Skip Navigation

Mitigating attacks based on knowing the length of a Windows Hello PIN - The Old New Thing

devblogs.microsoft.com Mitigating attacks based on knowing the length of a Windows Hello PIN - The Old New Thing

Balancing convenience against security, and how you can tune the knobs toward more security.

Mitigating attacks based on knowing the length of a Windows Hello PIN - The Old New Thing

Describes considerations of convenience and security of auto-confirmation while entering a numeric PIN - which leads to information disclosure considerations.

An attacker can use this behavior to discover the length of the PIN: Try to sign in once with some initial guess like “all ones” and see how many ones can be entered before the system starts validating the PIN.

Is this a problem?

1
1 comments