Elektrine lite

← Feed

@Slater450413@infosec.exchange

Post #2438370

2026-02-06 10:31 UTC

A few people have pointed out the security separation being a point of difference in Windows but I do wonder if that actually exists or if is it just assumed? The hardware itself just presents as a regular camera with a regular generic driver, nothing special about it. The login screen context is certainly segregated context (has been Win2k, I think) but does anyone elevate to enroll their face under their own user context? I've never used Windows Hello, so my knowledge is quite dated but I don't belive fingerprint scanners do, which would be a similar mechanism where an abstract identity token from an arbitrary hardware device is created and stored without the need to elevate. Presumably you still need to authenticate to prove "you are you" when enrolling new methods but just no privilege escalation to use the hardware device for the capture itself.

Replies (0)

No replies.