Keylogging on IPhone and Android Using Gyroscope Data and Machine Learning
medium.com
medium.com
If I got that close to making something as cool as this, I would not stop experimenting until I found out whether it worked or not.
That is, unless I tested it, found that the imprecisions made it impossible to obtain reliable data, and decided to not write about it to not discredit all the work I had done.
I really hope someone takes the idea and tries it out to assess how viable it is, then I can be paranoid about 2 more sensors spying on me.
https://www.usenix.org/legacy/event/hotsec11/tech/final_file...
They focused purely on the number keyboard to try and extract PIN numbers and were able to achieve 70% accuracy using only a basic classifier.
I wonder how much newer smartphones with bigger screens and more precise sensors could improve these results.
It's scary to think of how many different sensors could be used to gather even more information to make it more precise.
Also this is mindblowing, logging keystrokes from a standard keyboard using wifi.
"we show for the first time that WiFi signals can also be exploited to recognize keystrokes. The intuition is that while typing a certain key, the hands and fingers of a user move in a unique formation and direction and thus generate a unique pattern in the time-series of Channel State Information (CSI) values"
https://www.sigmobile.org/mobicom/2015/papers/p90-aliA.pdf
Edit: I wonder as an aside how precisely you could potentially use the accelerometer etc. for dead-reckoning.
Edit: Wow, I'm just skimming it at the moment, I'd never heard of 'Magnetic Particle Filtering' before, that is really amazing!
Also semi-related, I just found this https://en.wikipedia.org/wiki/Magnetic_anomaly_detector. Apparently they degauss submarines precisely to avoid that :)
It seems like it could be possible, but it would require a lot of training. Get it into a popular note-taking app to record keystroke + accelerometer data.
Also a simple fix for iOS as a platform would just be blocking out or filtering motion data when the secure keyboard is showing. I assume a similar thing could be done on android.
Unsuspecting user downloads “Evil Flappy”, an app where they have to tap on the screen mindlessly to advance some objective. During this tapping, the app uses transfer learning to tailor the model to the user and test its own predictive capacity.
Very sneaky indeed...and I loved Evil Flappy :-)
This is extremely contrived and would take a shitload of skilled work to get right. It's way easier to make a phishing page coupled with social engineering to get what you want.
On iPhone it restricts background activity after 10 minutes, but on Android you'd have free reign until they manually close the app.
Sorry, looks like I misunderstood them (didn't notice they were referring to the paper).
Regardless, I don't think a screen tap logger would be necessary in many cases, since you could just open the keyboard on the phone and manually check the bounding boxes for each key.
Making this work on N phones would be more difficult, but not unfeasible. You'd probably just need to know a few things about the phone (resolution, screen size), and it wouldn't be hard to find that information.
Would be especially easy to just target the limited iPhone line.
But for now i'll have to randomly rotate my device at each input... And or get one of those keyboards that shuffles the letters around the keyboard at each input.