Windows Hello, a new facial recognition security feature in Windows 10, has been defeated using a printed image. ZDNet reports that security researchers from German firm SYSS have managed to trick Windows Hello on Windows 10 machines running older versions of the operating system. Multiple versions of Windows 10 are affected, as well as a range of different hardware.
SYSS tested Microsoft, running last year's Windows 10 Anniversary Update, and found it vulnerable. Even Microsoft's Windows Hello anti-spoofing feature didn't help protect systems running older versions of Windows 10. SYSS found that if anti-spoofing is disabled in the Creators Update (released earlier this year) or in October's Fall Creators Update, then Windows Hello can be bypassed. Many modern laptops don't support Windows Hello anti-spoofing, so devices are still vulnerable even with the latest Windows updates.
Even applying the latest Windows 10 Fall Creators Update, which fixes the bug if anti-spoofing is enabled, may not be enough to prevent an attack. Windows 10 users who previously installed Windows Hello on an older version of Windows 10 (like the Anniversary Update last year) will still be vulnerable. Security researchers recommend that Windows 10 users who have Windows Hello enabled go back to settings and reconfigure facial recognition, and also ensure that anti-spoofing is enabled if a device supports it.
This type of attack, of course, requires a printed image of the authenticated user with an infrared camera, so it's not easy to pull off successfully. We've seen similar spoofing attacks for Samsung's Galaxy S8 face scanner, which required much less sophisticated images.
This makes it clear that some devices do not support the Windows Hello anti-spoofing feature.
