Preliminary research
Borrowing Windows Hello Keys for Authentication and Persistence
Borrowing Windows Hello keys for authentication and persistence
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
The WHFB private key lives in the TPM, yet the Passport KSP via NCryptOpenKey signs arbitrary data for a low-privilege user with no PIN or biometric prompt, a side effect of RDP needing the key usable under another device identity. Signing the PRT request JWT gives a 90-day Primary Refresh Token. The same key also acts as a FIDO2 passkey - the Entra challenge is bound to no session or tenant and user_handle is derivable - and the token has no device ID claim, so it registers a fresh device.
Record
- Document
- Borrowing Windows Hello keys for authentication and persistence
- Researcher
- Dirk-jan Mollema
- Published by
- dirkjanm.io
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Dirk-jan Mollema, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .