Windows Hello: Several publications report that Windows 10's facial recognition feature is one of the most secure out there.
But it turns out that Windows Hello can be fooled with a simple photo, just like Apple's Face ID.
The vulnerability was announced by German security firm Syss in Full Disclosure.
According to the researchers, even if you have installed all the latest updates for builds 1703 or 1709, facial recognition will need to be configured from the beginning to be resistant to the attack.
The “simple spoofing attacks” described in the researchers’ announcement are all variations using a “modified photo of an authorized user.” So with a simple photo an attacker can break into a locked Windows 10 system.
The default Windows Hello configuration has “enhanced anti-spoofing” enabled, Syss reports.
"If the 'enhanced anti-spoofing' feature is enabled, depending on the version of Windows 10, a slightly different modified photo should be used, but for an attacker the effort is negligible.".
The researchers tested the attack on a Dell Latitude running Windows 10 Pro (build 1703), as well as a Microsoft Surface Pro 4 running Windows build 1607.
The researchers tried changing the Surface Pro's setting to "enhanced anti-spoofing," but they claim that the "LilBit USB IR camera only supports the default setting and cannot be used with more secure facial recognition settings.".
The researchers released the following three videos as PoC:
