The way people tilt their smartphone 'can give away passwords and pins'
bbc.co.uk
bbc.co.uk
In my university days, long before the days of tablets and smartphones, the computer labs were the usual place where people will congregate to do their assignments or basically kill time on the internet in between classes.
One day, my mates and I noticed how annoyingly loud some people type on their keyboards and out of sheer boredom, we decided we could come up with an algorithm to determine what a person was typing simply from recording the sound of the keystrokes from our vantage point. Taking that sound clip, we graphed it out and we proceeded to hash out each "stroke" based on how loud it was in relation to the distance of where we were from the keyboard + the angle of the keyboard.
Fun times ensued. ;)
They can reconstitute private keys, by listening repeatedly to the sound the power supply of a laptop makes when encrypting/decrypting emails, from 5m away.
I’ve considered implementing this as a keyboard layout in Android, so you could put your phone on the desk and type by scratching a stylus or fingernail on the surface next to it.
Some of us are even familiar with acoustic cryptoanalysis[0].
However, combine these methods with this[1] tech, inspired on the work done here[2], and we have ourselves an impending crisis on our hands.
[0] Acoustic Cryptoanalysis - https://courses.csail.mit.edu/6.857/2014/files/23-shroff-hu-...
[1] Extracting Audio From Visual Information - https://news.mit.edu/2014/algorithm-recovers-speech-from-vib...
[2] Eularian Video Magnification - https://people.csail.mit.edu/mrub/papers/vidmag.pdf
Let's run through a scenario.
Your office orders pizza every Tuesday at the same time, via a coworker's cell phone. You are working on a technology that has the potential to disrupt several leading industries that are in bed with the government. After much lobbying, it is decided one day that your call to Domino's is to be rerouted via your broadband processor to an operative that mirrors your order to the real Domino's, and hand delivers the pizza at the front desk.
On their way out, they place a small, embedded, self-destructable camera device that focuses on your fancy new plexiglass installment. Over the next few weeks, the device documents all keystrokes and conversations from the front desk, and finds a way to socially engineer a copy of your codebase. Next year, seemingly out of nowhere, another venture suddenly launches ahead of your launch schedule, with your exact business model. All because you wanted some plexiglass and didn't think it was worth the money to actively scan the entire perimeter for bugs daily.
If this sounds crazy and far-fetched to anyone, then it would behoove them to look into past CIA infiltration techniques and also to realize that this is exactly the kind of stuff the CIA exists to do.
I think one can tend to create similar gibberish over time. I've worked on a system where I needed to do a new signup every time I wanted to test a feature and I've run into issues where the gibberish I entered matched an account that I had previously created.
[0] http://www.berkeley.edu/news/media/releases/2005/09/14_key.s...
This is brilliant and well-explained.
On page 6 of the PDF, the authors include a breakdown of the leakages they found in each browser family. The two that were most significant to me is Chrome's "Active/Other" leak on iPhones and Safari's "Locked" leak. I believe this means that malicious Javascript (1) on Google Chrome on an iPhone on an inactive tab, and (2) on mobile Safari while the screen is locked, can access tilt and motion data at a level of detail sufficient to deduce what the user is typing.
There is this annoying popup add that infects the ad networks of a few websites that first smashes the history of the tab and then vibrates your phone and has a page with a bunch of red warning text telling you that you have a virus, your phone is "damaged" and trying to get you to download some crappy virus scamware.
No way in hell a random website should be able to make your phone vibrate without your permission much less tell how its moving with the accelerometer.
I've google around a lot there is NO WAY to disable this :/
The patterns are predictable, and can be further narrowed down if you now the hand they normally use.
What use case am I not thinking of here?
Saves a lot of CPU if I have google search result in background tabs.
In the description it also mentions other extensions, especially suspend-background-tabs looks like something I might be using on one of my/someone elses machine.
Here is a helpful discussion including using the Yubikey Neo NFC with Android phones and alternatives to Yubikey: https://news.ycombinator.com/item?id=13635433
Google 1st: https://security.stackexchange.com/questions/150153/is-a-dum...
But isn't the point of 2FA that it's OK to have each of the factors individually be (relatively) insecure—passwords being about as insecure as imagineable for most users—as long as no-one is likely to have access to both of them? Thus, it's OK if someone can read your texts, as long as they don't also know your passwords.
edit: I like that "Obviously hackers wear hoodies..." hahaha, I like to wear a mask, and see as little as possible, while I mash on the keys hacking into the NSA.
edit: it's not funny though when you happen to see your server logs and you see various attempts to break in using wordpress-access attacks like forget the one xmlrc or something... I don't use Wordpress but man... gotta keep an eye on those logs. Also tracked one of the ips, lead to some site called BoltCloud, looks legit, with a login but... I don't know... not sure if you can bounce attacks from a server without that server's permission.
finally!
> They say they cracked four-digit pins with 70% accuracy on the first guess and 100% by the fifth guess.
I'd expect within a few months they could have 70% accuracy on the first guess for typing text/passwords.
I'm sure there's more written on this, but most patterns I've seen are just way too short. And hug the outer edge, are in-order, etc.
[1]: https://people.csail.mit.edu/mrub/VisualMic/
[2]: https://cacm.acm.org/magazines/2017/1/211095-eulerian-video-...
Even humans are very prone to "glass of juice" vs "gas the jews" type errors.
For example, the bar for Men's shopping password length is 3x-4x longer than for Women's, but in reality the value (in tiny font) is only ~8% greater (the others are ~4% and ~10%).
What about putting and end to tracking gestures?
>Based on a test set of fifty 4-digit PINs
Any option for iOS? Can someone recommend a good 4way privacy screen protector?
[1] http://www.theverge.com/2017/3/23/15038364/blackberry-privac...
Still the thought of someone snatching my wallet and swiping away at my cards. Where as if the card wasn't "active" unless my hand was the one holding it, I don't know how... finger print, pulse, heat, embedded RFID chip activates the card... I don't know. think DNA-linked money too, but someone could steal your hair... I don't know, I'm just not going to carry more than $20.00 on me in any form of money.
random thought too: when everyone has their own API and this replaces social media, why would that happen I don't know. If people had custom readers to pull in a person's data.
http://www.theverge.com/2016/5/2/11540962/iphone-samsung-fin...