Live data from Hacker News

Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

bleepingcomputer.com

11–20 of 94 posts

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#11

If the adversary has the level of physical access required to pull this off you've already lost.

Exactly. If the adversary has a camera pointed at your keyboard, they can even possibly attempt the more radical (and indefensible) “I literally recorded what you typed” attack. Scary stuff.

I think the argument here is that, since it can happen 30s later, you could enter your password, look at the screen, lock your screen & walk away, without being safe. Imagine a location where the mobo itself is secure enough to prevent anyone from quickly inserting something, but anyone could have quick access to the keyboard & monitor.

In that (highly contrived) situation, this attack is useful, since all you'd need is a quick thermal pic, no longer recording needed.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#13
post #10

Earlier quoted context omitted.

One can easily attach a long tele lens to one of these cameras, so one could capture passwords through windows. Specialized IR lenses are expensive, but regular lenses can do a good enough job. Edit: my bad IR doesn't go through most glass material. Still, laptops are commonly used in public, and through lenses or otherwise, your password can be leaked. That's worrying enough to stop the "physical access means total…

Thermal cameras don't really work through glass

[deleted]

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#15
I thought I read about this thing a long time ago, maybe on Brian Krebs' blog (?) but I can't find it. It was in the context of ATMs but the idea seems the same. All I can find at the moment, also on ATMs, is this from last year:

https://www.albany.edu/iasymposium/proceedings/2017/Study%20...

EDIT: That paper is actually cited in this work. They don't discuss the novelty of their approach compared to this though. Just a bigger search space due to more keys?

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#16

Earlier quoted context omitted.

Exactly. If the adversary has a camera pointed at your keyboard, they can even possibly attempt the more radical (and indefensible) “I literally recorded what you typed” attack. Scary stuff.

Indefensible is debatable. It can be defeated using any of the major 2FA mechanisms (FIDO U2F, HOTP/TOTP come to mind).

It seems like a limitation of this attack is that you must have the camera pointed at the keys ~1 minute from the last time it was used. (Presumably because the heat dissipates quite quickly.)

With that in mind a TOTP solution probably won't help, most systems that use 2FA will allow two adjacent codes to be considered valid to cope with "minor" clock-drift. If you're already using the computer 1 minute after the real owner has left it is possible you could reuse any valid code - if you captured it.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#17
at first, this seems completely harmless, but there are a few scenarios in which this could potentially be a viable attack.

I doubt it's much use on computers, but imagine someone rigging a candid infrared camera across the street from an ATM. You'd block the cameras view while typing, but then you leave and it's game over.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#18

Earlier quoted context omitted.

Exactly. If the adversary has a camera pointed at your keyboard, they can even possibly attempt the more radical (and indefensible) “I literally recorded what you typed” attack. Scary stuff.

I think the argument here is that, since it can happen 30s later, you could enter your password, look at the screen, lock your screen & walk away, without being safe. Imagine a location where the mobo itself is secure enough to prevent anyone from quickly inserting something, but anyone could have quick access to the keyboard & monitor. In that (highly contrived) situation, this attack is useful, since all you'd need…

Keypads arem by far, the biggest target for this attack

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#19

Earlier quoted context omitted.

Indefensible is debatable. It can be defeated using any of the major 2FA mechanisms (FIDO U2F, HOTP/TOTP come to mind).

It seems like a limitation of this attack is that you must have the camera pointed at the keys ~1 minute from the last time it was used. (Presumably because the heat dissipates quite quickly.) With that in mind a TOTP solution probably won't help, most systems that use 2FA will allow two adjacent codes to be considered valid to cope with "minor" clock-drift. If you're already using the computer 1 minute after the rea…

>It seems like a limitation of this attack is that you must have the camera pointed at the keys ~1 minute from the last time it was used. (Presumably because the heat dissipates quite quickly.)

An attacker could just stick a camera into a dark corner of a room and have it run perpetually. Video exfiltration might be an issue but certainly not insurmountable.

RE: your second point: that's true, but the point of TOTPs is that they expire before they can realistically be guessed (assuming rate limiting on the TOTP server).

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#20
post #17

at first, this seems completely harmless, but there are a few scenarios in which this could potentially be a viable attack. I doubt it's much use on computers, but imagine someone rigging a candid infrared camera across the street from an ATM. You'd block the cameras view while typing, but then you leave and it's game over.

This is a fairly well known attack on ATMs with plastic keys, but last I heard metal keys make it nearly impossible to carry out.
Post reply on HN