[HN Gopher] AI-driven thermal cameras used to obtain passwords
___________________________________________________________________
AI-driven thermal cameras used to obtain passwords
Author : ellm
Score : 82 points
Date : 2022-10-11 08:02 UTC (15 hours ago)
(HTM) web link (www.gla.ac.uk)
(TXT) w3m dump (www.gla.ac.uk)
| shultays wrote:
| Why it would work better for touch-typists? Aren't they faster at
| typing and thus less time for keys to cool?
|
| Or maybe their fingers spent less time on keys
| oogabooga13 wrote:
| This was a way to get through a level in Tom Clancy's Splinter
| Cell (the original game) 20 years ago.
|
| https://youtu.be/lVNlggJECwc?t=507
| rexreed wrote:
| Long passwords with repeated characters are the easiest defeat on
| this "attack". A simple camera that records the actual keypresses
| is a much more sensical attack. After all, if you can present a
| thermal camera to the keypad, you can present an actual camera.
| Why use heat residue to "guess" keypresses with an 80-ish%
| accuracy rate at best, when you can record the actual keypresses,
| in the right order, including repeated characters with a much
| higher accuracy rate? The only possible use for this "attack" is
| for analyzing residual heat with a handheld thermal camera after
| the person is gone, but as mentioned, long passwords with
| repeated keypresses is the defeat as is simply holding your hand
| on the keyboard after the password is entered. If you can protect
| against a visual camera then that's more important.
| SketchySeaBeast wrote:
| Now we need a palindromic equivalent to "correct horse battery
| staple".
| layer8 wrote:
| It already has four Rs, four Es, four Ts, and two As and Os.
| I think it's fine.
| rexreed wrote:
| Well if you mean Anagram, here's one that works:
| "CYBERATHLETES REPORT ACTORS"
| SketchySeaBeast wrote:
| No, I meant palindrome, so that you end up repeating the
| same letters with little increase in memorization
| complexity, but that works too - throw together a few
| anagrams and you're golden.
| rexreed wrote:
| My favorite palindrome is "A man, a plan, a canal,
| Panama". Supposedly a reference to former US president
| Theodore Roosevelt and his quest for the Panama canal.
| lowercased wrote:
| "Put Eliot's toilet up" has stuck with me for years. As
| has 'I know a fat man called Ella C Namtafawonki'.
| 2rsf wrote:
| Will this help? a keyboard that randomize the order of the digits
| everytime it is used
|
| https://www.reddit.com/r/mildlyinteresting/comments/bsx4ww/t...
| Semaphor wrote:
| This was common with mobile terminals in South Africa.
| pluc wrote:
| GrapheneOS's lock screen has this option! Such a no brainer for
| such an easy security win.
| somehnacct3757 wrote:
| My list of ATM defensive rituals grows even longer.
|
| For those who think time at ATM matters, consider a thermal
| camera like the one at the start of the video, concealed in the
| cabinet by fake panels. You enter your PIN, move your hand away
| to touch the screen seconds later, you're pwned. Thermal cam has
| your digits and vague sense of hand movements.
|
| Cover the keypad with your other hand, take detours when moving
| your hand, and, now, pretend press a handful of random keys.
|
| I will try inserting bogus numbers into my PIN ritual and pretend
| pressing them as part of entry. Should protect against hand
| movements and thermal imaging as well.
| MichaelMcG wrote:
| Sorry, but which video are you referring? Can't find it in the
| article, I'm assuming you were replying to a different comment.
| _visgean wrote:
| Hmm I have recently started using google pay at ATMs, with
| virtual card numbers -
| https://support.google.com/googlepay/answer/11234179?hl=en&c...
| I think it should be impossible to to skim that.
| 4gotunameagain wrote:
| what's easier, doing an elaborate dance every single time you
| touch an ATM, or cancelling your card and having the bank
| revert the transactions in the relatively slim chance of fraud
| ? :)
| MonkeyMalarky wrote:
| I just use the ATM inside my local bank branch. The same
| location, all the time.
| somehnacct3757 wrote:
| Depends on the situation. If you're traveling, cancelling
| your card while away from home is a huge setback.
| Ancapistani wrote:
| > My list of ATM defensive rituals grows even longer.
