[HN Gopher] AI-driven thermal cameras used to obtain passwords
       ___________________________________________________________________
        
       AI-driven thermal cameras used to obtain passwords
        
       Author : ellm
       Score  : 82 points
       Date   : 2022-10-11 08:02 UTC (15 hours ago)
        
 (HTM) web link (www.gla.ac.uk)
 (TXT) w3m dump (www.gla.ac.uk)
        
       | shultays wrote:
       | Why it would work better for touch-typists? Aren't they faster at
       | typing and thus less time for keys to cool?
       | 
       | Or maybe their fingers spent less time on keys
        
       | oogabooga13 wrote:
       | This was a way to get through a level in Tom Clancy's Splinter
       | Cell (the original game) 20 years ago.
       | 
       | https://youtu.be/lVNlggJECwc?t=507
        
       | rexreed wrote:
       | Long passwords with repeated characters are the easiest defeat on
       | this "attack". A simple camera that records the actual keypresses
       | is a much more sensical attack. After all, if you can present a
       | thermal camera to the keypad, you can present an actual camera.
       | Why use heat residue to "guess" keypresses with an 80-ish%
       | accuracy rate at best, when you can record the actual keypresses,
       | in the right order, including repeated characters with a much
       | higher accuracy rate? The only possible use for this "attack" is
       | for analyzing residual heat with a handheld thermal camera after
       | the person is gone, but as mentioned, long passwords with
       | repeated keypresses is the defeat as is simply holding your hand
       | on the keyboard after the password is entered. If you can protect
       | against a visual camera then that's more important.
        
         | SketchySeaBeast wrote:
         | Now we need a palindromic equivalent to "correct horse battery
         | staple".
        
           | layer8 wrote:
           | It already has four Rs, four Es, four Ts, and two As and Os.
           | I think it's fine.
        
           | rexreed wrote:
           | Well if you mean Anagram, here's one that works:
           | "CYBERATHLETES REPORT ACTORS"
        
             | SketchySeaBeast wrote:
             | No, I meant palindrome, so that you end up repeating the
             | same letters with little increase in memorization
             | complexity, but that works too - throw together a few
             | anagrams and you're golden.
        
               | rexreed wrote:
               | My favorite palindrome is "A man, a plan, a canal,
               | Panama". Supposedly a reference to former US president
               | Theodore Roosevelt and his quest for the Panama canal.
        
               | lowercased wrote:
               | "Put Eliot's toilet up" has stuck with me for years. As
               | has 'I know a fat man called Ella C Namtafawonki'.
        
       | 2rsf wrote:
       | Will this help? a keyboard that randomize the order of the digits
       | everytime it is used
       | 
       | https://www.reddit.com/r/mildlyinteresting/comments/bsx4ww/t...
        
         | Semaphor wrote:
         | This was common with mobile terminals in South Africa.
        
         | pluc wrote:
         | GrapheneOS's lock screen has this option! Such a no brainer for
         | such an easy security win.
        
       | somehnacct3757 wrote:
       | My list of ATM defensive rituals grows even longer.
       | 
       | For those who think time at ATM matters, consider a thermal
       | camera like the one at the start of the video, concealed in the
       | cabinet by fake panels. You enter your PIN, move your hand away
       | to touch the screen seconds later, you're pwned. Thermal cam has
       | your digits and vague sense of hand movements.
       | 
       | Cover the keypad with your other hand, take detours when moving
       | your hand, and, now, pretend press a handful of random keys.
       | 
       | I will try inserting bogus numbers into my PIN ritual and pretend
       | pressing them as part of entry. Should protect against hand
       | movements and thermal imaging as well.
        
         | MichaelMcG wrote:
         | Sorry, but which video are you referring? Can't find it in the
         | article, I'm assuming you were replying to a different comment.
        
         | _visgean wrote:
         | Hmm I have recently started using google pay at ATMs, with
         | virtual card numbers -
         | https://support.google.com/googlepay/answer/11234179?hl=en&c...
         | I think it should be impossible to to skim that.
        
         | 4gotunameagain wrote:
         | what's easier, doing an elaborate dance every single time you
         | touch an ATM, or cancelling your card and having the bank
         | revert the transactions in the relatively slim chance of fraud
         | ? :)
        
           | MonkeyMalarky wrote:
           | I just use the ATM inside my local bank branch. The same
           | location, all the time.
        
           | somehnacct3757 wrote:
           | Depends on the situation. If you're traveling, cancelling
           | your card while away from home is a huge setback.
        
