Windows 10 WARNING - PCs vulnerable to hack after shock security risk discovered

WINDOWS 10 users have been put on alert after a shock new security risk was discovered.

Windows 10MICROSOFT • LENOVO

Windows 10 users have been warned by experts about a new security risk

users have been warned about a new security risk which could open PCs up to an attack.

Microsoft’s flagship operating system can be hacked into via the Windows Hello facial authentication system, cybersecurity experts have warned.

Windows Hello lets users unlock their device simply with their face or with a fingerprint.

But security researchers from German firm SYSS managed to defeat the face scanning feature with a printed picture.

The cybersecurity experts were able to defeat Windows Hello on Windows 10 systems that have not yet received the Fall Creators Update.

SYSS said on these systems a ”simple spoofing attack using a modified printed photo of an authorised person" can crack open Windows Hello.

The researchers claim this attack works against multiple versions of Windows 10 and on different hardware, ZDNet reported.

SYSS tested the spoofing attack against a Dell Latitude with an LilBit USB camera and against a Microsoft Surface Pro 4.

These devices were running various versions of Windows 10, including one of the first releases, version 1511.

The researchers said the attack was also successful on version 1607, which is the Anniversary Update that was rolled out during summer 2016.

The attack was successful on this version even when Microsoft’s enhanced anti-spoofing was enabled.

However, the attack only worked on the two Creators Update released this year when anti-spoofing was disabled.

These updates fixed the exploit, however security researchers said users may still be vulnerable if Windows Hello was set up on an older version of Windows 10.

If that’s the case, then SYSS said Windows 10 users with Windows Hello enabled would have to go into the settings and set it up all over again.

To carry out the spoofing exploit, an attacker would need a printed picture of the authenticated user that was taken with an infrared camera.

In a post on Full Disclosure, SYSS wrote: "According to our test results, the newer Windows 10 branches 1703 and 1709 are not vulnerable to the described spoofing attack by using a paper printout if the ‘enhanced anti-spoofing’ feature is used with respective compatible hardware.

"Thus, concerning the use of Windows Hello face authentication, SYSS recommend updating the Windows 10 operating system to the latest revision of branch 1709, enabling the ‘enhanced anti-spoofing’ feature, and reconfiguring Windows Hello face authentication afterwards."

The news comes after Windows 10 users were put on alert after a security flaw was discovered that could see your passwords stolen by cyber criminals.

The warning revolves around a password manager that recently has been bundled in with some versions of Microsoft’s flagship OS.

Google Project Zero researcher Tavis Ormandy discovered the security risk after installing Windows 10 using a fresh image from Microsoft.

He found that, as a result of the fresh Windows 10 install, Keeper Password Manager was pre-installed on his PC.

Windows 10MICROSOFT

Even if you update to the Windows 10 Fall Creators Update you could still be exposed

When he tested the app, he found a browser plugin the app prompted him to enable resulted in the terrifying bug.

In a blog post he said the security flaw represented "a complete compromise of Keeper security, allowing any website to steal any password."

Ormandy installed Windows 10 using an image from Microsoft Developer Network (MSDN), meaning that it is meant for developers.

However, Reddit users also claimed to have received the vulnerable copy of Keeper after clean reinstalls and even on a brand new laptop.

Speaking to Ars Technica, a Microsoft spokesperson said: "We are aware of the report about this third-party app, and the developer is providing updates to protect customers.”

The developers of Keeper Password Manager fixed the flaw 24 hours after Ormandy privately reported the issue to them.

The security flaw was addressed in version 11.4 which removed the vulnerable "add to existing" functionality. 

Windows 10 users wouldn’t have been vulnerable unless they had opened Keeper, entered their passwords and followed the promote to install the browser plugin.

Windows 10 WARNING - PCs vulnerable to hack after shock security risk discovered

WINDOWS 10 users have been put on alert after a shock new security risk was discovered.

Windows 10MICROSOFT • LENOVO

Windows 10 users have been warned by experts about a new security risk

users have been warned about a new security risk which could open PCs up to an attack.

Microsoft’s flagship operating system can be hacked into via the Windows Hello facial authentication system, cybersecurity experts have warned.

Windows Hello lets users unlock their device simply with their face or with a fingerprint.

But security researchers from German firm SYSS managed to defeat the face scanning feature with a printed picture.

The cybersecurity experts were able to defeat Windows Hello on Windows 10 systems that have not yet received the Fall Creators Update.

SYSS said on these systems a ”simple spoofing attack using a modified printed photo of an authorised person" can crack open Windows Hello.

The researchers claim this attack works against multiple versions of Windows 10 and on different hardware, ZDNet reported.

SYSS tested the spoofing attack against a Dell Latitude with an LilBit USB camera and against a Microsoft Surface Pro 4.

These devices were running various versions of Windows 10, including one of the first releases, version 1511.

The researchers said the attack was also successful on version 1607, which is the Anniversary Update that was rolled out during summer 2016.

