6 ms·
Windows Hello – Biometric authentication to Windows 10 devices
- tdicola 12y agoI'd love to understand more about how the face recognition works. Does it have any way to combat someone just printing out a picture of your face and holding it up? I've done some simple face recognition stuff with OpenCV and it's super easy to fool with photos.
- freehunter 12y agoFor facial or iris detection, Windows Hello uses a combination of special hardware and software to accurately verify it is you – not a picture of you or someone trying to impersonate you. The cameras use infrared technology to identify your face or iris and can recognize you in a variety of lighting conditions.
- tdicola 12y agoAh, so reading between the lines I'm going to guess they're building Win 10 devices with a built in kinect-like device that does depth sensing in addition to photo recognition.
- TeMPOraL 12y agoTime to start 3D-printing faces...
- Raphmedia 12y agoI'm sure it could be done with paper folding.
- TeMPOraL 12y agoCome to think of it... print a cylindrical projection of the photo and then wrap around a cylinder...
- deleted 12y ago[deleted]
- Groxx 12y agoAnd then point a projector at it to warm up the paper at the right places. I really wish biometrics would quit claiming to be significant improvements over anything but writing your password on a post-it on the computer. They all fall very quickly.
- Someone1234 12y agoYou could, but it is an IR camera, so you better have the IR characteristics of your 3D face match also. If you combine IR and visible light photography you actually get a layered face-scan which is VERY hard to fake (not impossible, hard). e.g. http://produceconsumerobot.com/biosensing/content/Face%20fever.jpg http://produceconsumerobot.com/biosensing/content/Face%20fev...
- higherpurpose 12y agoWhat if you just hack the webcam firmware - like celebrity hackers and FBI have done for years already?
- MichaelGG 12y agoIf you can modify firmware, you've probably already won. Unless the auth is done remotely and requires remote attestation, perhaps.
- vmarsy 12y agoWindows Hello uses a combination of special hardware and software to accurately verify it is you – not a picture of you or someone trying to impersonate you. The cameras use infrared technology to identify your face or iris and can recognize you in a variety of lighting conditions. and later in the webpage: all OEM systems incorporating the Intel® RealSense™ 3D Camera (F200) will support the facial and iris unlock features of Windows Hello So by reading this we can assume it does more than 2D recognitions since this is a "3D Camera"
- higherpurpose 12y ago3D models have been created out of 2D images before. I'm not saying this will be hackable from day one, but it will probably take a few short years for a well sponsored and motivated attacker. Hopefully the technology will also keep up and within a year or two we'll see updated versions that make it even harder to replicate. However, if I were to pick, I'd go for fingerprint recognition instead. Images of people's faces are everywhere online. It's much less likely to have a good photo of your fingerprints.
- rpedroso 12y agoThis is an important point. I wonder if they're going to have hardware standards for the fingerprint readers. Low-quality finger print readers can be spoofed with prints lifted from everyday sources.
- stevecalifornia 12y agoIn the article it says it uses infrared.
- megaman821 12y agoThe video actually shows a person attempting this, and it did not unlock the computer.
- rplnt 12y agoIt did..? I think.
- ehaughee 12y agoIt was an odd way to demo the tech as it was really quick. But what happens in the video is that the user holds a picture up in front of his face and nothing happens. Then he removes the picture to show his face and is immediately logged in. It seemed to happen much quicker than the other examples of unlocking, in the same video, that I assumed it was a video example of how the tech would work and not necessarily a real life demo. Obviously I could be wrong though.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- maaaats 12y agoI hope this will make laptop vendors and others include IR capabilities in their devices, and that those are usable outside Windows Hello. Would be cool to see what other uses people could come up with, for this "baby-kinect".
- andrewfong 12y agoI hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the whole device-based authentication piece seems useful. A Windows 10 computer is now one factor in a 2FA scheme and the OS (and at least one of its browsers) gets to be directly integrated into Microsoft's SSO scheme.
- jotm 12y agoOr if your device manufacturer decides it's time to store that data on their cloud and forces you to use their proprietary security tools. Good times.
- CaveTech 12y agoYou don't need to only worry about your device being compromised, your biometric credentials are being leaked by your mere existence. Before long, I can imagine someone being able to build facial models capable of fooling recognition systems using only a few source images. Your finger prints are everywhere. Iris would be a bit harder, for now, but potentially possible with an image of high enough resolution.
- thomasz 12y agoFingerprint and iris scanners have been compromised with nothing more than a high resolution image https://www.youtube.com/watch?v=vVivA0eoNGM https://www.youtube.com/watch?v=vVivA0eoNGM
- spyder 12y agoYes, and the next step would be kinect-like 3D scanning and "video magnification" for pulse detection ( http://people.csail.mit.edu/mrub/vidmag/ http://people.csail.mit.edu/mrub/vidmag/ ), but these too could be compromised with some effort. That's why these should be used only as a replacement for usernames and not for passwords.
