Live data from Hacker News

Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

bleepingcomputer.com

51–60 of 94 posts

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#51

Earlier quoted context omitted.

One can easily attach a long tele lens to one of these cameras, so one could capture passwords through windows. Specialized IR lenses are expensive, but regular lenses can do a good enough job. Edit: my bad IR doesn't go through most glass material. Still, laptops are commonly used in public, and through lenses or otherwise, your password can be leaked. That's worrying enough to stop the "physical access means total…

Good IR tele lenses are not just expensive, the don't even have prices, they have "phone numbers". So you would have to get money from really a lot of people just to pay they IR camera and the lenses.

https://www.amazon.com/Fluke-FLK-LENS-4XTELE2-4X-Telephoto-T...

Basically double that of high end SLR lenses.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#52

I thought I read about this thing a long time ago, maybe on Brian Krebs' blog (?) but I can't find it. It was in the context of ATMs but the idea seems the same. All I can find at the moment, also on ATMs, is this from last year: https://www.albany.edu/iasymposium/proceedings/2017/Study%20... EDIT: That paper is actually cited in this work. They don't discuss the novelty of their approach compared to this though. Jus…

I always heard you should type your PIN at the ATM, then touch all of the buttons a bunch to block this ability. That way they only see that all the buttons were touched, not your PIN. Especially important now that thermal cameras (crappy ones) are pretty cheap.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#53

> THERMANATOR - The hottest attack of the summer! Coming soon to a computer near you! Are our jobs really this dull that we have to give our projects stupid hollywood names

Makes me wonder about the variable names.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#54

Earlier quoted context omitted.

This is a fairly well known attack on ATMs with plastic keys, but last I heard metal keys make it nearly impossible to carry out.

Yeah metal reflects thermal IR like a mirror.

It also generates IR by itself. It wouldn't be a big problem to carry out the attack, as long as the keypad isn't reflecting any strong IR source towards the camera.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#55
post #17

at first, this seems completely harmless, but there are a few scenarios in which this could potentially be a viable attack. I doubt it's much use on computers, but imagine someone rigging a candid infrared camera across the street from an ATM. You'd block the cameras view while typing, but then you leave and it's game over.

This is a fairly well known attack on ATMs with plastic keys, but last I heard metal keys make it nearly impossible to carry out.

Whenever possible I type in the PIN with a house key or car key. That way there's little, if not none at all, heat left behind and I don't have to contact a germ-laden touchpad. #germaphobe

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#56

Earlier quoted context omitted.

Indefensible is debatable. It can be defeated using any of the major 2FA mechanisms (FIDO U2F, HOTP/TOTP come to mind).

It seems like a limitation of this attack is that you must have the camera pointed at the keys ~1 minute from the last time it was used. (Presumably because the heat dissipates quite quickly.) With that in mind a TOTP solution probably won't help, most systems that use 2FA will allow two adjacent codes to be considered valid to cope with "minor" clock-drift. If you're already using the computer 1 minute after the rea…

Allowing adjacent codes and accepting the same code twice is not the same. I would be surprised if TOTP allowed for accepting the same code twice.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#58

I thought I read about this thing a long time ago, maybe on Brian Krebs' blog (?) but I can't find it. It was in the context of ATMs but the idea seems the same. All I can find at the moment, also on ATMs, is this from last year: https://www.albany.edu/iasymposium/proceedings/2017/Study%20... EDIT: That paper is actually cited in this work. They don't discuss the novelty of their approach compared to this though. Jus…

I always heard you should type your PIN at the ATM, then touch all of the buttons a bunch to block this ability. That way they only see that all the buttons were touched, not your PIN. Especially important now that thermal cameras (crappy ones) are pretty cheap.

Why should I care? It's the bank's responsibility to secure their equipment and refund any dollars stolen from me.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#59
I tried this using a flir one on my iPhone.

https://youtu.be/IMxZQ922rLs

Sorry, it sounds like a really good idea, but it just doesn't work very well in practise.

The users fingers don't sit on the keys long enough to transfer enough heat to last. Just use a standard video camera if this is your thing.

Post reply on HN