Live data from Hacker News

New acoustic attack steals data from keystrokes with 95% accuracy

bleepingcomputer.com

191–200 of 239 posts

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#191

I'm not clear why people are poo-pooing this as if it's not a big deal. From a security and espionage point of view this is pretty significant - the audio learning has got to the point that a sensitive audio bug can bascially be key logger. There are a ton of context where an audio tap would be much easier to get in place than a traditional network attack (and with modern shotgun mics, might not even require being in…

I wonder if playing the typing sound constantly could help. Not an abstract sound, but recording of your actual typing on this particular keyboard, mixed to play some realistic-sounding phrases / sequences. It should pause for a split second to let your actual keystrokes mix in. That would be really hard to decipher, or to correlate your typing with whatever other events (time to enter a password).

Better yet, play some white noise around you. I heard that it's actually done sometimes at really important meetings.

If you're not such a VIP, just type important things only on your phone; touch screens don't produce enough sound, hopefully.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#193
post #187
post #176

Earlier quoted context omitted.

That's already possible, the lack of battery, but likely impractical. There is enough energy during key press/release to be usable for sending radio signal, however it won't be sufficient to do it while holding a key. A combination of a solar panel, piezoelectric keys and a tiny li-ion (as backup) may be sufficient for a 'battery-less' keyboard, but it will be too expensive.

Could you send a separate 'key up' signal on release from the energy of the up-stroke?

That likely would require a (beefer) string to store the energy as release the key alone doesn't require any force

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#194

By the way, some (most?) videoconferencing software removes keyboard sounds from the audio, because it's particularly a distracting problem with laptops where the microphone is right next to the keys. I'm pretty sure Zoom does this by default as part of its noise cancellation (it's potentially even easier since you can use keydown events to help identify, not just the audio stream). So as long as basic default noise…

If any random webpage is granted access to the microphone, I would think this could be a problem.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#195
post #182

Earlier quoted context omitted.

I used to work in an office space with an independent contractor whose schtick was that he was a genius. The affectations around his genius-ness included casually bringing up Mensa meetings, dropping magazines like Foreign Affairs and academic journals around the office, and his fucking keyboard. The keyboard had custom switches that were very loud. And he typed fast - it was like living on a gun range. Everyone in t…

Somewhat tangential: clicky switches, like Cherry Blues, tend to click twice for each stroke. I think this leads to people assuming there are twice as many strokes going on. Tactile switches tend to only click once (when they bottom out). So, fancy keyboards can make people sound faster than they are.

Add a guy that bottoms out the keys and you will have an additional "click".

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#196

Earlier quoted context omitted.

I believe that is the generalisable version of the attack. You're not looking to learn the sound of arbitrary keyboards with this attack, rather you're looking to learn the sound of specific targets. For example, a Twitch streamer enters responses into their stream-chat with a live mic. Later, the streamer enters their Twitch password. Someone employing this technique could reasonably be able to learn the audio from…

Finally, a real security weakness to cite when making fun of people for their mechanical keyboard. Time to start recording the audio of Zoom calls with some particularly loud typers...

It’s so fascinating to watch this play out live. Once again, an ambitious kid can implement software hacks that are very funny when used for a joke, but also have massive real-world implications.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#197
post #158

Earlier quoted context omitted.

[insert yubikey plug] I don't use one but I know people who swear by them. Also this is an extremely obvious result. Typing is obviously a form of "penmanship", it was well known that telegraph operators could identify each other by how they tapped out Morse code in the 1800s. People have been able to do this based upon key stroke latency and even identify people based on habitual mouse patterns for decades. Audio re…

You sound confident enough that'd I'd like to see you show that off :P.

sounds like a good exercise although it'll literally just be for my own personal amusement. Nobody actually cares about this unless you've got some institutional clout which I do not. Praise for the PhD would be ridicule for you and me.

But really, should be fun ... the laptop dock mic will be great for this. If it's external you're in trouble ... but the researchers just used the onboard so it'll be fine.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#198
post #181

Earlier quoted context omitted.

Seems simple to defend - use a password manager.

until you have to type your password to unlock it

your password manager hopefully uses an additional factor to enable it on a new device, so definitely avoid typing that in on Twitch

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#199
post #47

Some systems have a setting to disable touchpad for x milliseconds after a key press. Do we need something similar for microphones too?

Users will do anything and everything for not getting rid of using FOSS which doesn't spy against a user by definition.
Post reply on HN