         | Ancapistani wrote:
         | > My list of ATM defensive rituals grows even longer.
         | 
         | As does my list of potential sources for free thermal cameras.
         | 
         | That said - I've yet to find a skimmer, even though I check for
         | them every time I use a terminal.
        
           | voakbasda wrote:
           | This is the best idea yet. The best defense is a good
           | offense.
        
             | throw101010 wrote:
             | Until you get caught dismounting the scammer's hardward by
             | the bank's security.
        
               | Ancapistani wrote:
               | I'm willing to play that game. They can explain to the
               | cops why they allowed third-party hardware on their
               | machines to capture users' card data.
        
         | pfarrell wrote:
         | Thinking about this for an ATM. How about entering your
         | password and then pushing every other key. That would leave
         | approximately the same heat signature in every key. Maybe.
        
           | omwow wrote:
           | That's what I do.
        
           | tremendo wrote:
           | Or pushing keys with a stylus, a pencil with the eraser side,
           | or some other object that won't leave a thermal print?
        
       | krona wrote:
       | Just touch (not press) several keys randomly?
        
       | gluecode wrote:
       | I wonder if ATM machines should have a keyboard cooling function
       | to erase thermal signatures, immediately after each customer
       | session.
        
         | LaputanMachine wrote:
         | There would still be a temperature difference for some time
         | after entering a PIN until the keys used are fully cooled. So
         | this method might not fully mitigate the attack.
         | 
         | A better solution could be to heat the keys to about the same
         | temperature as a human's finger tips, so that no heat is being
         | transferred while entering a PIN.
        
           | jaclaz wrote:
           | Exactly, easier and much more effective than the mitigation
           | suggested by the scientists:
           | 
           | >One potential risk-reduction pathway could be to make it
           | illegal to sell thermal cameras without some kind of enhanced
           | security included in their software.
        
             | Arrath wrote:
             | I'm curious what kind of software solution there could be
             | to this?
             | 
             | Some from of pattern matcher in the camera obscuring the
             | video output when it determines its observing a number pad?
        
               | jaclaz wrote:
               | Maybe something loosely similar to the protection that is
               | said to be present in very high level colour photocopier
               | that prevents from photocopying money?
        
         | bilekas wrote:
         | This is actually a great point I hadn't even considered. I had
         | heard of cretins using a small grease film like a tiny layer of
         | vasolene etc on pinpads and then after the victim uses, they
         | would shine a light on it to see.
        
           | dijonman2 wrote:
           | Grease films are typically detected by the user. Better to
           | dust the keys with a UV sensitive powder and inspect the ATM
           | after pin entry.
        
         | jerpint wrote:
         | I had seen a video demoing an attack like this some while ago
         | and I started "wiping" keypads with my fingers so they're all
         | "warm"
        
         | chrischen wrote:
         | I've always just used my credit card holder (metal) to punch in
         | numbers, due to this heat thing. They were doing this with pins
         | before this technique.
        
       | pabs3 wrote:
       | It is well past time to stop using passwords. We should be using
       | TLS client certs (as in mutual TLS aka mTLS) or WebAuthn passkeys
       | already. I prefer certs because they don't require support in the
       | web application, but they have a terrible UI and browsers seem to
       | be making that worse, so WebAuthn it is, I just wish WebAuthn
       | would have a standardised HTTP header or TLS extension so it
       | would be usable without JavaScript, currently every website has
       | to implement their own login protocol in JavaScript.
       | 
       | https://www.cloudflare.com/learning/access-management/what-i...
       | https://github.com/w3c/webauthn/issues/1255
       | https://github.com/w3c/webauthn/issues/1616
        
         | wongarsu wrote:
         | That's probably better. But moving entirely from "things I
         | know" to "things I own" comes with its own set of security
         | disasters waiting to happen. We are better off using those to
         | augment the password than to replace it.
        
           | bheadmaster wrote:
           | I don't think "things I own" is a bad security model in
           | itself.
           | 
           | The ideal of authentication (to me) seems to be some kind of
           | USB dongle with your private key baked in the hardware, that
           | you can use to create digital signatures proving your
           | identity. Short of stealing the dongle, there is no way
           | anyone can steal your identity.
        
             | alistairSH wrote:
             | Using your dongle example, how do you access important
             | services away from home? Carry the dongle everywhere? If
             | so, you risk losing the dongle.
             | 
             | Same with your phone as the "thing I own". That's great,
             | until the phone dies/breaks/gets lost. Hopefully you have a
             | tablet as backup, or the paper copy of your one-time codes
             | in your wallet.
             | 
             | I don't have a good answer. I just hate the idea of needing
             | to access banking services when traveling should my phone
             | become unavailable.
        
