this post was submitted on 02 Dec 2023
439 points (95.6% liked)

Technology

59421 readers
5045 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Researchers in the UK claim to have translated the sound of laptop keystrokes into their corresponding letters with 95 percent accuracy in some cases.

That 95 percent figure was achieved with nothing but a nearby iPhone. Remote methods are just as dangerous: over Zoom, the accuracy of recorded keystrokes only dropped to 93 percent, while Skype calls were still 91.7 percent accurate.

In other words, this is a side channel attack with considerable accuracy, minimal technical requirements, and a ubiquitous data exfiltration point: Microphones, which are everywhere from our laptops, to our wrists, to the very rooms we work in.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 43 points 11 months ago (3 children)

Not to be a jerk, but is this actually new? I've heard of this being done at least ten years ago...

On another note, one way to beat this (to a degree) would be to use an alternate keyboard like Dvorak (though you could probably code it to be able to detect that based on what's being typed)

[–] [email protected] 24 points 11 months ago (2 children)

I think it's largely been a state actor thing. Directional microphone to record your window from across the street, spend significant tax money on crunching numbers on a supercomputer to get at your password kind of thing, I think they already could do it in the 90s. Real-time 95% accuracy on a non-specialised device is a quite different ballpark: Now every skiddie can do it.

[–] [email protected] 4 points 11 months ago (2 children)

Now every skiddie can do it.

And this is the real, serious problem. Most people are pretty unlikely to stop a state sponsored spy operation no matter how careful they are. It's barely worth worrying about unless you know for a fact you're being tapped and that you will be killed about it, and even if you do know this the state can pull some space age bullshit out of their asses that doesn't yet have a counter. Top secret military industrial research goes into maintaining that exact advantage every year, if they really want to get you, you will get got. But if Joey Dickbeater and his school friends can just point a mic at your window and then upload it to the Pass-o-Gram to decode it, you have a real problem. It's like when TikTok kids figured out they can steal Kias with usb keys - if every teenager in America knows how to steal your car, its lifetime is going to be measured in minutes. Same with passwords.

Sounds like it's time to buy a bunch of random cherry switches and randomize them across my keyboard.....

[–] [email protected] 2 points 11 months ago (1 children)

Sounds like it's time to buy a bunch of random cherry switches and randomize them across my keyboard.....

And rotate them. While I don't plan to waste my energy, having hot swap sockets and swapping a few around should thwart the attack. You would have to do it frequently enough that relevant training data gets wasted before it's useful. I'm pretty paranoid, but not that much.

I'll just consider it good security hygiene to get a new keyboard often :)

[–] [email protected] 1 points 11 months ago

Have you considered only re-doing the tinfoil wrapper every day? It should crackle differently every time.

[–] [email protected] 2 points 11 months ago

What it means is that NIST probably needs to update its security recommendations to require hardware keys for even low level systems. It's going to be a huge pain in the ass though.

[–] [email protected] 2 points 11 months ago

Gotcha, that makes more sense

[–] [email protected] 20 points 11 months ago (2 children)

Coding for alternate key mappings is almost as trivial as detecting other languages.

[–] [email protected] 8 points 11 months ago

Yeah, that's what I figured

[–] [email protected] 3 points 11 months ago

It's more trivial because it's a 1:1 relationship. A is a, s is o, d is e, and so on. Detecting other languages is harder because there's more of them and there isn't a 1:1 conversation to English.

[–] [email protected] 14 points 11 months ago (2 children)

There has been previous work on this, yes. It required a dictionary of suggested words. That would make it useful for snooping most typing, but not for randomly generated passwords. This new technique doesn't seem to have that limitation.

[–] [email protected] 2 points 11 months ago

Okay, gotcha. I didn't look that deeply into it previously so I never realized how limited that was

[–] [email protected] 1 points 11 months ago

So about those people that run around saying passphrases are better... 😅