9 ms·
AI-driven thermal cameras used to obtain passwords
- amelius 4y agoFortunately most people stay at the machine after typing their password. Anyway perhaps now is a good time to get some 2fa hardware token.
- jbj 4y agonot if that machine is an ATM
- codetiger 4y agoSo in case of ATMs we now need to make sure we soft touch some random buttons to ensure this trick doesn't work.
- agent008t 4y agoI have already seen some ATMs that shuffle the numbers on the numberpad around for each PIN entry. It is inconvenient for muscle memory, but prevents this kind of attack.
- soco 4y agoI know somebody working at a bank talking about their implementation, and how many elderly customers block their cards after wrongly entering their pin.
- drath 4y agoAlso, to mitigate the problem somewhat, one could obfuscate the order at which the numbers were pressed by setting a custom pin with repeating numbers. Ideally, just repeating one./s
- amelius 4y agoWith an ATM you are already using a hardware token ;)
- cricalix 4y agoThere are ATMs in Europe that will take the card, ask for what you want to do, ask the amount if it’s a withdrawal, and then ask for the PIN and dispense it. This reduces the time between typing and dispensing. No idea if it’s a significant enough reduction in the time versus card, pin, navigate to withdraw, dispense such that it would enable this attack.
- deleted 4y ago[deleted]
- Semaphor 4y agoWhat do ATMs elsewhere do? This is the only way I know.
- SketchySeaBeast 4y agoThe ATMs I regularly use authenticate THEN ask for what you want to do.
- pluc 4y agoEven with 2FA, any sort of "remember me for a minute and I'll go get a coffee" makes it pretty useless.
- SanjayMehta 4y agoThis is just silly: how many people punch in their PIN number and then leave immediately? I guess these researchers haven't ever withdrawn money from an ATM.
- wongarsu 4y agoThat's how pin pads on doors work: you punch in the PIN, then immediately go through the door. And those pin pads are somewhat popular in commercial settings because it's easier to distribute knowledge than to distribute physical keys.
- SanjayMehta 4y agoI haven't seen a PIN pad lock in years in secure facilities, everyone uses contactless cards.
- dagw 4y agoAt work we have both for many doors. You have to scan your card and then enter your PIN. This way someone can't just steal a card.
- eequah9L 4y agoFrom TFA: > 86% of passwords when thermal images are taken within 20 seconds, and 76% when within 30 seconds I don't know how long you spend at the ATM, myself I suspect I would typically fit within the 20 second window.
- SanjayMehta 4y agoWell, then all they'd get from me is 5000 - that's the amount what I punch in after the PIN for my typical cash withdrawal.
- yetanotherloser 4y agoSomeone's been playing Splinter Cell!
- teddyh 4y agoOr watched the first episode of Max Headroom (from 1987).
- yetanotherloser 4y agoReally? Was fairly sure Splinter Cell really didn't invent this, but it was what came to mind. Didn't know it went back that far. I'll have to look that up, I only know Max Headroom from clips.
- nonrandomstring 4y agoPeople in urban public spaces are already entering passwords to phones, tablets and laptops within full view of cameras that can see the dirt under their fingernails.
- gluecode 4y agoI wonder if ATM machines should have a keyboard cooling function to erase thermal signatures, immediately after each customer session.
- chrischen 4y agoI've always just used my credit card holder (metal) to punch in numbers, due to this heat thing. They were doing this with pins before this technique.
- bilekas 4y agoThis is actually a great point I hadn't even considered. I had heard of cretins using a small grease film like a tiny layer of vasolene etc on pinpads and then after the victim uses, they would shine a light on it to see.
- dijonman2 4y agoGrease films are typically detected by the user. Better to dust the keys with a UV sensitive powder and inspect the ATM after pin entry.
- LaputanMachine 4y agoThere would still be a temperature difference for some time after entering a PIN until the keys used are fully cooled. So this method might not fully mitigate the attack. A better solution could be to heat the keys to about the same temperature as a human's finger tips, so that no heat is being transferred while entering a PIN.
- jaclaz 4y agoExactly, easier and much more effective than the mitigation suggested by the scientists: >One potential risk-reduction pathway could be to make it illegal to sell thermal cameras without some kind of enhanced security included in their software.
