SpyPhone Patrick Traynor shows off the "SpiPhone" app he created to tap keystrokes with phone accelerometers. Georgia Tech
As you logged in to write a comment this morning, think about where your smartphone was sitting. Was it next to your keyboard, where you could ensure you didn’t miss any notifications? If so, your phone could track everything you wrote. It could use the accelerometer to detect keyboard vibrations, deciphering every word of your insightful anonymous commentary. A hacker could conceivably use it to find out everything you write, with up to 80 percent accuracy, researchers say.
Here’s how it would work: An accelerometer samples a phone’s vibration about 100 times per second, so it would be able to detect pairs of keystrokes, according to a Georgia Tech news release about this research. It would model “keyboard events” and determine where the pairs of keys are located on the keyboard, and how far apart they are. Then it would compare the results against a dictionary the researchers developed for this demonstration. The dictionary defines words based on their locations on a typical QWERTY keyboard, like left/right or near/far. So in Georgia Tech’s example, the word “canoe” would translate to c-a, a-n, n-o, o-e possibilities. That works out to left-left-near, and so on. The location code is checked against the dictionary, and it turns up “canoe” as the most likely word.
Related ArticlesA DIY UAV That Hacks Wi-Fi Networks, Cracks Passwords, and Poses as a Cell Phone TowerYour iPhone Keeps a Secret Log of Everywhere You Go, Security Experts FindLast Shuttle Mission Will Carry iPhones to the Space StationTagsTechnology, Rebecca Boyle, accelerometer, iphone, keystrokes, malware, smartphones, spying, spyware, typingUsing a dictionary of about 58,000 words, the researchers were able to decipher typing with about 80 percent accuracy.
Researchers have studied smartphone as spy-phone before, using the phones’ microphones to sample vibrations and decipher keystrokes. But they are very sensitive and so a much more obvious security risk — many smartphones now will ask users to give a new app permission to access sensors like microphones. Not accelerometers, however. So how would an app with this capability get onto your smartphone? The authors of this study say it would probably be included as malware on an innocent-seeming app. Then when the phone is placed next to a keyboard, the malware turns on and starts listening, sending data to a hacker who wants to know what you have to say.
Granted, this all works only if your phone is pretty proximate to your keyboard, admits Patrick Traynor, an assistant professor in Georgia Tech’s School of Computer Science who was involved in the study. So just keep it elsewhere on your desk or in your bag. Plus it’s unlikely that anyone has to worry about this right now, he added.
“This was really hard to do. But could people do it if they really wanted to? We think yes.”
The work is being presented Thursday at the ACM Conference on Computer and Communications Security in Chicago.
Previous Article: Wearable Projector and Kinect-Like Camera Turns Any Object Into a TouchscreenNext Article: Germany's ROSAT Satellite Could Come Crashing Down Somewhere On Earth As Soon As Friday 3 Comments Link to this comment Midoman 10/19/11 at 11:39 amSuperPhones take Phreaking to a whole new level.
Link to this comment Q 10/19/11 at 12:42 pmThe CIA, FBI, others and other countries have been doing this for years, but with big large electronics. I suppose what is novel today it's now an App.
Besides Governmental offices locking down what type of cell phones can be brought into their areas, this also applies to civilian companies.
This will open the door to gaining access to logins and passwords, everywhere.
Just listen and record the clicks several days in a row. Will an average 80% copy quality; it should only take a few days of listening to find the login and password.
To comment, please Login. Popular TagsTechnology NASA International Space Station robots space DARPA computers UAVs drones Boeing satellites All Tags All Photos All Videos Photo GalleriesRSS LinkTechnologyArchive Gallery: Classic Thrill Rides and Carnival AttractionsGallery: The X Prize Oil Cleanup ChallengeGallery: Inside a Knife Factory+ More Photo Galleries
Popular Science+ For iPad
Each issue has been completely reimagined for your iPad. See our amazing new vision for magazines that goes far beyond the printed page
Download Our App
Stay up to date on the latest news of the future of science and technology from your iPhone or Android phone with full articles, images and offline viewing
Follow Us On Twitter
Featuring every article from the magazine and website, plus links from around the Web. Also see our PopSci DIY feed
October 2011: The Search for Alien Life
This month, we examine all the ways we're looking for extraterrestrial life, within our solar system and beyond.
Plus: Our annual Brilliant 10 list of young researchers, the story behind that "arsenic-based life form found" story, birth control for wildlife, and much more.
Read the issue here.
Find out more
Enter here
Learn more
Copyright © 2009 Popular ScienceA Bonnier Corporation Company. All rights reserved. Reproduction in whole or in part without permission is prohibited. bmxmag-ps
No comments:
Post a Comment