A more high tech method would be to use a modulated wifi reflector that is randomly modulated.
One should also watch out for wifi hotspots with ominously pointed directional antenna
But what stops a passive wifi observer who can guess those things or already knows them?
Also: "We collected training and testing data from 10 volunteers." Not a statistically useful sample set.
Under very controlled environments, measuring signal deltas may be possible- but I would like to see sample data that suggests high success rates before I think this is worthy of concern.
Finally- Self tuning antennas are a thing. This is going to get harder over time. https://www.qualcomm.com/videos/qualcomm-rf360-dynamic-anten...
Another strategy I've seen is to ask some random digits of a longer PIN, with a mask to fill out.
Some security features I can recall.
Random layout of the numbers on both the button itself and which button has which number. This is shuffled on every click.
Upon clicking all numbers and the mouse pointer vanish. This prevents screenshots taken on clicks by some keyloggers from working.
No keyboard input. Annoying but needed to combat keyloggers.
http://vignette2.wikia.nocookie.net/2007scape/images/c/c3/Ba...
Fingerprints and never using public WiFi would both be good strategies. (I use my fingerprint to log into my banking app when on mobile.)
Yes, that would defeat this particular attack.
Also, what safety does a VPN add if you are already using https?
Last year after a trip in Germany, my older iPhone had a random password saved in Safari settings. On top of that, every time I tried to delete the password, it would reappear when I went back (iCloud sync was off, etc.). I don't remember browsing anything out of the ordinary, but did connect to a bunch of public wifi spots. Here's to hoping it was just a really persistent ad-tracking method.
I generally don't browse on my phone, so if I'm opening up Safari on a public network, it's to a known site or bookmark to quickly reference something (e.g. transit map, exchange rate). It's totally possible an ad on the NYT or Bloomberg has some malicious Javascript, but currently I'm naively assuming otherwise.
Also, I think many people on their phones will connect to a public hotspot just to check Facebook / Instagram / Snapchat these days and not much else.
Slower too maybe, but we're long past the point it really matters, except for latency sensitive applications. 50+ Mbps is just plenty for most applications.
Only real need of wifi to save some battery power and maybe to get better latency and jitter for VoIP and interactive applications.
AFAIK, US and UK are still pretty bad. I guess they have to limit bandwidth and data volume to be able to, ahem, listen to their customer.
In which countries is that true? Certainly not any that I visit.
Without this information, it is difficult to determine if the user is inputting a password. In addition, if we know the user is using the bank of america app, and we know that the app uses a specific key lay out, it becomes a lot easier to figure out what keys they are pressing.
There is no reason that the other technique they discussed, which does not require the target to connect to a specific wifi hotspot, could not be improved though.