Live data from Hacker News

Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

bleepingcomputer.com

61–70 of 94 posts

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#61

> THERMANATOR - The hottest attack of the summer! Coming soon to a computer near you! Are our jobs really this dull that we have to give our projects stupid hollywood names

Clearly the naming is wrong anyway - while the terminator saw in monochrome (infra?)red, thermal vision surely points to Predator, not The Terminator...

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#63

How is it 2018 and I can enable 2-factor auth on Twitter but not where I withdraw money from my bank account?

Is an ATM card and PIN not two factors?

GP probably wants an excuse to use their expensive yubikey.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#64
post #56

Earlier quoted context omitted.

It seems like a limitation of this attack is that you must have the camera pointed at the keys ~1 minute from the last time it was used. (Presumably because the heat dissipates quite quickly.) With that in mind a TOTP solution probably won't help, most systems that use 2FA will allow two adjacent codes to be considered valid to cope with "minor" clock-drift. If you're already using the computer 1 minute after the rea…

Allowing adjacent codes and accepting the same code twice is not the same. I would be surprised if TOTP allowed for accepting the same code twice.

I wouldn't be surprised... Seeing how bad we generally are at infosec. But it'd definitely be against a sane totp spec to allow a "one time pass" more than once.

In general you should store the most recently accepted counter (or epoch timestamp) and never allow travel back in time. That allows for clock drift, if the time between authentication attempts is less than the otherwise accepted drift.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#67
post #36
post #35

True story: A friend who was a heavy smoker asked me to fix his computer. I went to his house and saw the beige desktop and CRT were stained tobacco brown from second hand smoke. After fixing his "screen's all blurry" problem with some Windex I was ready to go in and see what kind of spyware and viruses he had managed to install on the machine. I was about to ask for his password when I noticed the only spots not cov…

Isn't Windex bad for computer screens? https://news.ycombinator.com/item?id=17416298 says "no Windex, as tempting as it might be!"

> CRT

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#68

How is it 2018 and I can enable 2-factor auth on Twitter but not where I withdraw money from my bank account?

Is an ATM card and PIN not two factors?

I can wire my entire bank account away without any 2FA with online banking. My bank just started doing SMS verification for new devices but that's still not really enough. Like just get on the TOPT train and leave it alone.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#69
post #46

I like how this exact attack is used in the Splinter Cell games.

I knew I saw this somewhere! I wonder what other security issues / lessons I internalized from that game...

Don't have open man-sized vents lead into your SCIF?

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#70
post #68

Earlier quoted context omitted.

Is an ATM card and PIN not two factors?

I can wire my entire bank account away without any 2FA with online banking. My bank just started doing SMS verification for new devices but that's still not really enough. Like just get on the TOPT train and leave it alone.

Not even a TAN?
Post reply on HN