Microsoft defends Windows Hello security despite flaws being found

Microsoft has been forced to defend its Windows Hello software following the publication of a worrying security vulnerability that allows people to trick your webcam into unlocking your Windows 10 PC using little more than a printed photo.

As we reported when the news broke last week, PCs running versions of Windows 10 older than the recently-released Fall Creators Update and that use Windows Hello to unlock the machine using a webcam, can be easily caught out by a simple laser-printed photon taken with a near IR (infrared) camera.

Since then, Microsoft appears to have gone on the defensive, and has published a blog post that extols the virtues of using Windows Hello, rather than a password, to unlock your PC.

Hello, is it me you’re looking for?

Microsoft’s blog post quotes Bret Arsenault, Microsoft’s corporate vice president and chief information security officer as saying “[the password] model needs a makeover. Securing devices is important, but it’s not enough. We should also be focused on securing individuals. We can enhance your experience and security by letting you become the password.”

The blog post also goes into detail about the technology used by Windows Hello, with Rob Lefferts, director of program management for Windows Enterprise and Security, explaining that “It’s actually building a 3D map of your face. It has depth and characteristics, and we use multi-spectrum analysis so we’re getting multiple images of your face from different perspectives.”

If this isn’t enough to convince you that Windows Hello is secure, remember that the security issue from last week involved older versions of Windows 10 , so if your operating system is updated, and Windows Hello properly set up, your device should be more secure.

It’s also worth reading the whole blog, as it goes into a lot of depth about the security technology behind Windows 10.

However, on Microsoft’s behalf, it needs to do a lot more to ensure that embarrassing security lapses don’t happen again, especially as it claims that around 70% of Windows 10 users with biometric-enabled features (such as fingerprint readers or specialised webcams), use Windows Hello rather than normal passwords.

With that number of people relying on Windows Hello to secure their devices, it is imperative that Microsoft makes the technology as secure as possible – and no amount of defensive blog posts will make up for that.

Matt Hanson
Managing Editor, Core Tech

Matt is TechRadar's Managing Editor for Core Tech, looking after computing and mobile technology. Having written for a number of publications such as PC Plus, PC Format, T3 and Linux Format, there's no aspect of technology that Matt isn't passionate about, especially computing and PC gaming. He’s personally reviewed and used most of the laptops in our best laptops guide - and since joining TechRadar in 2014, he's reviewed over 250 laptops and computing accessories personally.

Latest in Computing Security
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Latest in News
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics