Bypassing face-recognition systems

Some laptops ship with specialized software designed to log into Windows XP and Vista without any password, using the built-in camera and face recognition algorithms.

Vendors introduce that feature as a way to prevent unauthorized people breaking into laptops and to ensure information security for their owners.

However, vietnamese security researchers from BKIS demonstrate that algorithms of face recognition software (as shipped with Asus, Lenovo and Toshiba with their laptops) can be defeated using specially crafted photos or videos. Even with a sharp built-in camera and even with the software set in high-security mode, they could log into user accounts without difficulty with photos that weren't high quality.

The key is to use enhanced photos, with greater contrast levels on prime areas, in order to match expectations of the software.

Click below in order to download the demonstration video made by BKIS, showing face-recognition software of several laptops bypassed with photos.

Bypassing face recognition system (video mirrored with permission from BKIS)

Here's the original BKIS advisory.