New acoustic attack steals data from keystrokes with 95% accuracy
11–20 of 239 posts
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#12Earlier quoted context omitted.
When calling my cellular/internet/medical/financial provider, it might be interesting to "see" what they are typing. (Or if they're randomly surfing the internet.)
Call support, get the URLs and logins for all their internal apps. Ouch!
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#13Re: New acoustic attack steals data from keystrokes with 95% accuracy
#14I don't use the qwerty layout, I use colemak. Likely this mitigates this for myself.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#15I don't use the qwerty layout, I use colemak. Likely this mitigates this for myself.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#16I don't use the qwerty layout, I use colemak. Likely this mitigates this for myself.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#17So they generated training data from one laptop and microphone then generated test data with the exact same laptop and microphone in the same setup, possibly one person pressing the keys too. For the Zoom model they trained a new model with data gathered from Zoom. They call it a practical side channel attack but they didnt do anything to see if this approach could generalize at all
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#18I don't use the qwerty layout, I use colemak. Likely this mitigates this for myself.
This is just security through obscurity. For real security, you need a cryptographically rolling keyboard layout.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#19Re: New acoustic attack steals data from keystrokes with 95% accuracy
#20Timing attacks have been attack vector for a while? I remember reading a tool on HN a couple years ago about it. You don’t even need audio, the rate of which you enter the keys into the password field is enough.