Acoustic Keyboard Eavesdropping
github.com
github.com
Today, gr-tempest can recreate monitor images from HDMI RF emissions, using a low-cost SDR, https://twitter.com/markopolophys/status/1459911025642414086. GNU Radio conference video: https://www.youtube.com/watch?v=QRycX0M0H4s. TEMPEST techniques have been known for decades, but only recently became accessible to pen-testers via OSS code and low-cost hardware, https://en.wikipedia.org/wiki/Tempest_%28codename%29 & https://en.wikipedia.org/wiki/Van_Eck_phreaking.
In 2024, 802.11bf Wi-Fi 7 Sensing with mmWave radar could see through home/business walls to monitor keyboard typing, human heartbeats and other activity. While attackers can use custom radio firmware today, WiFi 7 will bring "X-Ray Vision" to consumers, ready or not, unless nation-state spectrum regulators intervene. https://news.ycombinator.com/item?id=30172647. If a neighbor buys a Wi-Fi 7 Sensing device, they could monitor human activity through your walls.
Intel (2020) presentation on Wi-Fi 7, slides #19 and #20 describe Wi-Fi Sensing, https://www.intel.com/content/dam/www/public/us/en/documents...
EMF shielding materials readily available at hardware stores include insect screening metal mesh and aluminum vapor or radiant barrier. There's also drywall which includes RF shielding, but it's expensive. DIY pointers: https://mpkb.org/home/special/emf/whitezones/faradaycage
Caveats:
We used contact microphones. Taking the data out of the air from an acoustic signal would be much harder, but not impossible in a quiet room with some fancy DSP.
There is a symmetry such that tapping the same distance from corner A is indistinguishable from tapping the equivalent position in corner B. Still, for a 4 x 4 PIN entry that's useful extra info.
It depends on the physiology, finger length and nails of the operator, and how they hold the phone. The fact that this may also be a unique identifier of the operator should not be a surprise.
[1] https://www.amazon.com/SteelSeries-Apex-Mechanical-Gaming-Ke...
[2] https://www.amazon.com/Blue-Snowball-Condenser-Microphone-Ca...
I'm not dunking on them. This is a really really hard problem. My comment is more that I'm not worried about this as a viable threat just yet.
I notice comments that the approach is not working for various setups. I recommend starting with the most simple test - using Keytap [0] and training it with just 2 keys (for example 'q' and 'p' on QWERTY keyboard). You should get nearly 100% recall rate with "Average CC" above 0.80 for each of the 2 keys. If this is not the case, then Keytap will most certainly not work for your setup.
"We show that PC keyboards, notebook keyboards, telephone and ATM pads are vulnerable to attacks based on differentiating the sound emanated by different keys. Our attack employs a neural network to recognize the key being pressed. We also investigate why different keys produce different sounds and provide hints for the design of homophonic keyboards that would be resistant to this type of attack."
They are specifically designed so that all the keys sound exactly the same, and individually tested at the manufacturer. This is something they've already thought about, back in the early 1990s.
(I'm sorry I couldn't find the post again)
https://news.ycombinator.com/item?id=25686201 https://news.ycombinator.com/item?id=25644828
[0] https://www.anishathalye.com/2018/04/03/macbook-touchscreen/
Then, at some point, you or your peer are prompted to enter a password. The password field shows up as all bullets. But... can you still identify the password based on the audio feed?
I manually fudged spacebars and enters because they're accoustically obvious, and played around with punctuation keys. Generally the timing for fingers to move from one key to the other was where I was finding the strongest signal.
That must be a fun way to type in someone's password to their computer when they lock it and walk away to get some coffee...
Even just knowing the length of the password, estimating which keys in the sequence are capitalized (if Shift behavior is fairly easy to pin down) and being able to pin each key down to 5 possibilities would make a 20 character password trivial to crack. Right?
> algorithm improvements and better n-gram statistics
GPT-3
And you got a startup going.
If you can't get key switches loud enough, I made a little Emacs Lisp snippet that plays a tone on every keypress. Example is for macOS, but adaptation to *nix should be trivial. https://gist.github.com/ashton314/4ca20e6e040f07aef58a05f42d...
Better to just blast the airhorn while you type.
However, if the counter-noise would get triggered first by a key press then it would not be able to mask the initial part of the key noise when the finger strikes the key surface before pressing it down. Detection using a microphone would have the risk of false positives, so maybe a new key mechanism also including capacitive touch/proximity sensors would be needed.
And it would be ineffective against attacks that model key stroke patterns temporally.
"This is what mechanical keyboard users deserve" -- super guy
Ouch
I need to break out my relay board to see if the sound of the relays clicking mitigates attacks like this: https://youtu.be/6hMOGKTudcg (see it in all its clicky glory!)
As long as the click of the relay happens fast enough--and I add some sound dampening to the keyboard (which was the opposite of what I did for that test video haha)--I bet it would render this kind of attack useless.
They possess a large corpus of training data (heck, some of them play typeracer on-screen.), and would no doubt have a few with quite audible mechanical keyboards near decent recording setups.
Then again, good security hygiene still mitigates this. (Avoiding password re-use, using 2FA where available etc.)
You wouldn't be emitting the sounds of typing your password while using a password manager either... (Well, except for the unlock password. Also there's something to be said about clipboard implementation across different operating systems.)
It does not require training data - instead it uses statistical information about the frequencies of the letters and n-grams in the English language.
and from this it should also be noted that it won't apparently be able to extract passwords, as least those which aren't "n-grams in the English language".Preliminary looks into remapping keyboard inputs in real time looks annoying to make portable, but doable.
Which makes me wonder: With a sensitive enough microphone array, might it be possible to separate out the locations of each individual key? At the very least, it seems like it might be possible if it's coming from the right or the left side of the keyboard.
> “I think political systems will use it to terrorize people,” Hinton said. Already, he believed, agencies like the N.S.A. were attempting to abuse similar technology.
> “Then why are you doing the research?” Bostrom asked.
> “I could give you the usual arguments,” Hinton said. “But the truth is that the prospect of discovery is too sweet.” He smiled awkwardly, the word hanging in the air—an echo of Oppenheimer, who famously said of the bomb, “When you see something that is technically sweet, you go ahead and do it, and you argue about what to do about it only after you have had your technical success.”