               | bheadmaster wrote:
               | > Carry the dongle everywhere? If so, you risk losing the
               | dongle.
               | 
               | To be fair, we also carry our IDs everywhere and risk
               | losing them all the time, yet it works pretty fine in
               | most cases. Losing your ID is painful, and so would be
               | losing the dongle, but the security of it outweighs the
               | risk, IMHO.
               | 
               | Even more if we create dongles that are shaped like
               | cards, so we can keep them in our wallets like IDs.
        
               | AstralStorm wrote:
               | Normally you do not use the ID in day to day operations.
               | A better example would be a credit card, which combines a
               | password (or pin) with a cryptographic chip.
               | 
               | The card itself is too easy to steal, hence the backup
               | password. The other possibility is biometrics, but these
               | come with their own problems.
        
               | svachalek wrote:
               | It sounds like you don't live in the USA. No passwords
               | here.
        
         | [deleted]
        
         | teddyh wrote:
         | We should stop _manually entered_ passwords. Using a password
         | manager (like the one built into your web browser) with unique
         | secure passwords is fine.
        
           | Wowfunhappy wrote:
           | How do you authenticate the password manager?
        
             | teddyh wrote:
             | The context was to stop entering passwords _into web
             | sites_. The password manager is run locally.
        
               | layer8 wrote:
               | Passwords for websites are (hopefully) hashed locally.
               | And more importantly, how does it make a difference
               | whether you or the password manager types in the password
               | into the web form?
        
               | Wowfunhappy wrote:
               | > And how does it make a difference whether you or the
               | password manager types in the password into the web form?
               | 
               | Well, because a hidden camera can observe a human typing
               | their password, whereas a password manager does not need
               | to press any physical keys.
               | 
               | However, a camera can observe a human typing a master
               | password into their password manager, which is where I
               | was originally going with the question.
        
               | layer8 wrote:
               | I meant regarding local vs. nonlocal, what the GP
               | objected to.
        
             | SketchySeaBeast wrote:
             | With Keepass you can use a yubikey or key file.
        
       | DigitallyFidget wrote:
       | This isn't news to me at all. For ATM/Pin pads, I wipe my fingers
       | across every button as I press in the code, so it obscures what
       | was actually pressed, and linger fingers on keys not even in my
       | pin code. With enough practice, it doesn't take more than a
       | second or two longer than normally entering it.
       | 
       | As far as keyboards, I really don't ever interact with computers
       | that don't belong to me or aren't in a secure area, but I have a
       | custom scripted "keyboard" USB circuit thing that emulates
       | keypresses for me. I don't know what to even call it, but it's
       | like a mini Arduino sorta thing that emulates a generic Microsoft
       | keyboard to whatever you plug it into. It looks like a stick of
       | RAM with a USB plug, kinda. I have a few preset buttons that'll
       | type in my login info to automate logging into things. I made it
       | as a hardware password manager.
        
         | woeh wrote:
         | I've been in a hotel where the rooms had pin pads as locks that
         | required you to press two random numbers every time you want to
         | enter. The pad was a bit sensitive to fingerprints, but due to
         | this mechanism there would be fingerprints all over the device.
        
         | marbu wrote:
         | Indeed, this is not a new idea. The news here is about
         | particular implementation for extracting passwords from QWERTY
         | keyboards.
         | 
         | That said, this is not a big problem for ATM pin pads with
         | _metal keys_ , because these conduct heat well and so a heat
         | pattern is hard to detect after few seconds. See:
         | https://www.youtube.com/watch?v=PJCfTlQ82Fw
        
       | brk wrote:
       | They appear to be using a somewhat costly handheld thermal
       | camera, which likely has a FLIR Boson or equivalent sensor. Those
       | are pretty bulky and expensive, making it hard to use this attack
       | without hanging out near the keyboard/keypad you want to surveil.
       | 
       | A FLIR Lepton series[0], or similar, is much smaller, but still
       | ~$160/ea., and even though it is "smaller", it's not as easy to
       | hide in an ATM as a cheap pinhole camera. It is also much lower
       | resolution and has lower thermal sensitivity. Which would most
       | likely greatly reduce the places where you could deploy this
       | equip in a leave-behind covert setup.
       | 
       | It looks like a neat proof of concept, but probably not a day to
       | day risk the average person needs to be concerned about.
       | 
       | [0] https://www.digikey.com/en/products/detail/flir-
       | lepton/500-0...
        
         | AstralStorm wrote:
         | Yes, you're much more likely to have a regular camera installed
         | on the ATM or keypad. Night vision makes it work at all times.
         | Or you can instrument a keypad with a laser sensor overlay.
         | 
         | The IR camera is used to defeat obscured keypads only...
        
