Before the usual retort of "You know this is Microsoft, right" rolls in, this question does deserve consideration.
Was this not tested against, at all?
Did they not attempt to circumvent this method with a photo? I write code for a living, and something that's continually running through my mind is "how can this fail or break?" I'm certain there are devs at Microsoft who are similarly afflicted.
So I guess the real question is: Was it tested, and everyone just hoped no one in meat-space would also think to try a photo, or was there some pointy-haired manager who decided that enough dev time had been spent, and it was time to turn the profit faucet on?