- pqomdv 12y agoThey claim physical access for "hacking" is required, but that is not true. As long as you have a root access on a device you can do anything from anywhere. I don't see how this replaces or improves passwords from this perspective. Yes it is easier for the user, since they don't have to remember the password, but everything else stays the same.
- cwyers 12y ago> As long as you have a root access on a device you can do anything from anywhere. As Raymond Chen likes to say, "it rather involved being on the other side of this airtight hatchway." Once you have root, yes, you have compromised the machine.
- LoSboccacc 12y agoBut if it is a biometric password then you compromised all machines of a user.
- realo 12y agoConvenient, for sure. However, I always have the choice of not giving up my passwords, under (even painful) threat. Also, someone cannot get my passwords if I am dead. Ever. Unfortunately, with biometrics, it is quite easy to force me to put my face/finger/iris in front of the machine and unlock it. Even if I am (freshly) dead. Not that cool, really.
- s3r3nity 12y agoWow - I guess any apps I build have to satisfy the "If I'm tortured" use case.
- realo 12y agoSomething you have. Something you are. Something you know. You actually really need the three of them. The last one prevents the <Torture to death> scenario.
- andrewfong 12y agoThe last one really just prevents the (immediate) death scenario. The something you know could presumably be why they're torturing you in the first place, caveats about the effectiveness of torture notwithstanding.
- akerl_ 12y agoReal talk: I feel like the demographic of people who read and comment on HN is primarily people for whom "painful threat" is purely theoretical. Downstream folks are talking about preventing information leak if the adversary is literally willing to kill you via torture. In the real world, torture is a fairly effective way to make somebody divulge information, especially in the case where it can be readily checked (by trying the password they divulge). It's a fairly well proven fact that living beings will do pretty much anything to make the pain stop. For recent reference, this HN article, where he repeatedly complied with demands, even including lying about being tortured, in the hope that it would make the torture stop: https://news.ycombinator.com/item?id=9213753 https://news.ycombinator.com/item?id=9213753
- lawnchair_larry 12y agoI don't think I'm comfortable with this.
- feld 12y agoThis was demoed to my employer when Microsoft came through a month ago. I was not impressed -- biometrics are a username, not a password. edit: the article does not cover using your voice. I'm 99% sure they demoed to us the ability to use a custom phrase to authenticate with your voice as well.
- Someone1234 12y ago> biometrics are a username, not a password. Can you clarify what you mean by that. People like to parrot it, but few if any will explain why they feel that way. If you simply mean that you don't find it secure enough, wouldn't that really depend on the use-case? For example, what may not be secure enough to log into a DC, may be secure enough to let the secretary log into their computer which just has access to address books and calendars. It is all relative. Some biometric systems are fairly secure, like fingerprints. The cost and skill required to extract and reproduce a fingerprint so it is scannable make it a non-trivial affair. While the security services and a dedicated adversary could, for 80%+ of normal computer users it is a non-threat. Android's face unlock may have been trivially beaten but it reads like Microsoft are using multi-level photography (i.e. both IR for under-the-skin and visible light for on-the-skin) to extract a layered model of a person's face and head which could (maybe) prove harder to bypass with just a photograph.
- neohaven 12y agoBiometrics is identification, not authentication. It identifies who you are talking to, which is not the same as confirming who you are talking to (verifying authenticity of identity.)
- mynameisvlad 12y agoAn iris scan does not identify who you are talking to. A fingerprint scan does not either. These are unique to an individual, if they were the person who set them up, then it is, in 99% of cases, a unique element to a person that can be used to authenticate them. That's a whole of a lot better than a password, which can be shared by multiple people.
- higherpurpose 12y agoThey say the passwords or biometric data will be kept in hardware - what does that mean exactly? Is it the TPM? TPM 1.2? 2.0?
- ronald_dregan 12y agobiometric passwords are /never/ a good idea. it baffles me why people even bother.
- xena 12y agoThe only insecure part about passwords is the human element.
- pqomdv 12y agoWhat about password website leaks? Surely that is not my fault. Technically that is also the human element but I think you are talking specifically about users.
- itsbits 12y ago3d camera!!..next what? Kinect inside may phone/laptop..wow..!!
- jagermo 12y agoIt would be interesting if Cortana would get speaker recognition on top of speech recognition. Plus, she could ask you a question based on something (maybe whom you met for lunch a few days ago)to counter recorded voice attacks.
- sebleblanc 12y agoGreat! Now the FBI does not even have to arrest me to get my fingerprints and retina scanned!
- therobot24 12y agocome on, no one uses retina anymore
- jongalloway2 12y agoThe video says it never stores image on the device: https://youtu.be/1AsoSnOmhvU?t=3m12s https://youtu.be/1AsoSnOmhvU?t=3m12s I'd assume it's doing the equivalent of password hashing, so the authentication mechanism just verifies a hash match.
