12 ms·
Any page loaded in IE can track your mouse movements anywhere
- lini 14y agoOriginal Bugtraq post for those that are interested: http://seclists.org/bugtraq/2012/Dec/81 http://seclists.org/bugtraq/2012/Dec/81
- benologist 14y agoInteresting that this has been around for so long. What are the ramifications of leaking mouse/ctrl/alt/shift if they don't have any context about what you are clicking on?
- DanBC 14y agoAs others have said, some clicks are going to be things on a screen-keypad. The pad can be anywhere on the screen, and it can be in a different place each time, but you'd be able to capture repeated patterns of clicks.
- jtchang 14y agoWho says they don't have any context? Off the top of my head I know ingdirect had a virtual pinpad. Combine this with a XSS vulnerability Icould easily send you a link to login to your bank website. The link would then load this type of mouse tracking data.
- nl 14y agoThe INGDirect virtual pinpad changes the arrangement of the numbers everytime it loads and hides them when you click. That does provide some protection.
- nwh 14y agoI keep seeing websites use those things, and it drives me utterly insane. Not only is it an onscreen keyboard, but nothing stays still when I'm using the damn thing. I hope more websites don't think it's a good idea.
- taeric 14y agoI was under the impression this was actually a pretty good defence against usb keyloggers that are trivial to install on a public computer. Is that not the case? (Folks just not that concerned about that vector anymore?)
- nwh 14y agoIf someone has enough access to a computer to install a keylogger, they probably have more than enough access to just read whatever is being "typed" using the on screen keyboards. Inject javascript, read it out of the browsers memory, whatever. Of course you could be using such a system to defend against a hardware keylogger, in which case I'd be thinking long and hard, trying to decide who I pissed off. Edit: Just realised you /were/ referring to a hardware keylogger. My apologies.
- ZoFreX 14y agoYes, if someone had access to install arbitrary software on your computer they could attempt to get behind any on-screen keyboards... but given the wide variety of them, and how hard it would be to detect one based on its code alone, I doubt anyone would bother. Software keyloggers log which keys you type (obviously) but some also take a screenshot whenever you click to defeat on-screen keyboards. It sounds like INGDirect's keypad is designed to defeat this attack.
- eli 14y agoYup, I assume that's the idea. I can't imagine many consumer banking accounts are hacked via hardware keylogger though. Presumably if you have physical access to a computer, you can usually install software on it anyway. A well positioned webcam could probably see what you're clicking on with the onscreen password prompt as well.
- Too 14y agoWhat kind of security by obscurity banks are people using where they have to enter numbers with the mouse to avoid keyloggers and answer to silly questions like my mothers last occupation??! Any reputable bank will give you a small external card reader with a keypad where you have to insert your smartcard, enter your pin and a punch in the challenge-response code from the website. 2-factor authentication is a solved problem, plus no risk of keyloggers since the device is disconnected from the computer. (Most come with the option of connecting to the computer via usb to save you from manually entering the challenge-response but your pin is always entered on the external keypad.)
- ZoFreX 14y agoUgh, what a hassle. My bank only required the card reader for potentially harmful things, like transferring money to someone I've never sent money to before. If it asked me to use it every time I logged in then I would change bank.
- meaty 14y agoLooking at the holes and crocks of shit we see every damn day related to HTTP, HTML, JavaScript and the whole programming model that surrounds them, it's about time someone just shot it all and started again putting security and privacy first rather than playing whack-a-mole all the time. Unfortunately I fear this is not possible based on the sheer momentum that this ball of sticky tape and string has. I think the sheer number of articles that paper HN all the time over browser and protocol vulnerabilities, leaks and problems back up my assertion. EDIT: just to add, my frustrations are based on having to spend 5 hours porting some JS code so it works properly on all browsers.
- lucian1900 14y agoAnything you replace it with will have tons of vulnerabilities as well. Formal verification might help, but that's entirely orthogonal to the programming model. Sure, it sucks to develop for. But it's not fundamentally impossible to make it secure and private.
- derleth 14y ago> it's about time someone just shot it all and started again putting security and privacy first rather than playing whack-a-mole all the time. I agree fully. So do the people working on Algol-68, PL/I, Multics, the Canon Cat, Plan 9, and, perhaps most relevant to this, Project Xanadu. (Esperanto probably deserves a mention here, but it's duking it out somewhere with Volapük, Ido, Interlingua, Loglan, and Lojban.)
- meaty 14y agoI think only the Plan 9 people have got the idea so far. The problem that has shot us as a race is that in the 1990s, technology became suddenly ubiquitous and whatever was lying around was glued together to fill a niche which took off before people had a chance to think about it and engineer something sound. An analogy perhaps: http://megaswf.com/s/2529389/ http://megaswf.com/s/2529389/
- eitland 14y ago
- happslappy 14y agoThis could be used to track entropy of encryption key generation(like trucrypt or, the new MEGA site, any site that employs mouse/key binding for entropy.) Damn, this is FUBAR!