- 4y ago
- wongarsu 4y agoA video from the lock-picking lawyer discussing and demoing this attack (with a regular, non-AI thermal camera): https://www.youtube.com/watch?v=okgPbtz4ZkE https://www.youtube.com/watch?v=okgPbtz4ZkE He managed to make it work from 30 feet distance a minute after the key was entered.
- 2rsf 4y agoWill this help? a keyboard that randomize the order of the digits everytime it is used https://www.reddit.com/r/mildlyinteresting/comments/bsx4ww/this_keypad_randomizes_the_numbers_every_time_so/ https://www.reddit.com/r/mildlyinteresting/comments/bsx4ww/t...
- krona 4y agoJust touch (not press) several keys randomly?
- pabs3 4y agoIt is well past time to stop using passwords. We should be using TLS client certs (as in mutual TLS aka mTLS) or WebAuthn passkeys already. I prefer certs because they don't require support in the web application, but they have a terrible UI and browsers seem to be making that worse, so WebAuthn it is, I just wish WebAuthn would have a standardised HTTP header or TLS extension so it would be usable without JavaScript, currently every website has to implement their own login protocol in JavaScript. https://www.cloudflare.com/learning/access-management/what-is-mutual-tls/ https://www.cloudflare.com/learning/access-management/what-i... https://github.com/w3c/webauthn/issues/1255 https://github.com/w3c/webauthn/issues/1255 https://github.com/w3c/webauthn/issues/1616 https://github.com/w3c/webauthn/issues/1616
- deleted 4y ago[deleted]
- teddyh 4y agoWe should stop manually entered passwords. Using a password manager (like the one built into your web browser) with unique secure passwords is fine.
- Wowfunhappy 4y agoHow do you authenticate the password manager?
- SketchySeaBeast 4y agoWith Keepass you can use a yubikey or key file.
- teddyh 4y agoThe context was to stop entering passwords into web sites. The password manager is run locally.
- layer8 4y agoPasswords for websites are (hopefully) hashed locally. And more importantly, how does it make a difference whether you or the password manager types in the password into the web form?
- somehnacct3757 4y agoMy list of ATM defensive rituals grows even longer. For those who think time at ATM matters, consider a thermal camera like the one at the start of the video, concealed in the cabinet by fake panels. You enter your PIN, move your hand away to touch the screen seconds later, you're pwned. Thermal cam has your digits and vague sense of hand movements. Cover the keypad with your other hand, take detours when moving your hand, and, now, pretend press a handful of random keys. I will try inserting bogus numbers into my PIN ritual and pretend pressing them as part of entry. Should protect against hand movements and thermal imaging as well.
- Ancapistani 4y ago> My list of ATM defensive rituals grows even longer. As does my list of potential sources for free thermal cameras. That said - I’ve yet to find a skimmer, even though I check for them every time I use a terminal.
- voakbasda 4y agoThis is the best idea yet. The best defense is a good offense.
- throw101010 4y agoUntil you get caught dismounting the scammer's hardward by the bank's security.
- Ancapistani 4y agoI’m willing to play that game. They can explain to the cops why they allowed third-party hardware on their machines to capture users’ card data.
- 4gotunameagain 4y agowhat's easier, doing an elaborate dance every single time you touch an ATM, or cancelling your card and having the bank revert the transactions in the relatively slim chance of fraud ? :)
- rexreed 4y agoLong passwords with repeated characters are the easiest defeat on this "attack". A simple camera that records the actual keypresses is a much more sensical attack. After all, if you can present a thermal camera to the keypad, you can present an actual camera. Why use heat residue to "guess" keypresses with an 80-ish% accuracy rate at best, when you can record the actual keypresses, in the right order, including repeated characters with a much higher accuracy rate? The only possible use for this "attack" is for analyzing residual heat with a handheld thermal camera after the person is gone, but as mentioned, long passwords with repeated keypresses is the defeat as is simply holding your hand on the keyboard after the password is entered. If you can protect against a visual camera then that's more important.
- SketchySeaBeast 4y agoNow we need a palindromic equivalent to "correct horse battery staple".
- rexreed 4y agoWell if you mean Anagram, here's one that works: "CYBERATHLETES REPORT ACTORS"
- SketchySeaBeast 4y agoNo, I meant palindrome, so that you end up repeating the same letters with little increase in memorization complexity, but that works too - throw together a few anagrams and you're golden.
- rexreed 4y agoMy favorite palindrome is "A man, a plan, a canal, Panama". Supposedly a reference to former US president Theodore Roosevelt and his quest for the Panama canal.
