funsec mailing list archives

Researcher Hacks Microsoft Fingerprint Reader


From: "Fergie" <fergdawg () netzero net>
Date: Tue, 7 Mar 2006 03:04:51 GMT

Via InfoWorld.

[snip]

Never mind worrying about hackers stealing your password. A security researcher with the Finnish military has shown how 
they could steal your fingerprint, by taking advantage of an omission in Microsoft's Fingerprint Reader, a PC 
authentication device that Microsoft has been shipping since September 2004.

Although the Fingerprint Reader can prevent unauthorized people from logging on to your PC, Microsoft has not promoted 
it as a security device, but rather as convenient tool for home users who want a fast way to log on to Web sites 
without having to remember user names and passwords. In fact, the Microsoft.com Web site warns that the Fingerprint 
Reader should not be used to protect sensitive data.

[snip]

More:
http://www.infoworld.com/article/06/03/06/76157_HNfingerhack_1.html

- ferg


--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg () netzero net or fergdawg () sbcglobal net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: