BSI publishes "Windows dissected" biometric analysis

A person uses a fingerprint scanner for secure entry in a business setting.

Germany's Federal Office for Information Security (BSI) has published a technical analysis from its "Windows dissected" project examining how Windows Hello for Business performs biometric identification. Independent security firm ERNW (Enno Rey Netzwerke) conducted the work using debugging and reverse-engineering techniques to reconstruct internal processes. The study analyzed Windows 10 Enterprise LTSC 2021, focusing on facial recognition within Windows Hello for Business, which allows employees to sign in using a PIN, face, or fingerprint and binds enterprise authentication to cryptographic keys protected by the Trusted Platform Module.

Vulnerabilities found when Enhanced Sign-in Security is disabled

The report identifies limits when biometric authentication operates without Enhanced Sign-in Security (ESS). According to the analysis, ESS changes the Windows Hello architecture by moving sensitive biometric operations away from the normal Windows environment, introducing an additional isolation boundary built around Virtualization-based Security, TPM 2.0, and compatible biometric hardware. Without ESS in place, the researchers observed that Windows Hello accepted a facial mask during enrollment and later treated a different mask depicting the same person as a valid authentication match — a scenario the report classifies as a presentation attack.

Enrollment quality affects authentication reliability

The researchers also examined the effect of degraded enrollment conditions. In one experiment, a person registered for facial recognition while wearing a scarf, glasses, and a hood; another individual wearing the same combination of accessories was then able to authenticate successfully. When the original user re-enrolled without reduced facial visibility, the researchers could no longer reproduce the incorrect acceptance. The observations indicate that the security of facial authentication can also be affected by the quality of the biometric sample accepted during enrollment.

Practical measures for enterprise deployments

The BSI report offers practical measures for reducing the risks that arise when biometric identification is used to authorize access to device-bound enterprise credentials. It concludes that protection depends on how the device is configured, which biometric hardware is installed, who is allowed to enroll, how local administrator access is controlled, and whether the biometric process is isolated through Enhanced Sign-in Security. Organizations relying on Windows Hello for Business will need to weigh these configuration factors against the technology's stated benefits in reducing exposure to password phishing and credential theft.

Share this article

FacebookX

2 sources

Sources