Researchers at the German IT Security company SySS GmbH successfully fooled the Windows 10 facial recognition system by using a printed photo of the user's face.
Their spoofing efforts were published on This Isn't The Twilight Saga: New Moon: The XXX Parodythe cybersecurity site Seclists on Dec. 18. The cybersecurity experts bypassed Windows Hello -- which is Microsoft's password-free security software -- on both a Dell and Microsoft laptop running different versions of Windows 10, which is cause for concern for anyone using this feature to log into their account.
SEE ALSO: This nasty Android malware caused a phone to overload and bulgeDeceiving Windows 10 didn't take too much effort. It just required "having access to a suitable photo of an authorized person" to "easily" bypass the system, wrote the experts. The photo required is the full image of someone's face -- so if someone really wants to attempt to deceive the facial recognition system, the barriers aren't too great.
Similar to Apple's Face ID, it might be wise to view Windows Hello as a convenience feature, not a security feature.
Similar to the iPhone X's Face ID camera, Hello Windows uses an infrared camera (either built-in the or added separately) to recognize the unique shape and contours of a face before granting or denying access to a Windows account. But a flaw was found, specifically "an insecure implementation of the biometric face recognition in some Windows 10 versions."
They show their work below:
Many -- but not all -- Windows versions are vulnerable. In 2016, Microsoft included a new feature called Enhanced Anti-Spoofing to limit this sort of picture trickery. But even if this feature is enabled in your Windows settings, the researchers found a way to bypass the facial recognition system that ran older Windows versions, such as a Microsoft Surface Pro 4 device running 2016's Windows 10 Anniversary update, for instance.
However, the SySS researchers found that two new Windows versions, 1703 and 1709, are not vulnerable to their most simple spoofing attacks (using a printed photograph) if Enhanced Anti-Spoofing is enabled.
Their ultimate recommendation: Updating to Windows 10 version 1709, enabling anti-spoofing, and then having Windows Hello reanalyze your face.
If this sounds unappealing or risky, you can always go back to using a (not dumb) password. Infrared facial recognition in consumer applications is still relatively new, so flaws should be expected.
Similar to Apple's Face ID, it might help to view Windows Hello as a convenience feature, not a security feature.
Mashable has contacted Microsoft for comment and will update this story upon hearing back.
Topics Cybersecurity Windows
HGTV's 'Fixer Upper' is ending after five seasonsTwitter's new 280Watch these precious 'Jeopardy' contestants tank while trying to answer sports questionsTwitter is testing a 280The definitive guide to Travis Scott, the probable father of Kylie Jenner’s alleged babyTwitter can keep its extra characters, I want to edit tweetsThe Duffers insist we call it 'Stranger Things 2' like it's a movie sequelIf the iPhone X arrives late, blame 'Romeo and Juliet'Star Trek: Discovery is forcing me to make a galactic decision6 reasons Trump should stay away from longer tweetsStar Trek: Discovery is forcing me to make a galactic decisionAmazon's new Fire TV is tiny and HDRMarine biologist captures 'blue hole' in the Great Barrier ReefAmazon Echo Spot is coming for your alarm clockAmazon unveils Echo Plus, its first true smart home hubBBC presenter accidentally drops the cAmazon is showing off a lot of new AlexaTwitter is making some legitimately great video—and it's impossible to findThe BDSM underworld of the most disturbing 'World of Warcraft' sex dungeonThis video of Sean Hannity vaping on camera is mesmerizing Trump capping a pen with his tiny hands gets a huge Photoshop battle Aura readers' advice on how to pick your new iPhone color Trump is going to build that damn wall and all people can talk about is avocados The 'Downton Abbey' movie is the horniest PG The LGBTQ community is coming to march and werk on Washington CNBC's Trump tweet alert is a new level of absurd Google Pixel 4 takes photos of the stars in leaked video Teen shoots soda in her own face for pretty much no reason at all Twitter no longer recommends Trump's profile when you search 'asshole' New Google Maps tools aim to help combat opioid addiction White House official memo misspells British PM's name three times Apple's new iPhone 11 is already delivering memes Artificial intelligence could one day diagnose skin cancer from smartphones How Facebook will pick the news you see in its app Super talented dad transforms his sons' drawings into beautiful artwork The chaotic evil 'Don't have a bookmark?' meme is out of control The bill Uber and Lyft fought against passed, and it could shake up the gig economy Some evidence Trump is probably using to make his wild voter fraud case Adam Driver and Scarlett Johansson in 'Marriage Story': Review Apple’s new iPhone 11 is so pretty in person. About that bump, though…
2.7621s , 10132.8046875 kb
Copyright © 2025 Powered by 【This Isn't The Twilight Saga: New Moon: The XXX Parody】,Prosperous Times Information Network