False Promises of Passwordless: Defeating Windows Hello through TPM Misuses

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Passwordless authentication is increasingly being adopted as an alternative to traditional knowledge-based authentication, primarily because of its convenience and security advantages. There is a clear lack of research geared towards the integration of passwordless authentication with host security and operating systems. We bridge that gap by uncovering critical vulnerabilities in Windows' passwordless authentication. Specifically, we identify misconfigurations where hardware-backed protection is silently bypassed due to improper TPM integration, undermining Windows' intended security guarantees. Furthermore, we show that the use of biometrics weakens data protection. We present three practical attacks that exploit these vulnerabilities. (1) 'Template Injection', bypasses biometrics by injecting forged templates into the system. (2) 'Passkey Migration', extracts and reuses passwordless credentials across devices. (3) 'Phishing', alters host authentication behavior to deceive users into exposing sensitive data. Our evaluation shows that these attacks work across diverse configurations, require no prior knowledge of the victim, and remain undetectable in practice. Among all tested cases, only systems with Enhanced Sign-in Security (ESS) prevented our attacks. Beyond Windows' native authentication, we examine third-party credential sync services, focusing on Google Password Manager (GPM). We find that GPM is vulnerable under certain misconfigurations, allowing abuse of synced credentials. Finally, we discuss the root causes of these issues and propose mitigation strategies.

키워드

digital forensicsidentity managementos and system securitysoftware security
제목
False Promises of Passwordless: Defeating Windows Hello through TPM Misuses
저자
Lee, JeonghoKang, MinkyeongLee, SeunghwanChoi, Hyoung-Kee
DOI
10.1109/ACSAC67867.2025.00037
발행일
2025
유형
Proceedings Paper
저널명
Proceedings - Annual Computer Security Applications Conference, ACSAC
페이지
308 ~ 321