Daily Blog #753: Windows hello challenge part 4
Windows生物识别数据存储在\Windows\System32\WinBioDatabase文件夹中,文件名由GUID和.DAT扩展名组成。这些文件包含加密和哈希处理的用户身份信息,用于面部识别或指纹认证。加密密钥可能存储在TPM芯片中。 2025-2-19 04:14:0 Author: www.hecfblog.com(查看原文) 阅读量:35 收藏

By February 18, 2025

Hello, Reader,

The bonus question in this challenge asked where Windows stores the biometric data used for facial recognition or fingerprint authentication. It turns out that this information is kept in a database located at:

\Windows\System32\WinBioDatabase

Inside this folder, you’ll find files named with GUIDs and a .DAT extension, for example:

DC576DA6-D676-4A15-906D-C0CEAF949543.DAT

These files contain an encrypted and hashed version of a user’s identity that Windows uses for system authentication. This process is part of the Windows Biometric Framework. For more details, check out the Biometric Framework Overview on Microsoft Learn.

The encryption key being used remains unclear, and it’s possible that these keys are stored in a TPM chip. I’ll take a closer look at this file in my next post to see if the Data Protection API is also being utilized.

Stay tuned!


文章来源: https://www.hecfblog.com/2025/02/daily-blog-753-windows-hello-challenge.html
如有侵权请联系:admin#unsafe.sh