New acoustic attack steals data from keystrokes with 95% accuracy
121–130 of 239 posts
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#122Re: New acoustic attack steals data from keystrokes with 95% accuracy
#123Re: New acoustic attack steals data from keystrokes with 95% accuracy
#124The example figure shows a key hit every half second, which suggests a pecking style of typing at around 24 wpm. This way the model gets very clean waveforms. I wonder how their approach would work with average or fast typists. The sound profiles might be much harder to link to characters.
Even better if the target uses a passphrase, "hXXXse battXXX stXXXXX cXXXXXX" becomes interpretable given a few landmark letter identified with high probability.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#125Earlier quoted context omitted.
I guess more reason to just use a password manager to autofill your password?
Or just use 2fa
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#126Would love a wireless keyboard that works using this! It wouldn’t need any battery, charging or syncing!
Imagine the UX of 1 in 20 characters typed being incorrectly inferred though. The P_failure*Cost impact would strike me as insufferable even if error rate were to improve by an order of magnitude.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#127Earlier quoted context omitted.
Not according to the article.. Microphones are sensitive enough to mount the attack on quieter keyboards.
What we clearly need are louder keyboards - which overload the mic so as to render keystrokes indistinguishable.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#128Earlier quoted context omitted.
What we clearly need are louder keyboards - which overload the mic so as to render keystrokes indistinguishable.
Adding a gain knob to my keyboard, be right back.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#129So they generated training data from one laptop and microphone then generated test data with the exact same laptop and microphone in the same setup, possibly one person pressing the keys too. For the Zoom model they trained a new model with data gathered from Zoom. They call it a practical side channel attack but they didnt do anything to see if this approach could generalize at all