Understanding the Risks of Windows Hello: BSI Warns About Admin Rights Manipulation
The Federal Office for Information Security (BSI) has published a preliminary technical report as part of its extensive investigation project titled “Windows Dissected.” This report provides an in-depth look into the security architecture of Windows Hello for Business, the biometric authentication solution designed for enterprises. The BSI experts have identified specific attack scenarios that potentially undermine trust in biometric logins unless certain security measures are implemented.
Risks Associated with Local Administrator Rights
The BSI’s investigations indicate that the security of Windows Hello for Business significantly depends on the integrity of the local system. Findings suggest that attackers with local administrator rights on an endpoint can decrypt and manipulate biometric templates. This access to stored reference data for facial or fingerprint recognition allows unauthorized third parties to corrupt the authentication process.
By manipulating these templates, attackers can log in as another user. In such a threat scenario, the biometric component loses its validity as a reliable identity verification method, as the system mistakenly considers the manipulated input to be legitimate.
Best Practices to Secure Authentication
To address the identified vulnerabilities, the BSI has published a catalog of security measures and configuration recommendations. A central recommendation is the consistent use of the “Enhanced Sign-in Security” (ESS) feature. This mode adds an extra layer of protection for processing biometric data and makes it harder for manipulated processes to access the system level.
Key Recommendations Include:
User Registration: It is advisable to register only one person per device. This minimizes the risk of identity misuse or compromise within a shared hardware environment.
Alternative Login Methods: Utilizing a PIN is encouraged as a viable alternative to purely biometric logins. This approach reduces dependence on potentially manipulatable sensor data.
Hardware Security: A crucial component of security remains the use of hardware security modules. The BSI emphasizes the necessity of implementing a Trusted Platform Module (TPM) and combining it with full disk encryption.
The Rise of Modern Authentication Methods
As traditional passwords pose significant security risks, modern techniques like passkeys are becoming increasingly relevant alternatives to biometric logins. Understanding how to set up and protect these newer technologies in services such as Amazon or WhatsApp is essential for safeguarding against data theft.
Conclusion
The technical report offers IT managers in companies and government agencies a solid foundation for critically evaluating the implementation of Windows Hello for Business. It helps enhance the resilience of their infrastructure against local attackers. The “Windows Dissected” project will continue its efforts to analyze further core components of the operating system.
By following BSI’s recommendations and keeping abreast of emerging technologies, organizations can better protect themselves from the vulnerabilities associated with biometric authentication. Proper training and awareness will also play crucial roles in ensuring that security measures are effectively implemented.

