Microsoft Puts Built-In Fingerprint Sensor On Its 'Modern Keyboard' (Updated)

Latest Videos FromTom's Hardware
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • Wingman22
    biometric authentication?
    biometric at most can be used to get your username, and that is a risk already. It can't be easily changed.
    Password must be secret and very hard to guess at all cost
    Reply
  • clonazepam
    I'm definitely in the same camp of biometrics being strictly username, if anything.
    Reply
  • Using biometrics as password is wrong because once it gets compromised it is not like password which you can change.
    Reply
  • lathe26
    Microsoft already released a fingerprint keyboard over a decade ago. It was called the "Microsoft Optical Desktop with Fingerprint Reader". Users could log into the home version of windows but the product did not work with enterprise windows (wasn't secure enough).

    https://www.amazon.co.uk/Microsoft-Keyboard-Optical-Fingerprint-Bz5-00002/dp/B0002ZHBIM
    Reply
  • ravewulf
    Does Windows Hello still require you to create a simple numeric key as a backup to unlock your device? Cause that's another huge security flaw. Guessing or cracking a short numeric code is insanely easy compared to a password.

    Also, I can't wait until Microsoft moves on from "Mondern UI" etc to something else because I am not a fan of this aesthetic.
    Reply
  • thundervore
    Most people are forgetting that a US court can get a warrant for fingerprints to unlock a device (because its something they have) but they cannot get a warrant for a password due to one cannot self incriminate themselves (its something only you know).

    I'm surprised its not backlit, would be beautiful if it was.
    Reply
  • rantoc
    I have to agree with most clever people who see beyond today - Using any biometric as password is just STUPID, once its leaked/scanned or whatever it will open up all places where its used and even "is the scanned part/material alive" checks can be fooled... So using biometric for password is just as stupid as reusing the same password on multiple sites beside here it's not even possible to change it IE once spent its useless.
    Reply
  • falchard
    Biometric passwords are usually used in one of 2 cases. Either it is part of a 2 step authentication, or it is device specific. In these situations, the problems of a biometric scan are much better mitigated. For the common user, it would be easier for them and would be more secure than the typical 8 character password.
    Reply
  • computerguy72
    Wow. Lots of people speaking authoritatively who literally know nothing about what they rant. To the guy who thinks a court can force you print to be released - that could only happen with the image which isn't used in any of these consumer systems. It's only used to extract in a fips and AFIS systems and even then not in the same database. To the guy who thinks template data can somehow be built into a useful image - that is absolutely false. To those who says these are less secure than a password... you must be kidding... Just like very old passwords, very old fingerprint system were similarly vulnerable. To the guy who says your fingerprint can't easily be changed - since what's used in the extraction and how much of it is stored in the template technically the data changes for every system. The resolution in most of the systems today even detect the pores in your finger.
    Reply
  • therealduckofdeath
    99.999% use either insecure passwords or write them "in plain sight" because they're too hard to remember. Yes, biometrics has never been considered secure as Fort Knox. Nobody has ever claimed that. It is however infinitely more secure than having the password written on a sticker on the side of the display. This is not intended for "master passwords", this is for unlocking those dozens of applications and other things people otherwise ALWAYS use the stereotypical "Secret1" password on.
    Reply