Live data from Hacker News

Inferring Your Mobile Phone Password via WiFi Signals

fermatslibrary.com

61–69 of 69 posts

Re: Inferring Your Mobile Phone Password via WiFi Signals

#61

Earlier quoted context omitted.

It isn't really. Mobile data is a must from a security point of view. Combine it with a VPN and you have your out and about internet access sorted.

Mobile data is expensive and slower than WIFI. There is a reason people connect to a WIFI with their phones.

In many (most?) countries mobile data is cheaper than wired connections, but obviously with worse latency.

Slower too maybe, but we're long past the point it really matters, except for latency sensitive applications. 50+ Mbps is just plenty for most applications.

Only real need of wifi to save some battery power and maybe to get better latency and jitter for VoIP and interactive applications.

AFAIK, US and UK are still pretty bad. I guess they have to limit bandwidth and data volume to be able to, ahem, listen to their customer.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#62
post #53

I like this Fermat thing but it would be cooler if it could add a date to the papers who, for some reason, do not have a date.

Following DOI: http://dx.doi.org/10.1145/2976749.2978397 we find the paper was presented in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.

Date: 2016-10-24

Re: Inferring Your Mobile Phone Password via WiFi Signals

#63
post #60
post #4

Holy shit. From a brief scan it looks like the paper concentrates on recovering a numeric pin, but these attacks never get worse, only better, so I assume full keyboard access is not too far off. What's the defense? Have your phone manage the passwords and unlock via fingerprint?

Touch typing? Should present significantly different to one finger key hunting. Fingerprints and never using public WiFi would both be good strategies. (I use my fingerprint to log into my banking app when on mobile.)

Touch typing on a flat, featureless surface? Best of luck with that. I tried, and tended to drift off-center within a few tens of keystrokes. The F and J nubs on physical keyboard are there for Good Reasons - but even without, feeling where exactly you are striking the key (center or corner) gives you feedback to reposition. Touchscreen gives you nothing.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#65
post #61

Earlier quoted context omitted.

Mobile data is expensive and slower than WIFI. There is a reason people connect to a WIFI with their phones.

In many (most?) countries mobile data is cheaper than wired connections, but obviously with worse latency. Slower too maybe, but we're long past the point it really matters, except for latency sensitive applications. 50+ Mbps is just plenty for most applications. Only real need of wifi to save some battery power and maybe to get better latency and jitter for VoIP and interactive applications. AFAIK, US and UK are sti…

> mobile data is cheaper than wired connections

In which countries is that true? Certainly not any that I visit.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#66
post #48

Earlier quoted context omitted.

How is a VPN on mobile data safer than a VPN on public internet? Also, what safety does a VPN add if you are already using https?

The process of connecting to public wifi is risk. Most public wifi networks have a landing page that you have to click through before proceeding/granting you access. That page could have a malicious script. Last year after a trip in Germany, my older iPhone had a random password saved in Safari settings. On top of that, every time I tried to delete the password, it would reappear when I went back (iCloud sync was off…

Do you browse the web expecting sites not to have malicious scripts?

Re: Inferring Your Mobile Phone Password via WiFi Signals

#67
post #48

Earlier quoted context omitted.

The process of connecting to public wifi is risk. Most public wifi networks have a landing page that you have to click through before proceeding/granting you access. That page could have a malicious script. Last year after a trip in Germany, my older iPhone had a random password saved in Safari settings. On top of that, every time I tried to delete the password, it would reappear when I went back (iCloud sync was off…

Do you browse the web expecting sites not to have malicious scripts?

For my use case, I hope so.

I generally don't browse on my phone, so if I'm opening up Safari on a public network, it's to a known site or bookmark to quickly reference something (e.g. transit map, exchange rate). It's totally possible an ad on the NYT or Bloomberg has some malicious Javascript, but currently I'm naively assuming otherwise.

Also, I think many people on their phones will connect to a public hotspot just to check Facebook / Instagram / Snapchat these days and not much else.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#68

Earlier quoted context omitted.

So then its probably a pretty good idea to randomize the number keypad for the lock screen, which I do. Does this defeat that, I can't think of a way it does..

The paper focused on an attack against a payment system, not the lock screen, so you'd need to randomize every password input keyboard at the system level. Probably not a bad idea...

Another option would be to use thumbprints for all authorizations after the device is unlocked.

Re: Inferring Your Mobile Phone Password via WiFi Signals

#69
post #60

Earlier quoted context omitted.

Touch typing? Should present significantly different to one finger key hunting. Fingerprints and never using public WiFi would both be good strategies. (I use my fingerprint to log into my banking app when on mobile.)

Touch typing on a flat, featureless surface? Best of luck with that. I tried, and tended to drift off-center within a few tens of keystrokes. The F and J nubs on physical keyboard are there for Good Reasons - but even without, feeling where exactly you are striking the key (center or corner) gives you feedback to reposition. Touchscreen gives you nothing.

Ah, you're completely right - for some reason I had it in my head it was about laptops. Even the title was a big reveal.. Oh well.
Post reply on HN