|
| As does my list of potential sources for free thermal cameras.
|
| That said - I've yet to find a skimmer, even though I check for
| them every time I use a terminal.
| voakbasda wrote:
| This is the best idea yet. The best defense is a good
| offense.
| throw101010 wrote:
| Until you get caught dismounting the scammer's hardward by
| the bank's security.
| Ancapistani wrote:
| I'm willing to play that game. They can explain to the
| cops why they allowed third-party hardware on their
| machines to capture users' card data.
| pfarrell wrote:
| Thinking about this for an ATM. How about entering your
| password and then pushing every other key. That would leave
| approximately the same heat signature in every key. Maybe.
| omwow wrote:
| That's what I do.
| tremendo wrote:
| Or pushing keys with a stylus, a pencil with the eraser side,
| or some other object that won't leave a thermal print?
| krona wrote:
| Just touch (not press) several keys randomly?
| gluecode wrote:
| I wonder if ATM machines should have a keyboard cooling function
| to erase thermal signatures, immediately after each customer
| session.
| LaputanMachine wrote:
| There would still be a temperature difference for some time
| after entering a PIN until the keys used are fully cooled. So
| this method might not fully mitigate the attack.
|
| A better solution could be to heat the keys to about the same
| temperature as a human's finger tips, so that no heat is being
| transferred while entering a PIN.
| jaclaz wrote:
| Exactly, easier and much more effective than the mitigation
| suggested by the scientists:
|
| >One potential risk-reduction pathway could be to make it
| illegal to sell thermal cameras without some kind of enhanced
| security included in their software.
| Arrath wrote:
| I'm curious what kind of software solution there could be
| to this?
|
| Some from of pattern matcher in the camera obscuring the
| video output when it determines its observing a number pad?
| jaclaz wrote:
| Maybe something loosely similar to the protection that is
| said to be present in very high level colour photocopier
| that prevents from photocopying money?
| bilekas wrote:
| This is actually a great point I hadn't even considered. I had
| heard of cretins using a small grease film like a tiny layer of
| vasolene etc on pinpads and then after the victim uses, they
| would shine a light on it to see.
| dijonman2 wrote:
| Grease films are typically detected by the user. Better to
| dust the keys with a UV sensitive powder and inspect the ATM
| after pin entry.
| jerpint wrote:
| I had seen a video demoing an attack like this some while ago
| and I started "wiping" keypads with my fingers so they're all
| "warm"
| chrischen wrote:
| I've always just used my credit card holder (metal) to punch in
| numbers, due to this heat thing. They were doing this with pins
| before this technique.
| pabs3 wrote:
| It is well past time to stop using passwords. We should be using
| TLS client certs (as in mutual TLS aka mTLS) or WebAuthn passkeys
| already. I prefer certs because they don't require support in the
| web application, but they have a terrible UI and browsers seem to
| be making that worse, so WebAuthn it is, I just wish WebAuthn
| would have a standardised HTTP header or TLS extension so it
| would be usable without JavaScript, currently every website has
| to implement their own login protocol in JavaScript.
|
| https://www.cloudflare.com/learning/access-management/what-i...
| https://github.com/w3c/webauthn/issues/1255
| https://github.com/w3c/webauthn/issues/1616
| wongarsu wrote:
| That's probably better. But moving entirely from "things I
| know" to "things I own" comes with its own set of security
| disasters waiting to happen. We are better off using those to
| augment the password than to replace it.
| bheadmaster wrote:
| I don't think "things I own" is a bad security model in
| itself.
|
| The ideal of authentication (to me) seems to be some kind of
| USB dongle with your private key baked in the hardware, that
| you can use to create digital signatures proving your
| identity. Short of stealing the dongle, there is no way
| anyone can steal your identity.
| alistairSH wrote:
| Using your dongle example, how do you access important
| services away from home? Carry the dongle everywhere? If
| so, you risk losing the dongle.
|
| Same with your phone as the "thing I own". That's great,
| until the phone dies/breaks/gets lost. Hopefully you have a
| tablet as backup, or the paper copy of your one-time codes
| in your wallet.
|
| I don't have a good answer. I just hate the idea of needing
| to access banking services when traveling should my phone
| become unavailable.
