Live data from Hacker News

New acoustic attack steals data from keystrokes with 95% accuracy

bleepingcomputer.com

221–230 of 239 posts

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#221
There's a great scene in Le chant du Loup (The Wolf's Call) a French 2019 submarine flick (at one point on Netflix) where the sonar guy hears a password typed and reconstructs it from the sound of each keystroke.

https://youtu.be/a9Gz7Bg07u8

This attack is about as realistic as the film: a parallel universe where million to one chances happen nine times out of ten.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#222
post #167

Earlier quoted context omitted.

Finally, a real security weakness to cite when making fun of people for their mechanical keyboard. Time to start recording the audio of Zoom calls with some particularly loud typers...

I'll just have to add significantly more background clickity clacks as obfuscation.

My thought was to run psyops all the time.

"Just need to type in my password." He says a little too loudly to nobody. Then just type in the honeypot password and login with the real one that you entered with a virtual keyboard a few minutes ago.

Meanwhile you've got a prerecorded keyboard going concurrently that decodes to "I know what you're trying to do. Clever but not clever enough."

And I guess you might as well have a special keyboard that you only use for typing in passwords while you're at it.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#224
I wonder how hard this problem is. I bet it’s actually not that bad. If I were to guess, A huge part of the problem is likely the position of the microphone.

Note that the testing data in the confusion matrix appears to have a uniformish distribution of each key being pressed. I suspect this data was not generated by someone actually typing because you would rarely see numbers and rare letters. It is possible these were simply pressed one at a time rather than in a series of rapid presses.

My guess is this approach uses the mic to identify where the sound of the key press was coming from rather than what each key press sounds like. Which does not invalidate the results but may make it seem less magical. Tbh it’s probably much worse this way because such a model could probably generalize very well across all keyboards and typing styles.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#225
post #206

Earlier quoted context omitted.

But inconfortable for others. Surely you all know it bothers a good amount at least some of your colleagues, right?

Well, not everybody works in an open plan, a shared office, or in an office building.

Obviously the comment discusses a shared space. If you have your own room you can let your fart rips and sniff them for fun, pull out your dick and piss in a bottle for fun, clank on your loud toys for fun, all the things you should never do with other people around that you might find fun for whatever reason. No one cares. But don't do these things to other people around you, it's anti-social.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#226
post #140

Earlier quoted context omitted.

I'm guessing it would be easier (assuming you trained it on that keyboard), because each solenoid would be fairly unique due to manufacturing tolerances. Just my gut feeling, I have no data to back it up.

I know nothing about this keyboard, but I'd assume it just has one solenoid because the expense and space of 100+ solenoids is impractical if all you're using them for is simulating the vibration/sound of a typewriter.

I wish I could delete my comment to hide my stupidity. For some reason I was thinking about springs despite reading and typing solenoid. You are of course 100% correct and unfortunately it's too late for me to hide my shame.

Re: New acoustic attack steals data from keystrokes with 95% accuracy

#228

Earlier quoted context omitted.

potential solution: keep a few intentional typos in your passphrases. It also makes dictionary attacks much harder.

now you have to remember the the typos

Plus, if they can tell what the actual words would be, then brute forcing the typos is trivial
Post reply on HN