{"id":223091,"date":"2022-12-22T13:03:00","date_gmt":"2022-12-22T10:03:00","guid":{"rendered":"https:\/\/geek.mediadoma.com\/?p=223091"},"modified":"2022-10-23T10:33:47","modified_gmt":"2022-10-23T07:33:47","slug":"teadlastel-onnestus-uehe-riistvara-abil-windows-hellost-moeoeda-minna","status":"publish","type":"post","link":"https:\/\/geek.mediadoma.com\/et\/teadlastel-onnestus-uehe-riistvara-abil-windows-hellost-moeoeda-minna\/","title":{"rendered":"Teadlastel \u00f5nnestus \u00fche riistvara abil Windows Hellost m\u00f6\u00f6da minna"},"content":{"rendered":"\n<p>Microsoft<\/p>\n<p>CyberArki <a href=\"https:\/\/www.cyberark.com\/resources\/threat-research-blog\/bypassing-windows-hello-without-masks-or-plastic-surgery\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">turvateadlastel<\/a> \u00f5nnestus Windows Hello n\u00e4otuvastusest m\u00f6\u00f6da minna, kasutades v\u00f5ltsveebikaamerat, mis pumpab infrapunaandmed arvutisse. Protsess selle \u00e4rakasutamise taga on suhteliselt lihtne, kuigi see ei valmista tavainimesele t\u00f5sist muret, kuna see n\u00f5uab James Bondi-laadset taktikat.<\/p>\n<p>Windows Hello kontrollib kasutajaid <a href=\"https:\/\/www.howtogeek.com\/708986\/what-is-windows-hello-sign-in-on-windows-10\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">IR-hetkt\u00f5mmise<\/a> abil, et n\u00e4ha nende n\u00e4o 3D-kaarti, mist\u00f5ttu ei saa te prinditud fotoga autentimiss\u00fcsteemi petta. Kuid saate siiski toita Windows Hello autentimiss\u00fcsteemile &quot;kehtivaid&quot; pilte USB-seadmest, kui see teeskleb infrapuna- ja RGB-anduritega kaamerat.<\/p>\n<p>CyberArki meeskond leidis, et Windows Hello vajab kasutaja kontrollimiseks \u00fchte IR- ja RGB-pilti. Niisiis laadisid nad oma USB-seadmesse Windowsi kasutaja n\u00e4o kehtiva infrapunan\u00e4idiku ja Paavo RGB-pildi. Lukustatud arvutiga \u00fchendatud USB-seade tungis edukalt l\u00e4bi Windows Hello.<\/p>\n<p>Ilmselt ei kontrolli Windows Hello, et IR-kujutised p\u00e4rinevad reaalajas voost, ega kontrolli mis tahes edastatud RGB-kujutise sisu (CyberArk \u00fctleb, et v\u00f5ltsimise v\u00e4ltimiseks on t\u00f5en\u00e4oliselt olemas RGB-n\u00f5ue). P\u00f5hjalikum s\u00fcsteem aeglustaks t\u00f5en\u00e4oliselt Windows Hello sisselogimisprotsessi, mis v\u00f5ib m\u00f5nede kasutajate jaoks eesm\u00e4rgi kaotada.<\/p>\n<p>CyberArki meeskond \u00fctleb, et h\u00e4kkerid pole seda \u00e4rakasutamist ilmselt kunagi kasutanud, mis on m\u00f5istlik. Selle lahendamiseks vajab h\u00e4kker f\u00fc\u00fcsilist juurdep\u00e4\u00e4su arvutile, milles t\u00f6\u00f6tab Windows Hello, ja selle kasutaja peaaegu IR-pilti. Nii et lisaks s\u00fclearvuti varastamisele v\u00f5i hoonesse hiilimisele peaks h\u00e4kker tegema teist suhteliselt l\u00fchikese vahemaa tagant infrapunafotosid.<\/p>\n<p>\u00dckski neist pole v\u00f5imatu ja see v\u00f5ib olla suhteliselt lihtne, kui olete t\u00f5sise t\u00f6\u00f6eetikaga h\u00e4kker, valitsuse palgal olev agent v\u00f5i rahulolematu t\u00f6\u00f6taja, kes \u00fcritab teie t\u00f6\u00f6andjat \u00fcle keerata. Kuid siin on veel palju v\u00e4ikseid takistusi. Turvalisusega t\u00f5siselt tegelevad kontorid peidavad n\u00e4iteks t\u00f6\u00f6laua USB-pordid puuride taha, et v\u00e4ltida n\u00e4iteks isiklikke r\u00fcnnakuid, ja teil v\u00f5ib olla probleeme kaitstud arvutis v\u00f5i v\u00f5rgus tundlikule juurdep\u00e4\u00e4suga isegi siis, kui te lukustuskuvast m\u00f6\u00f6da l\u00e4hete.