Keyboard clicks can lead to security hacks

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Darth Fanboy
DUH! WINNING!
Posts: 11182
Joined: 2002-09-20 05:25am
Location: Mars, where I am a totally bitchin' rockstar.

Keyboard clicks can lead to security hacks

Post by Darth Fanboy »

Linky

Keyboard clicks can lead to security hacks
Last modified: September 14, 2005, 1:46 PM PDT
By Michael Kanellos
Staff Writer, CNET News.com


A new security vulnerability has been discovered: the clickety clack of the keyboard.

An audio recording of an individual's typing can be transposed into a transcript of what was typed, according to researchers with the University of California, Berkeley. The technique works because each key makes a distinct sound when hit, and users, who typically type about 300 characters a minute, leave enough time between keystrokes for a computer to isolate the individual sounds.

The researchers were able to take several 10-minute sound recordings of users typing at a keyboard, feed the audio into a computer, and use an algorithm to recover up to 96 percent of the characters entered.


The technique worked when music or cell phone ringing jangled in the background--and even on so-called quiet keyboards with off-the-shelf recording equipment.

While any sort of typed documents could be pilfered through this technique, the study underscores the vulnerability of passwords, said Doug Tygar, a UC Berkeley professor of computer science and information management, and a principal investigator of the study.

"Passwords are a mechanism for authentication that really need to be rethought," he said. "This is not an esoteric attack. It requires some knowledge of computer science, but it can be done using many components that are freely available...We used $10 microphones."

The work builds on research conducted by IBM's Dmitri Asonov and Rakesh Agrawal that showed how 80 percent of text typed could be recovered from keyboard recordings. Those experiments, however, were tightly controlled.

The results of their findings will be presented Nov. 10 at the Association for Computing Machinery Conference in Alexandria, Va.

The UC Berkeley technique relies on probabilistic computing techniques that underlie search engines. The computer categorizes the sound of each key and takes an educated guess about the character or word that was written. The computer uses both the sound of the keystroke and linguistic conventions to interpret a keystroke as an E after TH rather than a Q when the sound is similar--to come to a conclusion.

The first pass is right about 60 percent of the time for characters and 20 percent of the time for entire words. The transcript is then run through spelling and grammar checks, which increased character accuracy to 70 percent and the word accuracy to 50 percent.

The results are then fed back through the computer to refine future results. After three feedback cycles, the accuracy rate rose to 88 percent for words and 96 percent for characters.

Further experiments will take place. The researchers didn't examine what happens when the Shift, Control, Delete or Caps Lock keys are hit. Mouse actions also raise a major problem.
"If it's true that our species is alone in the universe, then I'd have to say that the universe aimed rather low and settled for very little."
-George Carlin (1937-2008)

"Have some of you Americans actually seen Football? Of course there are 0-0 draws but that doesn't make them any less exciting."
-Dr Roberts, with quite possibly the dumbest thing ever said in 10 years of SDNet.
User avatar
Soontir C'boath
SG-14: Fuck the Medic!
Posts: 6860
Joined: 2002-07-06 12:15am
Location: Queens, NYC I DON'T FUCKING CARE IF MANHATTEN IS CONSIDERED NYC!! I'M IN IT ASSHOLE!!!
Contact:

Post by Soontir C'boath »

I wonder if the crumbs of bread and other food I've eaten over this keyboard will change the way it sound...
I have almost reached the regrettable conclusion that the Negro's great stumbling block in his stride toward freedom is not the White Citizen's Counciler or the Ku Klux Klanner, but the white moderate, who is more devoted to "order" than to justice; who constantly says: "I agree with you in the goal you seek, but I cannot agree with your methods of direct action"; who paternalistically believes he can set the timetable for another man's freedom; who lives by a mythical concept of time and who constantly advises the Negro to wait for a "more convenient season."
bilateralrope
Sith Acolyte
Posts: 6185
Joined: 2005-06-25 06:50pm
Location: New Zealand

Post by bilateralrope »

Soontir C'boath wrote:I wonder if the crumbs of bread and other food I've eaten over this keyboard will change the way it sound...
Probably, but then they will just need to grab your keyboard so they can refrance it.
User avatar
Nephtys
Sith Acolyte
Posts: 6227
Joined: 2005-04-02 10:54pm
Location: South Cali... where life is cheap!

Post by Nephtys »

This isn't that new. I've read an account from the mid-late 90's about the FBI watching over some suspect by using one of those laser window microphones, and determining their typing from the clicking. So the CIA's sensative offices use masking equipment also to stop someone else from easilly recording keystroke sounds.

I'll need to find that article again. I think it was in an old issue of Wired.
User avatar
Davis 51
Jedi Master
Posts: 1155
Joined: 2005-01-21 07:23pm
Location: In that box, in that tiny corner in your garage, with my laptop, living off Dogfood and Diet Pepsi.

Post by Davis 51 »

even on so-called quiet keyboards
:shock: That's kinda creepy when you think about it.
Brains!
"I would ask if the irony of starting a war to spread democracy while ignoring public opinion polls at home would occur to George W. Bush, but then I check myself and realize that
I'm talking about a trained monkey.
"-Darth Wong
"All I ever got was "evil liberal commie-nazi". Yes, he called me a communist nazi."-DPDarkPrimus
Post Reply