Live data from Hacker News

Hackers backdoor the human brain, successfully extract sensitive data

extremetech.com

41–50 of 70 posts

Re: Hackers backdoor the human brain, successfully extract sensitive data

#42
post #29
post #26

Earlier quoted context omitted.

> I realised that, though I was typing the digits of the new PIN, I was subvocalising the digits of my old PIN. I trained myself to do this on purpose; subvocalising a different number. If I'm drugged out in a hospital bed and someone asks for my CC PIN, I want them to get an incorrect number.

Well that took a turn... Do you also by chance drink poison every day to build immunity for when that vicious lad taps your drink?

Yes - If he tries to poison me with caffeine, I'm pretty safe.

I'm not genuinely worried about being robbed of my PIN, though. I just found the mental challenge interesting.

Re: Hackers backdoor the human brain, successfully extract sensitive data

#43

This is an awfully contrived title for an article that could be summarized as "people can find out whether or not you recognize something shown to you by monitoring electrical activity along the scalp."

If you manage to hack out a list of all 4-digit numbers that you recognize, it's trivial to bruteforce which of those numbers are for your cards or for some other security PINs.

Also, it has other practical uses - think of it as a better-than-polygraph test for questions of type "have you seen this person" or "does this account-password belong to you".

Re: Hackers backdoor the human brain, successfully extract sensitive data

#44
post #18

Sensationalist title designed to gain unjustified views. Accurate title would be "$200-$300 buys you an off the shelf polygraph test". Same principles, this has been known as a "lie detector" test for years.. and it's defeatable..

It seems completely different than a lie detector. Classic polygraphs, in essence, measure stress-responses. This measures [success of] pattern recognition. You can't use it for many yes/no lie-detector questions, however, it has a potential to be much more accurate (and less spoofable) for questions like "Do you remember this face?" or "Have you seen 'ox9j$lkjew' before ? It's a password to a child-porn site we found on your computer - wondering if you have used it.."

Re: Hackers backdoor the human brain, successfully extract sensitive data

#45

Neat idea. The debit card pin bit does not seem feasible though, at least in a brute force setting - finding out a 6 digit pin, showing each number for 1 second, takes > 11 days in the worst case.

Couldn't you just do one digit at a time (is your first digit 1?, etc)? It would take less than a minute at 1 second per digit that way.

No, since all isolated digits would have similar responses. The attack vector is not "is x your PIN?" but it's "is pattern xyzw meaningful to your brain whatsoever?"

Re: Hackers backdoor the human brain, successfully extract sensitive data

#46
post #8

Earlier quoted context omitted.

Don't most people have a 4 digit pin? But in any case showing pins that way wouldn't work anyway - most people have a muscle memory for their pins, but would not recognize them when written down.

You also forgot to mention multiple cards and pins people have / used to have. I'd expect a false trigger in the system in that case.

You get a bunch of positives and check/bruteforce afterwards. This system couldn't distinguish my creditcard PIN from my office alarm PIN code, but it can give a shortlist to try.

Re: Hackers backdoor the human brain, successfully extract sensitive data

#48

This is an awfully contrived title for an article that could be summarized as "people can find out whether or not you recognize something shown to you by monitoring electrical activity along the scalp."

If you manage to hack out a list of all 4-digit numbers that you recognize, it's trivial to bruteforce which of those numbers are for your cards or for some other security PINs. Also, it has other practical uses - think of it as a better-than-polygraph test for questions of type "have you seen this person" or "does this account-password belong to you".

These articles are funny, coming up with all the negative possibilities of future technology. Elysium (new movie) showed another one, allowing a full download of people's brains, also to ill effect.

I can't wait until this technology is improved, so I can "search" my own brain to find all the stuff I seem to forget. I'm sure it's locked in my unconscious somewhere...

Re: Hackers backdoor the human brain, successfully extract sensitive data

#49

This relies on an unsuspecting victim wearing a complicated nonstandard headset and then looking at a series of images / numbers slowly enough to register each of them consciously. In what world would the victim not become suspicious? (I appreciate things may change in the future, and if brain control headsets become common then a malware model (ad popups, for example) could provide a plausible vector for this attack…

Think of it as a successor to the $5 wrench attack.

Re: Hackers backdoor the human brain, successfully extract sensitive data

#50
Wow I wasn't aware that EEGs are this cheap. Does anyone know how well these 200-300$ thingies play with Linux and how easy it is to hack around with them generally?

I'd love to log my brain activities while learning, reading or playing poker :D

Edit: Seems like the Emotive EPOC has an SDK that supports Linux and also an open source library called Emokit that was build from reverse engineering the device's communication :D

Post reply on HN