| bheadmaster wrote:
| > Carry the dongle everywhere? If so, you risk losing the
| dongle.
|
| To be fair, we also carry our IDs everywhere and risk
| losing them all the time, yet it works pretty fine in
| most cases. Losing your ID is painful, and so would be
| losing the dongle, but the security of it outweighs the
| risk, IMHO.
|
| Even more if we create dongles that are shaped like
| cards, so we can keep them in our wallets like IDs.
| AstralStorm wrote:
| Normally you do not use the ID in day to day operations.
| A better example would be a credit card, which combines a
| password (or pin) with a cryptographic chip.
|
| The card itself is too easy to steal, hence the backup
| password. The other possibility is biometrics, but these
| come with their own problems.
| svachalek wrote:
| It sounds like you don't live in the USA. No passwords
| here.
| [deleted]
| teddyh wrote:
| We should stop _manually entered_ passwords. Using a password
| manager (like the one built into your web browser) with unique
| secure passwords is fine.
| Wowfunhappy wrote:
| How do you authenticate the password manager?
| teddyh wrote:
| The context was to stop entering passwords _into web
| sites_. The password manager is run locally.
| layer8 wrote:
| Passwords for websites are (hopefully) hashed locally.
| And more importantly, how does it make a difference
| whether you or the password manager types in the password
| into the web form?
| Wowfunhappy wrote:
| > And how does it make a difference whether you or the
| password manager types in the password into the web form?
|
| Well, because a hidden camera can observe a human typing
| their password, whereas a password manager does not need
| to press any physical keys.
|
| However, a camera can observe a human typing a master
| password into their password manager, which is where I
| was originally going with the question.
| layer8 wrote:
| I meant regarding local vs. nonlocal, what the GP
| objected to.
| SketchySeaBeast wrote:
| With Keepass you can use a yubikey or key file.
| DigitallyFidget wrote:
| This isn't news to me at all. For ATM/Pin pads, I wipe my fingers
| across every button as I press in the code, so it obscures what
| was actually pressed, and linger fingers on keys not even in my
| pin code. With enough practice, it doesn't take more than a
| second or two longer than normally entering it.
|
| As far as keyboards, I really don't ever interact with computers
| that don't belong to me or aren't in a secure area, but I have a
| custom scripted "keyboard" USB circuit thing that emulates
| keypresses for me. I don't know what to even call it, but it's
| like a mini Arduino sorta thing that emulates a generic Microsoft
| keyboard to whatever you plug it into. It looks like a stick of
| RAM with a USB plug, kinda. I have a few preset buttons that'll
| type in my login info to automate logging into things. I made it
| as a hardware password manager.
| woeh wrote:
| I've been in a hotel where the rooms had pin pads as locks that
| required you to press two random numbers every time you want to
| enter. The pad was a bit sensitive to fingerprints, but due to
| this mechanism there would be fingerprints all over the device.
| marbu wrote:
| Indeed, this is not a new idea. The news here is about
| particular implementation for extracting passwords from QWERTY
| keyboards.
|
| That said, this is not a big problem for ATM pin pads with
| _metal keys_ , because these conduct heat well and so a heat
| pattern is hard to detect after few seconds. See:
| https://www.youtube.com/watch?v=PJCfTlQ82Fw
| brk wrote:
| They appear to be using a somewhat costly handheld thermal
| camera, which likely has a FLIR Boson or equivalent sensor. Those
| are pretty bulky and expensive, making it hard to use this attack
| without hanging out near the keyboard/keypad you want to surveil.
|
| A FLIR Lepton series[0], or similar, is much smaller, but still
| ~$160/ea., and even though it is "smaller", it's not as easy to
| hide in an ATM as a cheap pinhole camera. It is also much lower
| resolution and has lower thermal sensitivity. Which would most
| likely greatly reduce the places where you could deploy this
| equip in a leave-behind covert setup.
|
| It looks like a neat proof of concept, but probably not a day to
| day risk the average person needs to be concerned about.
|
| [0] https://www.digikey.com/en/products/detail/flir-
| lepton/500-0...
| AstralStorm wrote:
| Yes, you're much more likely to have a regular camera installed
| on the ATM or keypad. Night vision makes it work at all times.
