Black Hat presenter finds Microsoft fingerprint reader insecure. Shocker!

03/03/2006
Black Hat presenter finds Microsoft fingerprint reader insecure. Shocker!

Listen "Black Hat presenter finds Microsoft fingerprint reader insecure. Shocker!"

Episode Synopsis

Microsoft sells a fingerprint reader designed to logs into web sites without remembering passwords. Despite this, Microsoft explicately states that the device should not be used to protect sensative information. Mikko Kiviharju, a finnish researcher, discovered that Microsoft chose turn off the encryption that is supported by the OEM, Digital Persona. What baffles the Black Hat team is the statement from Digital Persona's CTO - 'The fact that they turned the encryption off, I would argue, does not in a practical sense open up any security holes'. Then why include it as a feature?