7 ms·
GAZEploit: Remote keystroke inference attack by gaze estimation in VR/MR devices
- LorenDB 2y agoI'm genuinely shocked. I assumed that Apple would have foreseen this possibility and locked the Persona's eyes somewhere as long as the user was typing, at least for passwords.
- generalizations 2y agoWhole point of the digital face is to look real though, and freezing the gaze would look unnervingly fake.
- LorenDB 2y agoBut you could at least dampen out or randomize eye travel while looking at the keyboard. Fully reproducing eye output is a recipe for disaster, and that should have been obvious.
- fidotron 2y agoOTOH once you as an outsider know that sometimes the AVP is lying to you about where the wearer is looking why would you ever trust it? For example, you could then use the AVP to stare at people and then claim afterwards you were doing no such thing.
- HeatrayEnjoyer 2y agoAdd a faint glow to indicate they're typing and the continued face animation is a stand-in.
- parasubvert 2y agoIt's about tradeoffs, the device is barely 7 months old at this point. Thankfully the fix is fairly obvious too.
- dylan604 2y agoThrow people for a loop and switch your headset keyboard to DVORAK. When they scan your eye movements and apply to QWERTY, they'll be confused AF!
- jrockway 2y agoWell, you still only have to try one other password. If you get locked out after one password attempt and nobody knows that you use dvorak, your defense works, but if you have three attempts, you can also add colemak to your list of things to try ;)
- kobalsky 2y agoadd sunglasses to the avatar while typing
- p1necone 2y agoSomeone hire this person please.
- throw10920 2y agoIt would, wouldn't it? I'd suggest blurring the face in a "password input context" (like password fields on the web with their redacted display text), but I suspect that that'd go against what Apple wants the Vision Pro experience to look like.
- dwallin 2y agoI'm confident they could come up with a filler eye animation algorithm that was convincing enough to pass muster for short periods of time. Even if hand coding something didn't quite work out, they certainly have tons of eye tracking data internally they could use to train a small model, or optimize parameters.
- dTal 2y agoThe complexity of this solution just shot up from "2 minute hack" to "2 month research project, minimum". It's understandable why they didn't do this.
- withinboredom 2y agoI don't think anyone was suggesting to go for the 'parameterized model' from the start. They could just hide the eyes while typing, as a good starting point.
- paulryanrogers 2y agoYeah. Make them appear closed, done
- underdeserver 2y agoNo way this takes two months to get to a convincing proof of concept.
- sli 2y agoIf I were implementing it and wanted to obscure, I'd blur the whole screen momentarily, probably with a small message. I really doubt that's ideal for a commercial offering, though. I'm not really worried about unnerving people if I'm using an avatar, that comes with the territory as it is.
- magicalhippo 2y agoJust have them close their eyes? That's what I do when I have to recall my password anyway.
- darby_nine 2y agoThen it shouldn't be used for secure input.
- bsza 2y agoWhy? Most people are capable of fixating at a single point with basically no perceptible eye movement.
- JamesSwift 2y agoJust do the same thing the external display does and do a 'cloudy eyes' version when they user is interacting w/ the keyboard.
- deleted 2y ago[deleted]
- talldayo 2y ago> I assumed Oh man, this is my favorite part of the Apple Design Cycle! 1. Apple announces a new feature that is suspiciously invasive and only marginally useful (eg. iCloud Screening, Find My, OCSP, etc.) 2. Self-conscious, Apple releases a security whitepaper that explains how things should work but doesn't let anyone audit their system 3. Users assume that things are okay because the marketing tells them it is okay, and do not ever consider the potential for an exploit 4. The data leaks, either to advertisers, Apple employees, warrantless government allies, government adversaries or OEM contractors 5. Apple customers attempt to absolve themselves of responsibility ("How was I supposed to know?") I've seen this process so many times at this point that I'm just apathetic to it all. Maybe one day people will learn to stop assuming the best when there is literally no evidence corroborating it.
- KerrAvon 2y agoWhat data leaks? What are you talking about?
- talldayo 2y agohttps://www.ifixit.com/News/33801/apple-genius-caught-stealing-sensitive-photos-despite-claims-that-independent-repair-is-risky https://www.ifixit.com/News/33801/apple-genius-caught-steali... https://arstechnica.com/tech-policy/2023/12/apple-admits-to-secretly-giving-governments-push-notification-data/ https://arstechnica.com/tech-policy/2023/12/apple-admits-to-... https://apple.stackexchange.com/questions/445122/is-icloud-private-relay-leaking-my-dns-queries-to-my-isp https://apple.stackexchange.com/questions/445122/is-icloud-p... Various oversight issues of that nature. Note: we could know about all of these exploits before-hand if Apple's supposedly-private infrastructure was meaningfully accountable.
- KaiserPro 2y agoThey released airtags without thinking about stalking, so I'm not that shocked.
