Open source laser microphone picks up laptop keystrokes
wired.com
wired.com
It may be hard to do a non-terrible DIY laser microphone that would allow to achieve this while targeting a non-laptop surface.
After you have the recording the biggest challenge is a problem solving one, you need to isolate the waveform for every keystroke, convert it to something that can be compared with other waveforms (and cluster them) and then solve the resultant substitution cipher (waveform -> key identity). If the keyboard was used for any length of time, you can assume the entry of common words and phrases occurred at some point and the solution to the cipher is trivial.
If you have the resources to collect the data, it should be possible to train a transformer model to convert an audio recording to the output of sound signatures belonging to key strokes of a keyboard or multiple keyboards. The trick would be to not try to train it to do the entire problem which will almost certainly fail or not generalize.
I'm trying to understand whether this requires a "decoder ring" recording ahead of time (in the case of the former—okay, on this keyboard an A sounds like this, a B sounds like this...), or whether you'd be able to pull this off with no prep work because an A always sounds like an A and a B always sounds like a B.
Each combination of room, mic, keyboard, and letter is going to have a unique sound signature. But, you don’t need prep work.
If you can just record enough keystrokes, it’s possible to figure out what sounds go with what letters. This is the “substitution cipher” the other comment mentioned.
For example, the sound that comes every 2-10 letters or so but rarely twice is spacebar. The one that sometimes comes between two spaces is I. It’s obviously more advanced, but just to give you an idea.
A convenient theory but not a fact.
Thank you. A lot of people don’t get these are two different things. I’m not going for perfect, I’m going for “oh I get it.”
It would be trickier however if looking at raw keystrokes, as one has to consider several confounding factors:
* The caret can be moved both by keystrokes and mouse * You don't know what is being typed. If someone is typing people's names all day, or writing software then the analysis of letter/key frequency will be shifted
Not impossible, but makes the process harder.
It's an interesting problem you'd probably try to solve with Markov chains back in the day, but now you'd just throw machine learning at.
Anyway, I assume the answers aren't known because it would be an ethics/privacy nightmare to run these kinds of experiments on anyone but yourself.
Also many keyboards are very quiet clicks these days. And what if I’m playing music?
I imagine a surreptitiously planted keystroke logger is far simpler. Or perhaps camera(s).
Perhaps a speaker in the keyboard that emits a random click-sound to mask the real sound could be helpful here. But it might confuse the typist when it emits the spacebar sound after you typed a regular letter...
This obviously assume the screen is not simultaneously snooped, which is feasible..
The sample from that link seems to be the former:
https://github.com/shoyo/acoustic-keylogger/blob/master/data...
Doesn't really tell me anything about how realistic this attack is.
I can also see a future home assistant using a laser microphone to pick up on users' speech from anywhere in a room without needing to raise one's voice above a mutter.
Either way, I’m all for laser monitored keyboard. If nothing else then just for the reactions of others when I bring my laptop and a USB-corded keyboard and start typing on the external keyboard without plugging it in :)
(Although I guess, there’s a pretty high chance they will just assume that the keyboard simply has Bluetooth and that that is how it’s working even though not plugged in.)
take out a blank sheet of paper, draw a game pad with controls, start playing a game on screen by tapping those buttons you just drew
edit:
combine ..
Gestures from Apple Vision Pro
GenAI capabilities that can convert a sketch into a working web page
Smart Home automation
I think the point is that the keyboard itself needs 0 power, so it doesn't ever need to be tethered, recharged, have batteries replaced, etc.
Then all you need is a microphone running on the destination device. Obviously this is insecure but could be fun anyway.
The room mic would be awesome, as long as laser safety concerns were addressed.
Supposedly the White House uses vibrating windows to avoid this class of attacks.
(I am willing to die on this hill.)
Or it has sufficient energy to make any transmission effects through vibration useless because broad-spectrum the glass is shaking to shakira too much anyway.
:-)
Then a nitpick:
> "For example, if you type only "the" all day, then when you press the letter 't' the letter 'h' will be on the home row."
'h' is already on the home row on most keyboards.
> 'h' is already on the home row on most keyboards.
For some reason this made me think about our unit tests at work :)
Declining is futile.
And he's got an awesome project using helium weather balloons to fly networked RGB leds synchronised to the DJ tunes.
https://github.com/ggerganov/kbd-audio
He's subsequently well known for llama.cpp.
Presuming you have sufficient levels of assurance that no software exploits are present and no keystroke loggers etc. The only way to attack and the value of the attack being high enough (root CA compromise?) that an adversary would deploy (laser) mics.
I figure that anyone this concerned would program a coupe of rubber duckies or yubikey static mode ? Then the emitted strings would be unknown.
Also what about collecting from the screen via emissions?
One thing that could help to randomize that is a surface with tightly-coupled [truly] randomly-moving masses underneath, so that the resonances of the surface also change randomly.
(And if done very right or very wrong, you get a free Van De Graaf generator!)
---
Or: A laser projected keyboard where the keys are always shifting to different locations.
(Bonus: Free psychosis!)
even if its not, enough decent fidelity data with letter/word frequency analysis paired with small Neural net will quickly disambiguate keystrokes after the first paragraph.
DNA tests used to be in the many thousands of $ range, so they were used for heavy crimes like murders and rape only. Nowadays, it's routine for police to use them for petty crimes like graffiti [1].
It's just the same for camera surveillance, mass exfiltration and analysis of just about the whole Internet's worth of traffic... even searching phones and datamining them is cheap enough these days that US CBP does it for travellers, and German authorities for refugees (until a court order stopped that crap [2]).
[1] https://www.krone.at/2718383
[2] https://www.tagesschau.de/inland/innenpolitik/bamf-handydate...
its like saying, humans haven't reached the moon, even though humanity witnessed it in the sixties.
sometimes peoples memories are short.
Sensitive government information is handled in SCIFs.
https://www.nbcnews.com/politics/politics-news/what-scif-who...
Every article of theirs tells you it's the end of the world and you have no chance against those evil dirty hackers around the corner.
Once you run a script batching nearly all your jobs, good luck trying to guess the user it's doing. A plus if you run tools like ii/jj or similar with bitlbee as your chat client. If you can bind vi/vim to it by using a file as the input, vi has the 'ab' (abbrevebiate) ex command (use nvi if you like unicode, in some systems it's called nvi2) which can autoexpand abbreviated input. Such as:
ab obsd openbsd
ab nbsd netbsd
ab fbsd freebsd
ab hnews news.ycombinator.com
ab kbd keyboard
ab spc space
ab cmd command
and so on.He uh, is more than an 'attractive youtuber'.