- lowercased 4y ago
- shultays 4y agoWhy it would work better for touch-typists? Aren't they faster at typing and thus less time for keys to cool? Or maybe their fingers spent less time on keys
- brk 4y agoThey appear to be using a somewhat costly handheld thermal camera, which likely has a FLIR Boson or equivalent sensor. Those are pretty bulky and expensive, making it hard to use this attack without hanging out near the keyboard/keypad you want to surveil. A FLIR Lepton series[0], or similar, is much smaller, but still ~$160/ea., and even though it is "smaller", it's not as easy to hide in an ATM as a cheap pinhole camera. It is also much lower resolution and has lower thermal sensitivity. Which would most likely greatly reduce the places where you could deploy this equip in a leave-behind covert setup. It looks like a neat proof of concept, but probably not a day to day risk the average person needs to be concerned about. [0] https://www.digikey.com/en/products/detail/flir-lepton/500-0643-00/5215151 https://www.digikey.com/en/products/detail/flir-lepton/500-0...
- AstralStorm 4y agoYes, you're much more likely to have a regular camera installed on the ATM or keypad. Night vision makes it work at all times. Or you can instrument a keypad with a laser sensor overlay. The IR camera is used to defeat obscured keypads only...
- DigitallyFidget 4y agoThis isn't news to me at all. For ATM/Pin pads, I wipe my fingers across every button as I press in the code, so it obscures what was actually pressed, and linger fingers on keys not even in my pin code. With enough practice, it doesn't take more than a second or two longer than normally entering it. As far as keyboards, I really don't ever interact with computers that don't belong to me or aren't in a secure area, but I have a custom scripted "keyboard" USB circuit thing that emulates keypresses for me. I don't know what to even call it, but it's like a mini Arduino sorta thing that emulates a generic Microsoft keyboard to whatever you plug it into. It looks like a stick of RAM with a USB plug, kinda. I have a few preset buttons that'll type in my login info to automate logging into things. I made it as a hardware password manager.
- woeh 4y agoI've been in a hotel where the rooms had pin pads as locks that required you to press two random numbers every time you want to enter. The pad was a bit sensitive to fingerprints, but due to this mechanism there would be fingerprints all over the device.
- marbu 4y agoIndeed, this is not a new idea. The news here is about particular implementation for extracting passwords from QWERTY keyboards. That said, this is not a big problem for ATM pin pads with metal keys, because these conduct heat well and so a heat pattern is hard to detect after few seconds. See: https://www.youtube.com/watch?v=PJCfTlQ82Fw https://www.youtube.com/watch?v=PJCfTlQ82Fw
- billsmithaustin 4y agoThermally insulated password gloves?
- Bakary 4y agoAugust Dvorak was more prescient than we ever gave him credit for!
- oogabooga13 4y agoThis was a way to get through a level in Tom Clancy's Splinter Cell (the original game) 20 years ago. https://youtu.be/lVNlggJECwc?t=507 https://youtu.be/lVNlggJECwc?t=507
- vivegi 4y agoMy bank ATM randomly sends a One-time-passcode to my mobile phone and challenges me to enter that on the ATM pinpad (in addition to my ATM pin). This is especially true when I try to withdraw from an ATM that is not my usual location (or I guess is an ATM at a location that is internally flagged for high number of ATM fraud incidents).
- mardoik 4y agoNow I feel better about using a password manager.
- tpoacher 4y agoThere's a bit of a problem in academia / academic papers, where the researchers feel compelled to comment on "impact", i.e., "why is this important / what are the implications". This is often required by the journal / reviewers as well. I confess I have been guilty of it as well (both as an author and as a reviewer). Which is not bad in itself, but sometimes there's no obvious immediate impact. That's the beauty of science. You do it to learn about something, and somebody may be interested in that something further down the line. E.g. MRI research came from hypercolliders / space research. It's unlikely particle smashers wrote "this could be used to generate medical images" in their conclusions section. At most they probably wrote "this could be used to create black holes and kill everybody" instead. (/s) Having to come up with a half-baked impact case as an afterthought in the conclusion, often manages to ruin the entire paper for me. It's the case for this article too. I was like, "wow, wow, wow, interesting", until I reached the "this could be used to ban thermal cameras" part, at which point I was "no, no, no, God no".