So they generated training data from one laptop and microphone then generated test data with the exact same laptop and microphone in the same setup, possibly one person pressing the keys too. For the Zoom model they trained a new model with data gathered from Zoom. They call it a practical side channel attack but they didnt do anything to see if this approach could generalize at all
I believe that is the generalisable version of the attack. You're not looking to learn the sound of arbitrary keyboards with this attack, rather you're looking to learn the sound of specific targets. For example, a Twitch streamer enters responses into their stream-chat with a live mic. Later, the streamer enters their Twitch password. Someone employing this technique could reasonably be able to learn the audio from…
New acoustic attack steals data from keystrokes with 95% accuracy
141–150 of 239 posts
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#142So microphones need to get muted automatically by password prompts, seems simple enough in principle.
This topic has me wondering though if it's possible to detect finger positioning or for that matter screen information from the reflection off the typist's eyeballs/eyeglasses shown in a webcam, or perhaps even if possible in principle, in practice most webcam resolution is simply too poor for that.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#143Earlier quoted context omitted.
I believe that is the generalisable version of the attack. You're not looking to learn the sound of arbitrary keyboards with this attack, rather you're looking to learn the sound of specific targets. For example, a Twitch streamer enters responses into their stream-chat with a live mic. Later, the streamer enters their Twitch password. Someone employing this technique could reasonably be able to learn the audio from…
Finally, a real security weakness to cite when making fun of people for their mechanical keyboard. Time to start recording the audio of Zoom calls with some particularly loud typers...
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#144Earlier quoted context omitted.
Brilliant suggestion. Have a TRNG or a CSPRNG (if too poor for a TRNG) choose the next layout at random for you, ideally with every keystroke. Good luck cracking that!
Could be done by using a device with a display - e.g. an "ereader" - to present a random keyboard layout. But, good luck being efficient typing on that. At that point, better use a different input model. Or, use techniques such as those in the article, such as random keypresses played during the actual ones.
I'm sure customer frustration was huge.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#145Re: New acoustic attack steals data from keystrokes with 95% accuracy
#146Oh cool, so it's time to learn Dvorak or other keyboard setups.
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#147So they generated training data from one laptop and microphone then generated test data with the exact same laptop and microphone in the same setup, possibly one person pressing the keys too. For the Zoom model they trained a new model with data gathered from Zoom. They call it a practical side channel attack but they didnt do anything to see if this approach could generalize at all
Re: New acoustic attack steals data from keystrokes with 95% accuracy
#148Re: New acoustic attack steals data from keystrokes with 95% accuracy
#149Re: New acoustic attack steals data from keystrokes with 95% accuracy
#150Oh cool, so it's time to learn Dvorak or other keyboard setups.