<\/p>\n<p>Microsoft on selle \u00e4rakasutamise <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&#038;mid=24542&#038;u1=rg\/92439&#038;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fen-US%2Fvulnerability%2FCVE-2021-34466\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">tuvastanud<\/a> ja \u00fctleb, et 13. juulil avaldati plaaster (kuigi ettev\u00f5tetel v\u00f5ib selle paiga installimine veidi aega v\u00f5tta). Ettev\u00f5te juhib t\u00e4helepanu ka sellele, et Windows Hello t\u00e4iustatud sisselogimisturvet kasutavad ettev\u00f5tted on kaitstud mis tahes riistvara eest, mis pole nende s\u00fcsteemiadministraatorite poolt eelnevalt heaks kiidetud \u2013 muidugi juhul, kui ettev\u00f5tte kasutatavad riistvaraseadmed on ebaturvalised, on t\u00e4iustatud sisselogimine Turvalisus v\u00f5ib ohtu sattuda.<\/p>\n<p>CyberArk \u00fctleb, et ta tutvustab k\u00f5iki oma Windows Hello leide <a href=\"https:\/\/blackhat.com\/us-21\/briefings\/schedule\/index.html#bypassing-windows-hello-for-business-and-pleasure-22868\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Black Hat 2021<\/a> raames, mis toimub 4. ja 5. augustil.<\/p>\n<p>Allikas: <a href=\"https:\/\/www.cyberark.com\/resources\/threat-research-blog\/bypassing-windows-hello-without-masks-or-plastic-surgery\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">CyberArk<\/a> <a href=\"https:\/\/www.windowscentral.com\/researchers-bypass-windows-hello-you-probably-dont-have-worry\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Windows Centrali<\/a> kaudu<a href=\"https:\/\/www.windowscentral.com\/researchers-bypass-windows-hello-you-probably-dont-have-worry\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external\"><\/a><\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/www.reviewgeek.com\" class=\"external external_icon\">www.reviewgeek.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CyberArki turvateadlastel \u00f5nnestus Windows Hello n\u00e4otuvastusest m\u00f6\u00f6da minna, kasutades v\u00f5ltsveebikaamerat, mis pumpab infrapunaandmed arvutisse. Protsess selle \u00e4rakasutamise taga on suhteliselt lihtne, kuigi see ei valmista tavainimesele t\u00f5sist muret, kuna see n\u00f5uab James Bondi-laadset taktikat.<\/p>\n","protected":false},"author":1,"featured_media":157305,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[735,620,640,650,650,660,735,724,620,724],"tags":[],"class_list":{"0":"post-223091","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","6":"hentry","7":"category-mitmesugused","8":"category-rakendusi","9":"category-arvutid","10":"category-hobid","12":"category-tark-kodu","14":"category-uudis"},"_links":{"self":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/posts\/223091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/comments?post=223091"}],"version-history":[{"count":0,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/posts\/223091\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/media\/157305"}],"wp:attachment":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/media?parent=223091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/categories?post=223091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/tags?post=223091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}