       | SanjayMehta wrote:
       | This is just silly: how many people punch in their PIN number and
       | then leave immediately?
       | 
       | I guess these researchers haven't ever withdrawn money from an
       | ATM.
        
         | eequah9L wrote:
         | From TFA:                 > 86% of passwords when thermal
         | images are taken within 20 seconds, and 76% when within 30
         | seconds
         | 
         | I don't know how long you spend at the ATM, myself I suspect I
         | would typically fit within the 20 second window.
        
           | SanjayMehta wrote:
           | Well, then all they'd get from me is 5000 - that's the amount
           | what I punch in after the PIN for my typical cash withdrawal.
        
         | wongarsu wrote:
         | That's how pin pads on doors work: you punch in the PIN, then
         | immediately go through the door. And those pin pads are
         | somewhat popular in commercial settings because it's easier to
         | distribute knowledge than to distribute physical keys.
        
           | SanjayMehta wrote:
           | I haven't seen a PIN pad lock in years in secure facilities,
           | everyone uses contactless cards.
        
             | dagw wrote:
             | At work we have both for many doors. You have to scan your
             | card and then enter your PIN. This way someone can't just
             | steal a card.
        
       | yetanotherloser wrote:
       | Someone's been playing Splinter Cell!
        
         | teddyh wrote:
         | Or watched the first episode of Max Headroom (from 1987).
        
           | yetanotherloser wrote:
           | Really? Was fairly sure Splinter Cell really didn't invent
           | this, but it was what came to mind. Didn't know it went back
           | that far. I'll have to look that up, I only know Max Headroom
           | from clips.
        
       | amelius wrote:
       | Fortunately most people stay at the machine after typing their
       | password.
       | 
       | Anyway perhaps now is a good time to get some 2fa hardware token.
        
         | cricalix wrote:
         | There are ATMs in Europe that will take the card, ask for what
         | you want to do, ask the amount if it's a withdrawal, and then
         | ask for the PIN and dispense it. This reduces the time between
         | typing and dispensing. No idea if it's a significant enough
         | reduction in the time versus card, pin, navigate to withdraw,
         | dispense such that it would enable this attack.
        
           | [deleted]
        
           | Semaphor wrote:
           | What do ATMs elsewhere do? This is the only way I know.
        
             | SketchySeaBeast wrote:
             | The ATMs I regularly use authenticate THEN ask for what you
             | want to do.
        
         | pluc wrote:
         | Even with 2FA, any sort of "remember me for a minute and I'll
         | go get a coffee" makes it pretty useless.
        
         | jbj wrote:
         | not if that machine is an ATM
        
           | amelius wrote:
           | With an ATM you are already using a hardware token ;)
        
           | codetiger wrote:
           | So in case of ATMs we now need to make sure we soft touch
           | some random buttons to ensure this trick doesn't work.
        
             | agent008t wrote:
             | I have already seen some ATMs that shuffle the numbers on
             | the numberpad around for each PIN entry. It is inconvenient
             | for muscle memory, but prevents this kind of attack.
        
               | soco wrote:
               | I know somebody working at a bank talking about their
               | implementation, and how many elderly customers block
               | their cards after wrongly entering their pin.
        
             | drath wrote:
             | Also, to mitigate the problem somewhat, one could obfuscate
             | the order at which the numbers were pressed by setting a
             | custom pin with repeating numbers. Ideally, just repeating
             | one./s
        
       | billsmithaustin wrote:
       | Thermally insulated password gloves?
        
       | Bakary wrote:
       | August Dvorak was more prescient than we ever gave him credit
       | for!
        
       | vivegi wrote:
       | My bank ATM _randomly_ sends a One-time-passcode to my mobile
       | phone and challenges me to enter that on the ATM pinpad (in
       | addition to my ATM pin). This is especially true when I try to
       | withdraw from an ATM that is not my usual location (or I guess is
       | an ATM at a location that is internally flagged for high number
       | of ATM fraud incidents).
        
       | wongarsu wrote:
       | A video from the lock-picking lawyer discussing and demoing this
       | attack (with a regular, non-AI thermal camera):
       | https://www.youtube.com/watch?v=okgPbtz4ZkE
       | 
       | He managed to make it work from 30 feet distance a minute after
       | the key was entered.
        
       | nonrandomstring wrote:
       | People in urban public spaces are already entering passwords to
       | phones, tablets and laptops within full view of cameras that can
       | see the dirt under their fingernails.
        
       ___________________________________________________________________
       (page generated 2022-10-11 23:02 UTC)