- thebruce87m 2y agoThis has to be a lie made on purpose since it is so easily proven wrong. Here is the keynote: https://www.youtube.com/live/JdBYVNuky1M?si=46vw7FG3SjWWBezn https://www.youtube.com/live/JdBYVNuky1M?si=46vw7FG3SjWWBezn 9.25 is when they talk about unwanted tracking.
- KaiserPro 2y agoOk, if you want me to be more specific. (Given that we are talking about keynotes, which are, by design, marketing mistruths. ) They thought a bit about stalking, but not enough to alter the experience, or release tools for non-apple owners to avoid being tracked. Sure, there are some "industry leading features" but no-one else in industry decided to co-opt a network of ~1 billion devices to provide location updates. Sure Apple made it very difficult to track an airtag on a person, for the owner's privacy. But that also means that the non-owner is less able to find it. It takes about 3-5 days (although its been up to two weeks in some cases) before my various iphones twig that an errant airtag is with me. Now you might see me as someone who is anti apple, or has an agenda against apple. Thats not the case. The issue is, when you create a device like this, and marry it to such a capable platform, you have to own the side effects. It took something like _6 months_ to release an android airtag detector. Which means it was very much an after thought. Had they talked to any Domestic Violence support groups, they would have told them very clearly how these devices would be used. (I suspect they did, but that would destroy the product vision too much, so it was downgraded. )
- nicolas_17 2y agoWhat?? It had much better anti-stalking features at launch than its competitors like Tile.
- KaiserPro 2y ago
- KerrAvon 2y agoPlease note this is fixed: > The researchers alerted Apple to the vulnerability in April, and the company issued a patch to stop the potential for data to leak at the end of July
- generalizations 2y agoIt'd be pretty cyberpunk if the mitigation to this is to have your eyes digitally obscured when typing in sensitive data.
- steve1977 2y agoAnd we know the only viable option would be simulated mirror shades
- wrboyce 2y agoBut then a would-be attacker could simply read what you type in the reflections!
- __MatrixMan__ 2y agoThe shades "reflect" a password that takes you to a honeypot
- KineticLensman 2y agoAnd perhaps replaced with a cartoon ‘x’ if your life signs terminate while you are using the device
- wslh 2y agoI think the key problem with all the data we’re sharing, including telemetry, is that even when specific inputs like passwords aren’t directly visible, the information still narrows down the possible key, and password spaces.
- wslh 2y agoJust today, another news of credentials flying away: https://news.ycombinator.com/item?id=41535901 https://news.ycombinator.com/item?id=41535901
- thih9 2y ago> as long as we get enough gaze information that can accurately recover the keyboard, then all following keystrokes can be detected That’s a pretty big assumption. Also, I guess the user has to be stationary - stay in the camera’s field of view and not move their head in a way that would obstruct the image. Unless this is about intercepting in-device data; but in this case it seems easier to address.
- cassianoleal 2y ago> Also, I guess the user has to be stationary - stay in the camera’s field of view and not move their head in a way that would obstruct the image. The user is always stationary in relation to the headset and the cameras in it.
- dagmx 2y agoYes but not to the video feed that the other person sees. If you move around, your head moves too. If you stand up, you momentarily go out of frame before it applies a delayed sync. The idea being that it matches what a regular webcam would do.
- cassianoleal 2y agoI see what you mean. I doubt it's very common for people to move around that much whilst trying to type their password on the on-screen keyboard though. Sure there may be cases where the attack fails but I bet they'd be few and far between.
- adolph 2y agoShades of the Lotus Notes “Visual Hash” https://security.stackexchange.com/questions/41247/changing-picture-as-characters-entered-into-password https://security.stackexchange.com/questions/41247/changing-...
- tambourine_man 2y agoThis is remarkable. Enterprise software is its own microcosmos of pain.
- fidotron 2y agoThis deserves a separate submission. That is so bad it almost has to be a deliberate method to extract passwords.
- deleted 2y ago[deleted]
- yodon 2y agoEye tracking data is incredibly sensitive and privacy-concerning. HN tends to dislike Microsoft, but they went to great lengths to build a HoloLens system where eye tracking was both useful and safe. The eye tracking data never left the device, and was never directly available to the application. As a developer, you registered targets or gestures you were interested in, and the platform told you when the user for example looked to activate your target. Lots of subtlety and care went into the design, so yes, the first six things you think of as concerns or exploits or problems were addressed, and a bunch more you haven't thought of yet. If this is a space you care about, read up on HoloLens eye tracking. It's pretty inexcusable if Apple is providing raw eye tracking streams to app developers. The exploits are too easy any too prevalent. [EDIT ADDED: the article is behind a paywall but it sounds from comments here like Apple is not providing raw eye tracking streams, this is about 3rd parties watching your eyes to extract your virtual typing while you are on a conference call]
- simondw 2y ago> if Apple is providing raw eye tracking streams to app developers Apple is not doing that. As the article describes, the issue is that your avatar (during a FaceTime call, for example) accurately reproduces your eye movements.