The attack was successful on this version even when Microsoft’s enhanced anti-spoofing was enabled.

However, the attack only worked on the two Creators Update released this year when anti-spoofing was disabled.

These updates fixed the exploit, however security researchers said users may still be vulnerable if Windows Hello was set up on an older version of Windows 10.

If that’s the case, then SYSS said Windows 10 users with Windows Hello enabled would have to go into the settings and set it up all over again.

To carry out the spoofing exploit, an attacker would need a printed picture of the authenticated user that was taken with an infrared camera.

In a post on Full Disclosure, SYSS wrote: "According to our test results, the newer Windows 10 branches 1703 and 1709 are not vulnerable to the described spoofing attack by using a paper printout if the ‘enhanced anti-spoofing’ feature is used with respective compatible hardware.

"Thus, concerning the use of Windows Hello face authentication, SYSS recommend updating the Windows 10 operating system to the latest revision of branch 1709, enabling the ‘enhanced anti-spoofing’ feature, and reconfiguring Windows Hello face authentication afterwards."

The news comes after Windows 10 users were put on alert after a security flaw was discovered that could see your passwords stolen by cyber criminals.

The warning revolves around a password manager that recently has been bundled in with some versions of Microsoft’s flagship OS.

Google Project Zero researcher Tavis Ormandy discovered the security risk after installing Windows 10 using a fresh image from Microsoft.

He found that, as a result of the fresh Windows 10 install, Keeper Password Manager was pre-installed on his PC.

Windows 10MICROSOFT

Even if you update to the Windows 10 Fall Creators Update you could still be exposed

When he tested the app, he found a browser plugin the app prompted him to enable resulted in the terrifying bug.

In a blog post he said the security flaw represented "a complete compromise of Keeper security, allowing any website to steal any password."

Ormandy installed Windows 10 using an image from Microsoft Developer Network (MSDN), meaning that it is meant for developers.

However, Reddit users also claimed to have received the vulnerable copy of Keeper after clean reinstalls and even on a brand new laptop.

Speaking to Ars Technica, a Microsoft spokesperson said: "We are aware of the report about this third-party app, and the developer is providing updates to protect customers.”

The developers of Keeper Password Manager fixed the flaw 24 hours after Ormandy privately reported the issue to them.

The security flaw was addressed in version 11.4 which removed the vulnerable "add to existing" functionality. 

Windows 10 users wouldn’t have been vulnerable unless they had opened Keeper, entered their passwords and followed the promote to install the browser plugin.

Windows 10 WARNING - PCs vulnerable to hack after shock security risk discovered

WINDOWS 10 users have been put on alert after a shock new security risk was discovered.

Windows 10MICROSOFT • LENOVO

Windows 10 users have been warned by experts about a new security risk

users have been warned about a new security risk which could open PCs up to an attack.

Microsoft’s flagship operating system can be hacked into via the Windows Hello facial authentication system, cybersecurity experts have warned.

Windows Hello lets users unlock their device simply with their face or with a fingerprint.

But security researchers from German firm SYSS managed to defeat the face scanning feature with a printed picture.

The cybersecurity experts were able to defeat Windows Hello on Windows 10 systems that have not yet received the Fall Creators Update.

SYSS said on these systems a ”simple spoofing attack using a modified printed photo of an authorised person" can crack open Windows Hello.

The researchers claim this attack works against multiple versions of Windows 10 and on different hardware, ZDNet reported.

SYSS tested the spoofing attack against a Dell Latitude with an LilBit USB camera and against a Microsoft Surface Pro 4.

These devices were running various versions of Windows 10, including one of the first releases, version 1511.

The researchers said the attack was also successful on version 1607, which is the Anniversary Update that was rolled out during summer 2016.

The attack was successful on this version even when Microsoft’s enhanced anti-spoofing was enabled.

However, the attack only worked on the two Creators Update released this year when anti-spoofing was disabled.

These updates fixed the exploit, however security researchers said users may still be vulnerable if Windows Hello was set up on an older version of Windows 10.

If that’s the case, then SYSS said Windows 10 users with Windows Hello enabled would have to go into the settings and set it up all over again.

To carry out the spoofing exploit, an attacker would need a printed picture of the authenticated user that was taken with an infrared camera.

In a post on Full Disclosure, SYSS wrote: "According to our test results, the newer Windows 10 branches 1703 and 1709 are not vulnerable to the described spoofing attack by using a paper printout if the ‘enhanced anti-spoofing’ feature is used with respective compatible hardware.

"Thus, concerning the use of Windows Hello face authentication, SYSS recommend updating the Windows 10 operating system to the latest revision of branch 1709, enabling the ‘enhanced anti-spoofing’ feature, and reconfiguring Windows Hello face authentication afterwards."

The news comes after Windows 10 users were put on alert after a security flaw was discovered that could see your passwords stolen by cyber criminals.

The warning revolves around a password manager that recently has been bundled in with some versions of Microsoft’s flagship OS.

