Skip to content
logo The magazine for digital lifestyle and entertainment
CoBi Microsoft News Security Windows All topics
Urgent Warning

Windows Login Process Not Secure, Says BSI

Close-up of a finger touching the "Sign-in options" section under "Accounts" in the Windows settings on a screen
An analysis reveals how attackers could manipulate biometric data on Windows Photo: Getty Images/Florian Schuh
Share article

July 26, 2026, 12:49 pm | Read time: 3 minutes

The Federal Office for Information Security has taken a closer look at Windows Hello for Business. The agency published the first technical report from the “Windows Dissected” project. The focus is on the login procedure developed by Microsoft, which is used on many private and business Windows computers. Instead of a traditional password, login is done via PIN, fingerprint, or facial recognition. The report describes both the technical foundations and potential vulnerabilities that can be exploited under certain conditions.

How Windows Hello Works in the Background

According to the BSI, Windows creates cryptographic keys during setup. These bind the login to the respective device. The private key remains on the computer and is only released after a person authenticates via PIN, fingerprint, or facial recognition. Additional protection can be provided by a Trusted Platform Module, or TPM. The module stores important key information in a secure hardware environment, making it more difficult to access.

The report (PDF document) also describes situations where these protective measures can lose their effectiveness. This particularly affects systems where attackers already have local administrator rights and can access certain stored data.

Biometric Data Can Become a Risk

For facial and fingerprint recognition, Windows stores encrypted templates in a database on the device. According to BSI, attackers can, under certain conditions, access information that serves to protect this data. This could allow them to decrypt the stored templates, alter the database, and assign their own biometric data to another user’s account.

In such a case, it would be possible to log in with one’s own face under the identity of another person. However, the report states that the attack does not work remotely. Instead, the system must already be largely under the control of the attackers, with the necessary rights in place.

More on the topic

ESS Aims to Enhance Security

According to BSI, the described vulnerability is particularly relevant on shared computers. This is especially true when multiple people have stored their biometric features on the same device.

As a protective measure, the agency recommends using “Enhanced Sign-in Security” (ESS) if possible. This feature shifts parts of the biometric processing to a specially protected area. Additionally, compatible cameras and fingerprint sensors are more closely integrated into the security functions. This is intended to better protect both the stored biometric data and their comparison. However, ESS is only available on devices whose hardware and drivers support the feature.

Also of interest: Due to AI, Microsoft urges updates within three days

Recommendations for Businesses and Private Users

The BSI derives several recommendations from the investigation. Companies should, if possible, register only one person per device for Windows Hello. This reduces the risk of biometric data being incorrectly assigned to different accounts.

If ESS is not available, logging in exclusively via PIN may be the safer alternative. Furthermore, the agency recommends using a suitable TPM and an encrypted hard drive. Private users should also check whether their system supports ESS and whether biometric login can be additionally secured.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.