Keyboard Attack “Thermanator” Steals Your Passwords Using Body Heat - TechnoExploit

Breaking

Post Top Ad

Post Top Ad

Saturday, July 7, 2018

Keyboard Attack “Thermanator” Steals Your Passwords Using Body Heat


            Remember the movie “Mission Impossible” where the protagonist, Tom Cruise bypassed a security system using body heat signatures left on the keyboard? Well, that is actually happening in 2018.


A new attack discovered by a group of researchers let hackers steal your passwords by recording thermal residue left on the keyboard after you walk away from it.

The researchers based out of the University of California, Irvine (UCI) concluded that entire password could be recovered within a time span of 30 seconds of the first key being entered using a thermal imagining camera. And partial keywords can be retrieved in under one minute.

According to the published report “Thermanator,” the researchers attached a FLIR thermal imagining camera 25 inches away from the four standard PC keyboards by Dell, HP, AZiO Prism KB507 and Logitech. The UCI team say that the Thermanator attack can be used to recover verification codes, ATM pins, and even long strings of text.

The “hunt and peck” typists (pressing each key individually while looking at the keyboard are more vulnerable to password stealing since they take longer completion times, which leaves longer time for keycaps to cool off before recording begins.



The Thermanator attacks will soon become reality as the thermal imagining camera will become more and more affordable in the future. At present, FLIR cameras range from $100,000 to $400, and lower end ones can be attached to any Android smartphone.

Resource: https://arxiv.org/pdf/1806.10189.pdf

Also Read: Cyber Advisory | Information Leakage Due To Huawei’s Weak Algorithm Vulnerabilities

No comments:

Post a Comment

Post Top Ad