- FrustratedMonky 2y agoBut the technology is there. That is the concern.
- simondw 2y agoThe technology to reproduce eye movements has been around since motion pictures were invented. I'm sure even a flat video stream of the user's face would leak similar information. Apple should have been more careful about allowing any eye motion information (including simple video) to flow out of a system where eye movements themselves are used for data input.
- 2y ago
- moron4hire 2y agoWhat if the keyboard was put in the user's off-hand and they typed on it by tapping their palm? Then the keyboard wouldn't be in a fixed position to correlate eye movement against it.
- laserbeam 2y agoIt's a probabilistic attack. Of course there are workarounds and doesn't work when people are touch typists and don't look at their keyboards... Brilliant though, just brilliant.
- bgirard 2y agoIf you look at the video, it's not only the eyes here. There's a huge head movement too. Having a keyboard so large in your FOV that you have to turn your head to type something is a contributing factor. I wonder what the accuracy is if you drop the eye tracking and only do head tracking on that demo.
- dagmx 2y agoIt would be interesting to see both isolated. I don’t think eye tracking alone would give you the necessary bounds for inferring the keyboard size. For one, eyes flit around more and also are harder to see. I also wonder how easily this attack is foiled by different key clusters. E.g it looks like they’re relying on large head movements at opposite ends of the keyboard to infer the bounds. But keyboard use can be very clustered which would foil the ability to know how wide the user has the keyboard. I imagine it also breaks when the user moves the keyboard
- sparsely 2y agoFinally all those banks with randomised input grids on their websites are validated!
- deleted 2y ago[deleted]
- falcor84 2y agoAs if there weren't enough reasons to learn touch typing.
- voidUpdate 2y agoYou type by looking at the letters on the keyboard
- falcor84 2y agoWhen I type in VR, I do it with a physical keyboard.
- toolz 2y agoHow many people are typing with their eyes to begin with? Aren't they using their hands far more often? Cool attack, but I'm not sure there's much real attack surface here if no one is typing with their gaze while using an avatar.
- outericky 2y agoyou look at the letter and pinch... that's how i do it. Not often. and not during facetime calls. But yeah... possible.
- toolz 2y agoYeah, I know you can type that way, but I have a quest3 and after watching the video I would think no one is actually typing that way. It looks to be easily twice as slow and way more annoying than just using your fingers with hand tracking.
- dagmx 2y agoThe video is definitely exaggerated because they’re moving their whole head. Typing with your eyes is much faster and more subtle than what they show here.
- deleted 2y ago[deleted]
- stretchwithme 2y agoWe need more factors of authentication. And the number required should increase with the serious of the operation. Buying lunch - 1 Selling your home - 10
- puttycat 2y agoCan this also be done for normal videos over zoom?
- deleted 2y ago[deleted]
- KaiserPro 2y agoNot really. you need to know the size of the keyboard, know the shape ov peoples eyes, have enough temporal and optical resolution to workout where they are pointing. Even with optimal conditions (ie dedicated cameras, no eye make up and correct positioning) uncalibrated gaze has at least a 5 degree uncertainty.
- dagmx 2y agoVideo for those who can’t get past the paywall https://youtu.be/DPYT8IH-R18?si=5tcQ3NJltxROJDUq https://youtu.be/DPYT8IH-R18?si=5tcQ3NJltxROJDUq
- jrockway 2y agoI think the underlying flaw here is that pointing your eyes at a virtual keyboard in space to type passwords is just a poor input method. Take away the VR headset and do the same thing and the flaw still exists. Now I want to make a keyboard where you shine a laser pointer at the key you want to press, and your cat jumping up is what actually triggers the button press.
- iwontberude 2y agoI don’t have letters on any of my keys and switch between keyboard layouts frequently. I never look at my keyboard, am I still vulnerable?
- LelouBil 2y ago> I never look at my keyboard The article title : > Gaze estimation It doesn't seem like it
- iwontberude 2y agoThat’s my thought too but maybe we subconsciously move our eyes when we type and still is a side channel.
- deleted 2y ago[deleted]
- jrockway 2y agoDefinitely not. It seems that the keyboard on Apple Vision Pro is an onscreen keyboard you type with using your eyes. The Vision Pro also broadcasts your eye movements to a screen on the front of your headset, and the combination of the two is what leaks your password. If you are just in VR looking at a virtual keyboard to type, it's no big deal. If you are typing on a physical keyboard and people are videotaping your eyes, it's no big deal. The combination of the two is the problem.
- karlgkk 2y ago> I think the underlying flaw here is that pointing your eyes at a virtual keyboard in space to type passwords is just a poor input method fwiw while you can do that, it's much easier to just poke the keys or use Siri a folding bluetooth keyboard with built in trackpad has become a must have travel accessory for me :)
- AfurikanTedoku 2y agoFirst author here. https://www.arxiv.org/abs/2409.08122 https://www.arxiv.org/abs/2409.08122 Here is our pre-print. I am happy to answer questions in this thread. :)