Live data from Hacker News

Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

bleepingcomputer.com

71–80 of 94 posts

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#71
> The research team argues that it may be time to move away from passwords as a means to secure user data and equipment.

Many people have expressed this sentiment. By all means we should be using two-factor authentication everywhere. But what, besides a password, has the critical property of residing entirely within your mind and not being obtainable without your cooperation (barring issues like this)?

Physical tokens can be stolen. Biometrics can be obtained and forged, or physically coerced. Authenticating via a secondary device (such as a phone) just moves the problem to "how do you authenticate to that device".

On the other hand, if you ever type in your password in a place where someone can record you, someone could figure out your password, or at least get enough information to make it easier to brute-force your password.

Short of a challenge-response scheme that you can compute entirely within your mind without scratch materials, what could we use that would address both problems? Something that can't simply be stolen or used without your cooperation, but that also isn't potentially disclosed in reusable form every time you use it?

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#72
Former NASA engineer turned YouTube science fun guy Mark Rober explained this attack in 2014 https://www.youtube.com/watch?v=8Vc-69M-UWk

and references this 2011 UCSD paper Heat of the moment: characterizing the efficacy of thermal camera-based attacks

https://dl.acm.org/citation.cfm?id=2028058

So not sure what the Thermanator folks are adding here...

EDIT: Thermanator paper cites the UCSD research, focuses on qwerty keyboards, updated technology for thermal cameras, comparisons to other attack vectors for public password entry (when you are at coffee shop, airport, ATM etc.).

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#73
post #68

Earlier quoted context omitted.

Is an ATM card and PIN not two factors?

I can wire my entire bank account away without any 2FA with online banking. My bank just started doing SMS verification for new devices but that's still not really enough. Like just get on the TOPT train and leave it alone.

I believe some banks have 2FA. My bank's app will require me to setup SMS verification by October. A little late, but better than never I guess

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#74

> The research team argues that it may be time to move away from passwords as a means to secure user data and equipment. Many people have expressed this sentiment. By all means we should be using two-factor authentication everywhere. But what, besides a password, has the critical property of residing entirely within your mind and not being obtainable without your cooperation (barring issues like this)? Physical token…

Yeah, and you can't rotate your fingerprints or retinal scans.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#75

How is it 2018 and I can enable 2-factor auth on Twitter but not where I withdraw money from my bank account?

Is an ATM card and PIN not two factors?

Yes. I didn't really consider that. I was thinking more along the lines of an expiring token. If you had to punch it in, someone who came around and Thermanator'd it would always be too late.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#76
I've always thought you could predict the characters in a password by looking at the oil/polish on the keycaps.

I always figured this could be an attack someday. But didn't know the tech was cheap enough/sensitive enough yet. I need to start being more paranoid.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#77

I've always thought you could predict the characters in a password by looking at the oil/polish on the keycaps. I always figured this could be an attack someday. But didn't know the tech was cheap enough/sensitive enough yet. I need to start being more paranoid.

Which is why keeping your keyboards wiped down (I use baby wipes) isn't just for compulsives.

It's a hygiene and security best practice.

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#78

> The research team argues that it may be time to move away from passwords as a means to secure user data and equipment. Many people have expressed this sentiment. By all means we should be using two-factor authentication everywhere. But what, besides a password, has the critical property of residing entirely within your mind and not being obtainable without your cooperation (barring issues like this)? Physical token…

Yeah, and you can't rotate your fingerprints or retinal scans.

Would holding your finger upside down on the scanner work?

(Nope. My Nexus 5X unlocks no matter the orientation of my finger)

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#79

Earlier quoted context omitted.

I knew I saw this somewhere! I wonder what other security issues / lessons I internalized from that game...

Don't have open man-sized vents lead into your SCIF?

Until now I never even questioned why there would be man-sized vents in every bulding

Re: Thermanator Attack Steals Passwords by Reading Thermal Residue on Keyboards

#80
post #77

I've always thought you could predict the characters in a password by looking at the oil/polish on the keycaps. I always figured this could be an attack someday. But didn't know the tech was cheap enough/sensitive enough yet. I need to start being more paranoid.

Which is why keeping your keyboards wiped down (I use baby wipes) isn't just for compulsives. It's a hygiene and security best practice.

The oils on my fingers attack the print on my keyboard. After a few years the "home row" is very faded. Fortunately my password is not something I type enough other things that you can figure out passwords out based on this.
Post reply on HN