Google Project Zero researcher Tavis Ormandy discovered the security risk after installing Windows 10 using a fresh image from Microsoft.

He found that, as a result of the fresh Windows 10 install, Keeper Password Manager was pre-installed on his PC.

Windows 10MICROSOFT

Even if you update to the Windows 10 Fall Creators Update you could still be exposed

When he tested the app, he found a browser plugin the app prompted him to enable resulted in the terrifying bug.

In a blog post he said the security flaw represented "a complete compromise of Keeper security, allowing any website to steal any password."

Ormandy installed Windows 10 using an image from Microsoft Developer Network (MSDN), meaning that it is meant for developers.

However, Reddit users also claimed to have received the vulnerable copy of Keeper after clean reinstalls and even on a brand new laptop.

Speaking to Ars Technica, a Microsoft spokesperson said: "We are aware of the report about this third-party app, and the developer is providing updates to protect customers.”

The developers of Keeper Password Manager fixed the flaw 24 hours after Ormandy privately reported the issue to them.

The security flaw was addressed in version 11.4 which removed the vulnerable "add to existing" functionality. 

Windows 10 users wouldn’t have been vulnerable unless they had opened Keeper, entered their passwords and followed the promote to install the browser plugin.

Windows 10 WARNING - Password manager has HUGE security hole
Google Chrome REMOVED from Windows 10 Store, and this is why Windows 10
George Michael death partner Fadi Fawaz Instagram tribute anniversary

George Michael’s partner Fadi Fawaz pays moving tribute on first anniversary of his death

Prince Harry Meghan Markle Queen Christmas gift present royal family

Prince Harry’s most shocking present for Queen REVEALED as Meghan Markle joins festivities

sandringham harry sky news meghan markle royal Christmas

Wedding fever hits Sandringham: Moment royal fan pops questions while waiting for Meghan

Gogglebox Leon dead wife June Twitter cast final scenes Channel 4

Gogglebox: Leon’s wife June speaks out after his heartbreaking final scenes air

meghan markle prince harry pictures news latest christmas sandringham

Meghan Markle wears sleek camel coat as she walks to Sandringham church with Prince Harry

Galaxy S9 release date Samsung dual camera fingerprint

Galaxy S9 release - Samsung may have just revealed two big new features

Install Kodi Amazon Fire TV Stick online streaming player app not available

Install Kodi on Amazon Fire TV Stick? The REAL reason popular player is NOT available

Netflix codes best Christmas movies films Bright Love Actually Die Hard

Netflix codes - How to watch the BEST Christmas movies this year for all the family

WhatsApp Block UK Ban Smartphone 2017

WhatsApp will STOP working on these phones THIS WEEK, are YOU affected?

Apple Slow Down Old iPhone iOS Planned Obsolescence

Apple admits it slows down YOUR older iPhones

WhatsApp Block Stop Sharing Facebook Data UK

WhatsApp BLOCK: Facebook-owned chat app ordered to STOP sharing your data

Kodi add ons movie TV streams security warning online piracy

Kodi WARNING - Security risk alert after popular add-on makes SHOCK claim

Pirate Bay torrent download movies Google Chrome ad blocker

End of Pirate Bay? Torrent sites left fearing 2018 will ‘kill’ off online piracy

Surface Phone Photos Microsoft Folding Phone

Surface Phone: Even MORE images of Microsoft FOLDING phone appear online

Fitbit Ionic review price deal Apple Watch fitness tracker

Fitbit Ionic review - Is this new smartwatch really an Apple Watch beater?

Samsung Galaxy S8 Android Oreo update release date

Galaxy S8 Android Oreo 8 update delay? Samsung has revealed some shock news

Find Secret Facebook Inbox On iPhone How To

How to find the secret Facebook inbox on your iPhone

Netflix Account Share Rules Number Of People

If you use someone else’s Netflix account, you NEED to read this

Norad Santa Tracker How To follow Father Christmas Journey Online Phone

Norad Santa Tracker - How to follow Father Christmas' journey online and on smartphones

Google Santa Tracker Follow Progress LIVE Online App

Google Santa Tracker - Best app for following Santa LIVE this Christmas Eve

Facebook Warning Christmas Not To Share

Facebook WARNING: Whatever you do, do NOT share these 5 posts over the Christmas holidays

Torrent Site Pirate Bay KAT Movies Online

Torrent SHOCK as students PAID to pirate movies so YOU can watch for free

Google Chrome Remove Delete Block Windows 10

Google Chrome REMOVED from Windows 10 Store, and this is why

Samsung Galaxy S9 vs Galaxy S8 Release Date UK

Samsung Galaxy S9 will have one MASSIVE advantage over the Galaxy S8, leak hints

Argos Amazon Currys best deals christmas sonos nintendo switch macbook

Argos, Amazon and Currys deals - Best Christmas sales and biggest offers REVEALED

  • Find us on Facebook
  • Follow us on Twitter
  • Check us on Google+
  • Subscribe to our rss feed