started · updated
German BSI warns Windows Hello for Business vulnerable to admin‑level attacks
The German Federal Office for Information Security (BSI) released the first technical report of its "Windows dissected" project, focusing on the biometric authentication solution Windows Hello for Business. The agency identified attack scenarios where attackers who already have local administrator rights on a device can decrypt and manipulate stored facial or fingerprint templates, allowing them to authenticate as another user.
To mitigate these risks, BSI recommends enabling the Enhanced Sign‑in Security (ESS) mode, using a Trusted Platform Module (TPM), restricting each device to a single biometric template, and applying additional organisational and technical safeguards outlined in its published guidance.