Live data from Hacker News

Inferring Your Mobile Phone Password via WiFi Signals

fermatslibrary.com

41–50 of 69 posts

Re: Inferring Your Mobile Phone Password via WiFi Signals

#41

Read the section "limitations". Only works on 10 users right now, must be trained for the pattern "per user", phone must be sitting on stable surface, gesture must be performed as close to "the same" every time. This is just clickbait and "please fund our research" IMO.

What did you expect — a turn-key solution for sale? They claim no such thing.

This is great research. They've demonstrated that it is in fact possible to obtain a passcode at a distance, at least in contrived conditions. The fact it's possible whatsoever is a significant result. Even without being able to obtain the exact passcode, this would yield the ability to guess a passcode in much better time than just random selection.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#42
post #4

Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?

Well if one modifies the channel state information in an unpredictable manner while performing sensitive operations, it becomes very difficult to extract any information. The simplest way to do this might be to fidget. Use one hand to type and another hand to fidget with something.

A more high tech method would be to use a modulated wifi reflector that is randomly modulated.

One should also watch out for wifi hotspots with ominously pointed directional antenna

Re: Inferring Your Mobile Phone Password via WiFi Signals

#43

Read the section "limitations". Only works on 10 users right now, must be trained for the pattern "per user", phone must be sitting on stable surface, gesture must be performed as close to "the same" every time. This is just clickbait and "please fund our research" IMO.

Throw in the fact that mobile phones adjust their radio power output based on battery and AP signal strength and any signal strength measurements become completely unreliable

Re: Inferring Your Mobile Phone Password via WiFi Signals

#44

Read the section "limitations". Only works on 10 users right now, must be trained for the pattern "per user", phone must be sitting on stable surface, gesture must be performed as close to "the same" every time. This is just clickbait and "please fund our research" IMO.

Remember: Attacks never get worse, only better. What you've read is the new lower bound of what's possible.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#46

Earlier quoted context omitted.

That is a large cost to pay.

It isn't really. Mobile data is a must from a security point of view. Combine it with a VPN and you have your out and about internet access sorted.

How is a VPN on mobile data safer than a VPN on public internet?

Also, what safety does a VPN add if you are already using https?

Re: Inferring Your Mobile Phone Password via WiFi Signals

#48

Earlier quoted context omitted.

It isn't really. Mobile data is a must from a security point of view. Combine it with a VPN and you have your out and about internet access sorted.

How is a VPN on mobile data safer than a VPN on public internet? Also, what safety does a VPN add if you are already using https?

The process of connecting to public wifi is risk. Most public wifi networks have a landing page that you have to click through before proceeding/granting you access. That page could have a malicious script.

Last year after a trip in Germany, my older iPhone had a random password saved in Safari settings. On top of that, every time I tried to delete the password, it would reappear when I went back (iCloud sync was off, etc.). I don't remember browsing anything out of the ordinary, but did connect to a bunch of public wifi spots. Here's to hoping it was just a really persistent ad-tracking method.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#49

Earlier quoted context omitted.

It isn't really. Mobile data is a must from a security point of view. Combine it with a VPN and you have your out and about internet access sorted.

How is a VPN on mobile data safer than a VPN on public internet? Also, what safety does a VPN add if you are already using https?

For the second one, I believe you can still ID what sites a user is likely using if you're in the middle, regardless of https, via eg reverse IP lookups- just not what they're sending to that site. A VPN covers that.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#50
post #4

Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?

Never use public wifi. I don't.

If you want to be really secure, just never use the internet.
Post reply on HN