8 ms·
Guessing smart phone PINs by monitoring the accelerometer
- mdorazio 7y agoI suspect issues like this are one of the reasons why iOS locked down accelerometer access in Safari. Motion sensors have a lot more potential for malicious use than most users think.
- fmjrey 7y agoI was going to say Apple must have became aware of such flaw a year ago (iOS 12.2). However checking back on the article I see it is from 2013! So for all this time nothing has been done, Apple reacted last year, and Google has done nothing. Worrying.
- Dahoon 7y agoIt still works in iOS.
- braindongle 7y agoBy locked down, do you mean requiring justification to get through the app store or accessing the data at all? The latter is no problem for iOS-only [0] or Flutter [1]. I've been spending much time with cross-platform sensor access in Flutter. It works. [0] https://developer.apple.com/documentation/coremotion/getting_raw_accelerometer_events https://developer.apple.com/documentation/coremotion/getting... [1] https://pub.dev/packages/sensors https://pub.dev/packages/sensors
- judge2020 7y ago> in Safari
- r1ch 7y agoMeanwhile in Android land, Chrome gives all websites access to sensor data without any permission prompts!
- YetAnotherNick 7y agoAFAIR, it is the same for Safari on iOS.
- tinus_hn 7y agoThe accelerometer calibration can be detected by websites and is a way to identify users. On the other side the use case for websites is pretty limited. https://sensorid.cl.cam.ac.uk/ https://sensorid.cl.cam.ac.uk/
- untog 7y agoThis stuff is so fascinating... and so frustrating. Now browsers have accelerometer data behind a permission prompt. It makes total sense given stuff like this but it used to be a nice little way to create immediately playable games, apply visual parallax-y effects... and now we have permission prompts sat in front of that. I guess I’m not blaming anyone here, just amazed that there isn’t any data source that doesn’t leak something sensitive!
- atoav 7y agoI don't see the issue there: it is good if my browser tells me what is going on and leaves the decision to me. Of course in an ideal world we would be able to trust the sites we visit enough to not jave our browsera protect us, but that is not how a ad financed web worka sadly
- JoeAltmaier 7y ago"Figure out" means, in this case, classify. So it can tell which of 50 is 'the one'if its in that set. That's a hell of a long way away from decoding your PIN from the tens of thousands possible.
- reisub0 7y agoThis was a paper from 2013 though, 7 years ago. I'm sure they've more than made it a proper technology now, with all the compute power and deep learning and what not. Maybe unrelated, but WhatsApp does monitor your phone accelerometer data 100% of the time, even when it's in the background. An app doesn't even need to ask for permission to get access to the accelerometer data, so there's not even a pop up of any sort.
- gruez 7y ago>but WhatsApp does monitor your phone accelerometer data 100% of the time Source for this? Did anyone call them out on it? What plausible reason is there to have it on 24/7?
- ficklepickle 7y agoI was also curious. I found a relevant reddit discussion: https://www.reddit.com/r/lgg6/comments/7yxk0a/whatsapp_insane_accelerometer_usage/ https://www.reddit.com/r/lgg6/comments/7yxk0a/whatsapp_insan...
- axelfontaine 7y agoI came across an interesting solution to this while paying at a restaurant in Ecuador: they used an Android device which randomized the position of the numbers of the on-screen keypad before each transaction. The original intent is to make it much harder for onlookers to guess your pin based on finger movements. This could however apply equally well to the usecase of the article. It is a bit of a usability trade-off though as you can't enter a pin using muscle memory alone anymore, as you must first understand the current keypad layout.
- frabert 7y agoI had this feature enabled on my old phone, on which I had flashed LineageOS. Unfortunately the new phone's stock ROM doesn't have that, but it also features a fingerprint sensor, so I don't really type my passcode that frequently anymore.
- stabbles 7y agoWhen I was in Barcelona an ATM had its keypad numbers flipped (7 8 9; 4 5 6; 1 2 3), which I only realized after the first attempt. Second attempt I got my PIN wrong, and I did not dare to try it a third (and final) attempt. Apparently it's really muscle memory.
- nitrogen 7y agoCould this have been a skimmer on top of the legit keypad, or is 10-key (vs phone) layout standard in Spain?
- wpietri 7y agoInteresting! I'd love to see what happens when somebody studies that. That surely creates a much larger inter-digit delay as people hunt for the right numbers. So I'd bet it's harder if the attacker can't also see the screen, but easier if they can.
- tantalor 7y agoY. S. Ryu, D. H. Koh, B. L. Aday, X. A. Gutierrez, and J. D. Platt. Usability evaluation of randomized keypad. Journal of Usability Studies, 5(2), 2010. https://uxpajournal.org/usability-evaluation-of-randomized-keypad/ https://uxpajournal.org/usability-evaluation-of-randomized-k...
- robinduckett 7y agoSomeone add (2013) to this
- floatingatoll 7y agoThey ask us to use the Contact link in the HN footer to ask them to do so.
- angry_octet 7y agoWhy can't Android manage to do basic security things, like disable the accelerometers during keyboard input?
- pbhjpbhj 7y agoI imagine it could be a useful signal - most "touch" on a particular key at the instant the accelerometer gives largest jerk ... might help to avoid false keying?
- wcoenen 7y agoAre we sure that it doesn't? This news is from 7 years ago.
- adrianmonk 7y agoIt's probably not that simple and clear cut. There are probably some reasonable use cases for apps that need the accelerometer on continuously. Which makes it a trade-off. One example could be a pedometer / activity tracker app that totals up your number of steps per day. Suppose the user decides to get on a treadmill and walk for 30 minutes but finds it boring so they text their friends while doing it. Maybe they have the keyboard open the entire time, so at the end of their 30 minutes of exercise, the pedometer registers zero activity. Or maybe you have an app that uses certain accelerometer-based gestures to trigger certain actions. If Android gets an update that turns off the accelerometer when the keyboard is open, many users won't understand why the gesture only works sometimes, and the app developer will get a ton of bug reports. And you'd be creating these potential problems to solve a privacy leak which doesn't seem that severe given that it can only give you weak information about a person's pin. I'm not saying that shutting off the accelerometer isn't ultimately the right decision, but I am saying it's not a no-brainer.
- angry_octet 7y agoDoesn't Android know when the user is authenticating? How many seconds a day are you inputting to the lock screen? Doesn't need to be for any time the keyboard is open. (Of course, doing it semi randomly is also now necessary, to obscure user unlock times.) As to weak info, you do it again and again, I'd say it's pretty good info.
- jacknews 7y agoHow do you get the accelerometer data? Surely if you have enough privilege to get that, you could just get input data directly?
- dubbel 7y agoBy requesting access to it. To a user that just installed a e.g. step counting app that wouldn't be suspicious. Otherwise on Android apps would need to request accessibility feature access to be able to monitor keyboard input into other apps (and there is an explicit warning), or, which is most common, request an overlay permission and start a "phishing overlay" if a targeted app is started by the user.
- avip 7y agoUnbait, unBS yourself: After five guesses it could spot Pins about 43% of the time [...] these results were produced when Pins and patterns were picked from a 50-strong set of numbers and shapes. (2015)