bk99.de entertain the web since 1997

Lenovo admits security holes in Fingerprint Manager

Summary

In January 2018 Lenovo admitted holes in its Fingerprint Manager Pro software, which managed biometric data on computers running Windows 7, 8 and 8.1. The software used a weak encryption algorithm, contained a hard-coded password and was accessible to local users without special rights. Windows 10 was not affected because Windows Hello takes over the function there.

Ideas

  • A hard-coded password renders any encryption worthless.
  • Biometric data was stored on the device for websites and logins.
  • Functions integrated into the operating system replaced manufacturer software.

Insights

  • Additional software from device manufacturers is often less well secured than the operating system.
  • With biometrics, leaks weigh more heavily because fingerprints cannot be replaced.

Facts

  • The holes were discovered by Jackson Turaisamy of Security Compass.
  • Lenovo did not name the algorithm used.
  • Lenovo recommended an update to version 8.01.87 or newer.

References

Critique

  • The report does not say whether stored credentials had to be re-encrypted or deleted after the update.

Recommendations

  • Remove preinstalled manufacturer software whose function the operating system itself provides.
  • Store biometric data only in the device’s dedicated security hardware.

Read the original article

Search the Web Archive