Live data from Hacker News

Exploiting a Bug in Google's Glass

saurik.com

31–32 of 32 posts

Re: Exploiting a Bug in Google's Glass

#31
post #11
post #9

While the first part of this article couldn't decide whether it was directed toward technical or non-technical audience, second part about security implications of such an easy way to get root was definitely thought-provoking. While I was super-eager to get Glass before, it really got me wondering if having camera and microphone in your glasses is such an great idea after all.

Yes it's a great idea. Microphones are already a standard part of widely accepted headphones/headsets. Cameras aren't as accepted yet but they will be, whether that's in 2015 or 2025 is the 64 billion dollar question.

Well, I'm glad you have the answer :P

I agree with your statement that cameras will be accepted in the future, but I'm not sure it follows that it's a great idea.

On the other hand, I'm not even convinced cellphones and facebook are great ideas, so my life is probably not representative. (Now get off my lawn.)

Re: Exploiting a Bug in Google's Glass

#32
post #16

Earlier quoted context omitted.

> from audio recordings of known keyboard keys clicking Neat. http://dl.acm.org/citation.cfm?id=1102169 "We present a novel attack taking as input a 10-minute sound recording of a user typing English text using a keyboard, and then recovering up to 96% of typed characters. There is no need for a labeled training recording. Moreover the recognizer bootstrapped this way can even recognize random text such as passwords.…

Thanks for sourcing my statement. I was worried for a minute that I'd misremembered it. (I'm also glad that's a word!)

Also, this is worth mentioning as a related attack:

http://static.usenix.org/events/sec06/tech/shah/shah_html/jb...

"In particular, we show a practical Keyboard JitterBug that solves the data exfiltration problem for keystroke loggers by leaking captured passwords through small variations in the precise times at which keyboard events are delivered to the host. Whenever an interactive communication application (such as SSH, Telnet, instant messaging, etc) is running, a receiver monitoring the host's network traffic can recover the leaked data, even when the session or link is encrypted."

Post reply on HN