UPI en Español  |   UPI Asia  |   About UPI  |   My Account
Search:
Go

Software flaw endangers laptop security

|
 
Published: Sept. 6, 2012 at 5:57 PM

MOSCOW, Sept. 6 (UPI) -- A flaw in software that controls security fingerprint readers on laptop computers can expose all files and documents on a PC, Russian security experts say.

Laptops from many of the world's top PC makers contain fingerprint readers that utilize the vulnerable software, ZDNet reported Thursday. Russia's ElcomSoft, a developer of Windows software, said it discovered a flaw in the UPEK Protector Suite, a fingerprint reader software program, that compromises a computer's security.

Protector Suite lets users utilize a finger swipe in place of entering a password. The software records passwords to Web sites and Windows itself to support the one-finger logon.

"We found that your Windows account passwords are stored in Windows registry almost in plain text, barely scrambled but not encrypted," ElcomSoft's Olga Koksharova wrote in a blog. "We could extract passwords to all user accounts with fingerprint-enabled logon. Putting things into perspective: Windows itself never stores account passwords unless you enable 'automatic login,' which is discouraged by Microsoft."

Windows allows activation of the setting after warning users automatic logon is a security risk.

The UPEK flaw is "nothing but a big, glowing security hole compromising the entire security model of Windows accounts," ElcomSoft said.

Laptop manufacturers using UPEK software include Acer, ASUS, Dell, Gateway, Lenovo, MSI, NEC, Samsung, Sony, and Toshiba.

Users with UPEK Protector Suite software should disable the Windows logon feature, ElcomSoft said.

© 2012 United Press International, Inc. All Rights Reserved. Any reproduction, republication, redistribution and/or modification of any UPI content is expressly prohibited without UPI's prior written consent.

Order reprints
Join the conversation
Most Popular Collections
'Star Trek Into Darkness' screening NBC upfronts Met Ball 2013
'Great Gatsby' premieres in New York Spire raised on top of One WTC 2013: Celebrity break ups and divorces
Additional Technology Stories
1 of 16
Flags-In Ceremony at Arlington National Cemetery
View Caption
Staff Sgt. Jeffrey Roskos with the 3rd U.S. Infantry Regiment, "The Old Guard," participates in the annual Flags-In ceremony, May 23, 2013, at Arlington National Cemetery in Arlington, Virginia. Soldiers place American flags in front of more than 260,000 gravestones in the cemetery in honor of Memorial Day. UPI/Kevin Dietsch
fark
Is it possible to have a library with no books? Yup
The Skagit River Bridge, which is part of Interstate 5, has collapsed in Washington. People and...
Worst butt dial ever
Stalking a 15-year-old pupil for two straight years will get you banned from teaching for life....
Proof that Heinz sight is 20/20, investors are pouring money into condiment futures instead of bonds...
Man files lawsuit to have President Obama declared Kenyan. The man is currently serving a 17 year...