Liliputing

  • Reviews
  • Deals
  • How To…
  • Mini PCs
  • Shop
  • About
    • About Liliputing
    • Contact us
    • Advertise on Liliputing
    • Support Liliputing
    • Privacy Policy

If you’re using Lenovo Fingerprint Manager Pro, update your software

01/29/2018 at 1:51 PM by Brad Linder 1 Comment

Lenovo Fingerprint Manager Pro is an application that shipped on more than two dozen Lenovo ThinkPad laptops and desktops released with Windows 7, Windows 8, and Windows 8.1 software. The company stopped shipping it on systems that come with Windows 10, because Microsoft has added native support for fingerprint recognition to the operating system.

But if you have one of those older systems, Lenovo’s software would let you login to the PC with a fingerprint or access websites and other content using your fingerprint rather than by typing in a password.

Unfortunately, Lenovo Fingerprint Manager Pro was kind of a security nightmare. Lenovo has released a security notice urging anyone using the software to upgrade to a newer version (although I wouldn’t blame you for just deciding to stop using it altogether).

The language in the advisory is pretty interesting, since Lenovo basically admits that its software was easily hackable, and it doesn’t sound like the company took any common-sense steps to ensure that it wasn’t:

A vulnerability has been identified in Lenovo Fingerprint Manager Pro. Sensitive data stored by Lenovo Fingerprint Manager Pro, including users’ Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system it is installed in.

Lenovo gives credit to Jackson Thuraisamy from Security Compass for identifying the issue, but it really sounds like bad design rather than a flaw that needed to be “identified.”

You can find the list of affected Lenovo PCs in the security notice. And if you want to keep using the software, you can download the latest version from the Lenovo support site.

via The Register and ThreatPost

Share this:

  • Facebook
  • Twitter
  • Reddit
  • Email

Daily Deals (2-20-2019)

Amazon is running a 1-day sale on networking and storage gear, which makes today a pretty good day to pick up a microSD card, portable hard drive, … [Read More...]



Support Liliputing

Liliputing’s primary sources of revenue are advertising and affiliate links (if you click the “Shop” button at the top of the page and buy something on Amazon, for example, we’ll get a small commission).

But there are several ways you can support the site directly even if you’re using an ad blocker and hate online shopping.

Contribute via PayPal

  • donate monthly
  • donate once only
Select a Donation Option (USD)

Enter Donation Amount (USD)

Subscribe via Patreon

Become a Patron!

1
Leave a Reply

Login with
Facebook Google Twitter WordPress Yahoo! Disqus Reddit Stackoverflow GitHub
avatar
This comment form collects your name, email address, and content to allow us to keep track of comments placed on this website. Please read our privacy policy for more details.
Save my name, email, and website in this browser cookies for the next time I comment.
1 Comment threads
0 Thread replies
0 Followers
 
Most reacted comment
Hottest comment thread
1 Comment authors
zdanee Recent comment authors
avatar
This comment form collects your name, email address, and content to allow us to keep track of comments placed on this website. Please read our privacy policy for more details.
Save my name, email, and website in this browser cookies for the next time I comment.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  Subscribe  
newest oldest most voted
Notify of
zdanee
Member
zdanee
You can flag a comment by clicking its flag icon. Website admin will know that you reported it. Admins may or may not choose to remove the comment or block the author. And please don't worry, your report will be anonymous.

Well, most of these old swipe-down fingerprint sensors are more of a security risk than not, you can fool most of them with a piece of tape and a fingerprint of the original user somewhere on the notebook (or a nearby mug on their desk or something). No buggy software needed for the feat.

Vote Up3Vote Down  Reply
1 year ago

Follow Liliputing:

Facebook Twitter YouTube tumblr RSS Patreon

Latest News

Samsung Galaxy S10 Bixby button can also launch other apps

Samsung really wants its customers to use its Bixby assistant software, which is … [Read More...]

Chrome OS 74 will enable audio for Linux apps

You can install and run Linux apps on most recent Chromebooks thanks to Google's … [Read More...]

Samsung Galaxy S10 5G has 6 cameras, a big screen, and a big battery

Samsung's Galaxy S10 series smartphones may pack a lot of features... but … [Read More...]

Featured articles

GPD MicroPC handheld computer preview

It's been a good couple of years for handheld computer enthusiasts. Companies … [Read More...]

Taihe Gemini portable 1080p touchscreen monitor preview

The Taihe Gemini portable monitor has made quite a splash since going up for … [Read More...]

Zotac Pico PI470 is a pocket-sized PC with Intel Amber Lake

Zotac's latest pocket-sized computer is the company's most powerful to date. … [Read More...]

Disclosure: Some links on this page are monetized by Skimlinks and Amazon's and eBay's affiliate programs.

Login

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org

Copyright © 2019 Liliputing · About Liliputing · Contact Us · Privacy Policy · Go to top of page

wpDiscuz
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.