- therobot24 12y agoAs someone who actively researches biometric authentication, when I hear/read someone saying that biometrics are "usernames" and not "passwords", I automatically think they fundamentally misunderstand what a biometric is. A biometric is both a 'username' and a 'password' - for instance, when you access your computer/device/whatnot you type in your username and your password to identify to the system that you are requesting access (on mobile the account is implied). When using a biometric, the system will have a stored template (similar to a password) that it associates to the system user account, and in ideal situations you (the user) do not need to do anything other than be present to access the system resources. It's a difference between identification and verification. Do you go to your friends each time they ask you something and say "are you so and so?", or have you already identified who they are? Based on the video it seems that MS is starting to understand this difference. Check out the video at ~2:35. He sits down at the login screen, and it just opens the desktop. For consumer applications this is really the goal of any biometric system. Now spoofing and biometric template data being stolen are still real problems. Unfortunately, spoofing is not a very hot topic in the biometric field (usually conferences only have a relatively small percentage of papers on the subject), but given more consumer applications I'm hoping more funding will start to head that way. Concerning biometric template data, no you can't change it in it's most raw format, your fingerprint is static..that's what so great about it. However, there are methods such as key-binding where the template is itself encrypted with a private key. This however leads to more passwords... In any case, it's unfortunately up to companies like MS to start paving the way to successful implementations - if the data breaches we hear about almost monthly (Uber, Target, etc) are any indication, your password is just as at risk as your fingerprint.
- hurin 12y ago> if the data breaches we hear about almost monthly (Uber, Target, etc) are any indication, your password is just as at risk as your fingerprint. Two things - let's assume these companies follow best practices and both the fingerprints, biometric details and passwords are all hashed. Still: a) Unlike a password your biometric data is publicly obtainable. b) You cannot change your biometric data after it's been compromised. > As someone who actively researches biometric authentication, If you are an expert in the field - I think you are doing people an active disservice by telling them the security is just as good. Finally I think typing passwords just isn't that hard - everyone is used to it by now. I maybe odd in this - but its hard for me to see the greater degree of convenience as a huge breakthrough (even without the security implications).
- hurin 12y agowith technology that is much safer than traditional passwords From what I understand this is simply not true - could someone with a security background weigh in if this statement has any basis (were they comparing to <first_name>-"1234" and "user"-"password")?
- sly010 12y agoI honestly think biometric is just eye-candy. The real interesting thing here is MS Passport. Passwords are only broken because for most intended purposes they act as a symmetric key that you happen to leave around everywhere and when it leaks, you have a problem. If we had a web standard for asymmetric key authentication, you just unlock your device and your device authenticates you. A leaked public key (created for a single service) is useless. And once you only need to unlock ONE device, you might as well remember that single password, because at that point it is way more secure than a fingerprint. Of course devices break and get stolen, so you need to back up your keychain, and I bet that is exactly what MS Passport does for you, which is why it will never be adapted by other vendors.
- narrator 12y agoBiometrics sound like the next frontier for milking licensing revenue. Pretty soon they will offer a discounted license for office, but only for one biometricly identified user. Multiple users, such as library users, will require the special license, even though they are all using the same computer.
- therobot24 12y agoNever thought of this...i hope not.
- Roritharr 12y agoGreat! While we're at it: Can i please use my Microsoft Account to Remote Desktop into any currently available Device that is registered to my account, without having to jump through the hoops of doing all the port and network configuration beforehand?
- nanna 12y agoOne thing I like about passwords is that they give me the choice to not unlock something, should I wish that, which isn't the case with biometrics. Say I'm a journalist who gets stopped at the border of a country and am asked to open up my computer. If I want to, I can refuse - and face the consequences but still, i can make that choice. With biometrics all they'd have to do is force my finger onto the scanner, or put the computer in front of me and scan my iris or face. That's a big downside. Also, after everything we know about Microsoft and and the security services, there's absolutely no way I'd give them my biometric data.
- linkregister 12y agoFollowed you and agreed up until the last paragraph. Can you elaborate?
- nanna 12y agoJust the usual post-Snowden concerns about MS... http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...
- linkregister 12y agoYeah it looks like it'd be vulnerable to an NSL or Prism req. Thanks for the link.
- MichaelGG 12y agoJust an FYI, but that was the least useful bit of the Snowden leaks and is more speculation and insinuation than anything. It's literally based on the reading of a PowerPoint slide. AFAIK, there's been no actual evidence of "direct access", whatever that's supposed to mean. An automatic subpoena-serving could easily be written down as " direct access " on a ppt to management. It's probably a good idea to not store critical data with any third parties, but I'd be far more worried about Google than MS.
- 12y ago