Live data from Hacker News

Scary AI recognizes passwords by the sound of your typing

pcworld.com

21–28 of 28 posts

Re: Scary AI recognizes passwords by the sound of your typing

#23
post #10

Earlier quoted context omitted.

My 2FA OTPs are synced by 1Password which I can access from any of my devices; you can set up something similar with FOSS if you want full control. Authenticating to 1Password requires both a master password and a secret key; they have a feature called "Emergency Kit" for creating offline backups of the key ( https://support.1password.com/emergency-kit/ )

Using a password manager introduces a single point of failure. My biometrics are leaked every time I post a selfie or a picture of myself holding something. The idea of something like an "emergency kit" being extant for something I care about makes my skin crawl. They say you should put it in you cloud storage!!! What the actual fuck. The only points of vulnerability in the chain for the things I have passwords on is…

I have about 300 logins and my memory ain't so good after too many hits to the ol' noodle. You don't expect me to remember all of those without a password manager? I'm much more worried about the SPOF inside my skull.

Re: Scary AI recognizes passwords by the sound of your typing

#24
post #7

I read about this in the Silence on the Wire by Michal Zalewski. And you don't need a fullblown AI, a good statistical model is enough to make a guess on passwords, and if you have a bunch of probabilities to cut down your search space to a more probable set. And the book is from 2005, so I wouldn't say it is new. https://nostarch.com/silence.htm I even remember reading about how Clifford Stoll recognized the differe…

Earliest reference I know is to a TLA bugging plaintext teletype printers in The Hacker's Handbook, Hugo Cornwall, 1985.

Re: Scary AI recognizes passwords by the sound of your typing

#25

Earlier quoted context omitted.

2FA is password (something you know) and device (something that you have). You have to enter the password to use 2FA. Are you thinking of password manager? Most password managers involve entering the master password. Some can open with fingerprint but need to use the password occasionally. Are you thinking about passkeys? Those aren’t 2FA.

I suspect he's thinking of just straight up using an authenticator instead of a password, which i should remind people is 1FA.

I was thinking Password manager + TOTP or yubikey.

Of course it does also have downsides. I don’t store all my passwords there.

Re: Scary AI recognizes passwords by the sound of your typing

#26

Don’t type passwords. Use 2FA whenever possible

No thanks, I'd rather keep my secrets unbound from any physical object.

Certain crucial passwords can be kept in the memory. There are thousands of menial logins though and a password manager might be more reliable than the memory

Re: Scary AI recognizes passwords by the sound of your typing

#27
post #23

Earlier quoted context omitted.

Using a password manager introduces a single point of failure. My biometrics are leaked every time I post a selfie or a picture of myself holding something. The idea of something like an "emergency kit" being extant for something I care about makes my skin crawl. They say you should put it in you cloud storage!!! What the actual fuck. The only points of vulnerability in the chain for the things I have passwords on is…

I have about 300 logins and my memory ain't so good after too many hits to the ol' noodle. You don't expect me to remember all of those without a password manager? I'm much more worried about the SPOF inside my skull.

Oh, yeah well that makes sense. I only have to remember something like 20. SaaS is bad and you shouldn't use it but I guess if you have to then them's the brakes kid.
Post reply on HN