [windows-hello]

6 questions
7
votes
1 answer

What are the security risks of USB fingerprint scanners in Windows 10?

Hi I have a Lenovo laptop encrypted with Bitlocker, which I also use a fingerprint scanner with. Bear in mind I'm not working with super-secure information, more the level that a developer/manager for a business would have. What are the potential…
user1102550
  • 981
  • 1
  • 10
  • 15
4
votes
1 answer

How does Windows Hello recognize me with a mask on?

The first time I forgot to take my mask off before using the facial recognition login to my Windows 10 computer, it wouldn't work (which I expected). After a couple times, though, it started logging me in before I had a chance to take my mask off.…
Benjamin Hollon
  • 143
  • 1
  • 5
4
votes
2 answers

Lateral Movement: What is the benefit of Windows Hello For Business?

I work as a security researcher, tonight I implemented Windows Hello For Business in our environment, because it is marketed as the "passwordless way of the future" and I wanted to see if it holds up to its promises. The decision was made to go…
Robert R
  • 63
  • 6
4
votes
2 answers

How does Window Hello protect against brute forcing?

With my Windows 10 computer, I have the option to set up a PIN with Windows Hello (I believe it's with that program). My normal Outlook password is 15+ characters mixed with upper case and lower case and numbers and symbols, but my PIN is only a few…
Axel Munoz
  • 41
  • 2
1
vote
1 answer

Managing security of a desktop/mobile app

I'm working on an app that stores sensitive data (think of it as a password locker) for the UWP (Universal Windows Platform). The most important requirement is the ability to roam the data between user's devices, so that the user can add his…
StepTNT
  • 111
  • 2
-1
votes
2 answers

How exactly is a fingerprint stored in Windows Hello? Why is it claimed to be more secure than a password?

I can't quite imagine a scenario where fingerprints can be stored in a way that defeats the weaknesses of password storage (i.e. pass the hash attacks or password reuse). Moreover, I couldn't quite find a concise explanation of the way Windows Hello…
Hex_27
  • 9
  • 1