Earlier quoted context omitted.
Never use public wifi. I don't.
That is a large cost to pay.
Inferring Your Mobile Phone Password via WiFi Signals
31–40 of 69 posts
Re: Inferring Your Mobile Phone Password via WiFi Signals
#32Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?
Re: Inferring Your Mobile Phone Password via WiFi Signals
#33Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?
Never use public wifi. I don't.
Re: Inferring Your Mobile Phone Password via WiFi Signals
#34Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?
Or scramble the numeric keypad on every try, but that would get annoying fast.
Another strategy I've seen is to ask some random digits of a longer PIN, with a mask to fill out.
Re: Inferring Your Mobile Phone Password via WiFi Signals
#35Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?
Or scramble the numeric keypad on every try, but that would get annoying fast.
Re: Inferring Your Mobile Phone Password via WiFi Signals
#36Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?
Also: "We collected training and testing data from 10 volunteers." Not a statistically useful sample set.
Under very controlled environments, measuring signal deltas may be possible- but I would like to see sample data that suggests high success rates before I think this is worthy of concern.
Finally- Self tuning antennas are a thing. This is going to get harder over time. https://www.qualcomm.com/videos/qualcomm-rf360-dynamic-anten...
Re: Inferring Your Mobile Phone Password via WiFi Signals
#37Earlier quoted context omitted.
That is a large cost to pay.
It isn't really. Mobile data is a must from a security point of view. Combine it with a VPN and you have your out and about internet access sorted.
Re: Inferring Your Mobile Phone Password via WiFi Signals
#38Re: Inferring Your Mobile Phone Password via WiFi Signals
#39Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?
Or scramble the numeric keypad on every try, but that would get annoying fast.
Some security features I can recall.
Random layout of the numbers on both the button itself and which button has which number. This is shuffled on every click.
Upon clicking all numbers and the mouse pointer vanish. This prevents screenshots taken on clicks by some keyloggers from working.
No keyboard input. Annoying but needed to combat keyloggers.
http://vignette2.wikia.nocookie.net/2007scape/images/c/c3/Ba...
Re: Inferring Your Mobile Phone Password via WiFi Signals
#40Earlier quoted context omitted.
Never use public wifi. I don't.
As far as I understood, this attack vector has nothing to do with using public wifi.
Without this information, it is difficult to determine if the user is inputting a password. In addition, if we know the user is using the bank of america app, and we know that the app uses a specific key lay out, it becomes a lot easier to figure out what keys they are pressing.
There is no reason that the other technique they discussed, which does not require the target to connect to a specific wifi hotspot, could not be improved though.