The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    ThinkVantage Fingerprint Software vulnerability

    Discussion in 'Lenovo' started by AofI, Oct 9, 2012.

  1. AofI

    AofI Notebook Geek

    Reputations:
    0
    Messages:
    81
    Likes Received:
    0
    Trophy Points:
    15
  2. Thors.Hammer

    Thors.Hammer Notebook Enthusiast

    Reputations:
    982
    Messages:
    5,162
    Likes Received:
    33
    Trophy Points:
    216
    Thanks for the heads up. We don't allow fingerprint login in my company. Good thing.
     
  3. power7

    power7 Notebook Evangelist

    Reputations:
    155
    Messages:
    531
    Likes Received:
    66
    Trophy Points:
    41
    It only affects the Thinkvantage tool. Uninstalling the tool, and just using the Windows built-in biometrics support for login, is unaffected.

    As to the vulnerability itself, it's actually not very serious. To exploit the vulnerability user must be convinced to execute a tool made by attacker with administrative rights. And if user does that, the attacker is free to install a keylogger and use the system as his own anyway.
     
  4. sniper_sung

    sniper_sung Notebook Evangelist

    Reputations:
    66
    Messages:
    611
    Likes Received:
    0
    Trophy Points:
    30
    "From a penetration testing perspective, local administrator access is required to obtain the necessary registry key's value, so it only matters if you already have control of the PC,"

    Hence this does not bother me.