- chris_wot 14y agoI find it particularly inspiring that they turned this into a game. And more inspiring still that folks spent 4 hours playing the game!
- scotty79 14y agoIt's a shame that before releasing that to the public noone gathered few terabytes of such data and put it up on torrents. We might learn a lot about how people use computers and UIs with such data.
- algorias 14y agoRight, and the affected people's right to privacy be damned...
- scotty79 14y agoYes. But I think the data would be also useful if you don't include IP address. This should limit the damage to acceptable levels.
- gavinjoyce 14y agoWould you be happy publishing your keystrokes if your IP address was removed?
- scotty79 14y agoIf that were only the keystrokes of alt ctrl shift then I wouldn't mind.
- blahpro 14y agos-c-o-t-t-y-7-9-<tab>-p-a-s-s-w-o-r-d
- deleted 14y ago[deleted]
- yread 14y agothis looks like keyboard input not mouse input?
- alexjeffrey 14y agoWhile this seems like something that Microsoft should fix as a matter of urgency, I don't believe the problem is as severe as is being portrayed. In order to get any meaningful information from this attack, you would need to know what application/website the user is currently using (or send them to it), where it's positioned on the screen and the exact layout of the subject. The interface would also have to be either mouse- or meta-key driven, which isn't a common facet for sensitive inputs (passwords, bank transfers, and private messages off the top of my head).
- ch0wn 14y agoI guess it shouldn't be too hard to create an algorithm that maps the movements to potential numbers on a visual type pad. Once you have the numbers, you just need to match them to patterns which could be cc numbers, phone numbers, bank accounts and so on. You just need to collect enough to find some useful data.
- njr123 14y agoAs they mention in the article, if the user is using an onscreen keyboard, then the trace essentially amounts to a keylog. And since on screen keyboard usage would have very distinctive patterns, if you had a large enough dataset, you should be able to extract those logs relatively easily.
- slashdotdash 14y agoHas anyone tried this with Microsoft's Surface tablet to find out whether the on-screen keyboard can be tracked?
- ygra 14y agoI guess the on-screen keyboard when used with a finger won't yield any mouse move events.
- deleted 14y ago[deleted]
- 14y ago
- colkassad 14y ago>The vulnerability is already being exploited by at least two display ad analytics companies across billions of page impressions per month. Who are these companies?
- 3825 14y agoName no names please. Don't want a witch hunt when we are in a glass house.
- deleted 14y ago[deleted]
- javajosh 14y agoHonestly, I don't understand this reluctance to name wrongdoers, especially for something like this where verifying the wrong is trivial (e.g. load up a client site and find the offending code in source). It seems to me that the harm is greater not naming names - reputation is important and if you take steps to invade user's privacy then your reputation can and should suffer for it.
- saraid216 14y agoMy first thought on reading this was, "Ah. 3825 works for one of them."
- 14y ago
- wahsd 14y agoKind of ironic considering Windows 8 visual/swipe password feature. Which, in general, is quite novel and interesting, albeit not very secure for various other reasons.
- snarfy 14y agoThe proof-of-concept should be a page that tracks the swipes and can then log in on Windows 8. I bet then Microsoft would prioritize fixing it.
- ygra 14y agoIt cannot. The log-on gesture is made on a completely different desktop under a completely different user account. If that worked then Microsoft would have a much more severe problem to fix.
- abdophoto 14y agoFreaking IE. I hate that damn browser
- alpb 14y agoThis is not correct. When I run it on IE, first it asks permission to run ActiveX controls on my browser, which I don't allow if I trust. Then of course, it is just like Flash, it can track your mouse.
- jey 14y agoWhere in the exploit HTML + JS is the ActiveX component being invoked from?
- blahpro 14y agoThis is probably related to the YouTube video embed on the demo page, which I believe uses Flash. The mouse tracking itself is entirely JavaScript. Edit: I am one of the authors of the demo code included in the disclosure.
- wlesieutre 14y agoI received no ActiveX warning with Windows 7 and IE9. What version are you running?
- alpb 14y agoIE10.
- navneetpandey 14y agoI have no problem at all, whether they track mouse movement or anything else. You know why? because I use Chrome.
- rossc1 14y agoIs there any, any whatsoever, evidence to say that this exploit has ever been exploited? It seems far fetched. And if your using a virtual keyboard for security... you'd be using IE? C'mon now.
- bonjourmr 14y agoThis should scare customers whose bank uses a login system such as this, correct? https://online.westpac.com.au/esis/Login/SrvPage?referrer=http%3A%2F%2Fwww.westpac.com.au%2Fpersonal-banking%2F https://online.westpac.com.au/esis/Login/SrvPage?referrer=ht...
- goggles99 14y agoThis is so low risk, why even bother posting it? Zero days come out every month or two with far better attack vectors. Criminals are not going to waste their time with this rubbish.
- blahpro 14y agoJust to point out how ridiculous this is: you can get mouse position information from any event (fired programatically using fireEvent or otherwise). You can even get it from the "onbounce" event on <marquee> elements, for goodness’ sake.