| Or you can instrument a keypad with a laser sensor overlay.
|
| The IR camera is used to defeat obscured keypads only...
| SanjayMehta wrote:
| This is just silly: how many people punch in their PIN number and
| then leave immediately?
|
| I guess these researchers haven't ever withdrawn money from an
| ATM.
| eequah9L wrote:
| From TFA: > 86% of passwords when thermal
| images are taken within 20 seconds, and 76% when within 30
| seconds
|
| I don't know how long you spend at the ATM, myself I suspect I
| would typically fit within the 20 second window.
| SanjayMehta wrote:
| Well, then all they'd get from me is 5000 - that's the amount
| what I punch in after the PIN for my typical cash withdrawal.
| wongarsu wrote:
| That's how pin pads on doors work: you punch in the PIN, then
| immediately go through the door. And those pin pads are
| somewhat popular in commercial settings because it's easier to
| distribute knowledge than to distribute physical keys.
| SanjayMehta wrote:
| I haven't seen a PIN pad lock in years in secure facilities,
| everyone uses contactless cards.
| dagw wrote:
| At work we have both for many doors. You have to scan your
| card and then enter your PIN. This way someone can't just
| steal a card.
| yetanotherloser wrote:
| Someone's been playing Splinter Cell!
| teddyh wrote:
| Or watched the first episode of Max Headroom (from 1987).
| yetanotherloser wrote:
| Really? Was fairly sure Splinter Cell really didn't invent
| this, but it was what came to mind. Didn't know it went back
| that far. I'll have to look that up, I only know Max Headroom
| from clips.
| amelius wrote:
| Fortunately most people stay at the machine after typing their
| password.
|
| Anyway perhaps now is a good time to get some 2fa hardware token.
| cricalix wrote:
| There are ATMs in Europe that will take the card, ask for what
| you want to do, ask the amount if it's a withdrawal, and then
| ask for the PIN and dispense it. This reduces the time between
| typing and dispensing. No idea if it's a significant enough
| reduction in the time versus card, pin, navigate to withdraw,
| dispense such that it would enable this attack.
| [deleted]
| Semaphor wrote:
| What do ATMs elsewhere do? This is the only way I know.
| SketchySeaBeast wrote:
| The ATMs I regularly use authenticate THEN ask for what you
| want to do.
| pluc wrote:
| Even with 2FA, any sort of "remember me for a minute and I'll
| go get a coffee" makes it pretty useless.
| jbj wrote:
| not if that machine is an ATM
| amelius wrote:
| With an ATM you are already using a hardware token ;)
| codetiger wrote:
| So in case of ATMs we now need to make sure we soft touch
| some random buttons to ensure this trick doesn't work.
| agent008t wrote:
| I have already seen some ATMs that shuffle the numbers on
| the numberpad around for each PIN entry. It is inconvenient
| for muscle memory, but prevents this kind of attack.
| soco wrote:
| I know somebody working at a bank talking about their
| implementation, and how many elderly customers block
| their cards after wrongly entering their pin.
| drath wrote:
| Also, to mitigate the problem somewhat, one could obfuscate
| the order at which the numbers were pressed by setting a
| custom pin with repeating numbers. Ideally, just repeating
| one./s
| billsmithaustin wrote:
| Thermally insulated password gloves?
| Bakary wrote:
| August Dvorak was more prescient than we ever gave him credit
| for!
| vivegi wrote:
| My bank ATM _randomly_ sends a One-time-passcode to my mobile
| phone and challenges me to enter that on the ATM pinpad (in
| addition to my ATM pin). This is especially true when I try to
| withdraw from an ATM that is not my usual location (or I guess is
| an ATM at a location that is internally flagged for high number
| of ATM fraud incidents).
| wongarsu wrote:
| A video from the lock-picking lawyer discussing and demoing this
| attack (with a regular, non-AI thermal camera):
| https://www.youtube.com/watch?v=okgPbtz4ZkE
|
| He managed to make it work from 30 feet distance a minute after
| the key was entered.
| nonrandomstring wrote:
| People in urban public spaces are already entering passwords to
| phones, tablets and laptops within full view of cameras that can
| see the dirt under their fingernails.
___________________________________________________________________
(page generated 2022-10-11 23:02 UTC)