Two German researchers demonstrated at Black Hat that an attacker with local administrative access can inject a malicious biometric template into Windows Hello for Business and sign in as another user with nothing more than their own face — a practical, low-noise bypass that undermines one of...
admin privileges
biometric templates
biometricssecurity
credential theft
device authentication
edr monitoring
enhanced sign-in security
enterprise security
ess
faceplant
local admin rights
passwordless securitysecurity architecture
security by design
tpm
virtualization security
wbs
windows biometric service
windows hello for business
Windows Hello, Microsoft's biometric authentication system, has long been celebrated for its convenience and security, allowing users to sign in using facial recognition, fingerprints, or a PIN. Traditionally, the facial recognition component relied primarily on infrared (IR) sensors to create a...