Showing posts with label Smartphone. Show all posts
Showing posts with label Smartphone. Show all posts

Thursday, 17 November 2011

iPhone turned into spiPhone: Smartphone senses nearby keyboard vibrations and deciphers sentences

ScienceDaily (Oct. 18, 2011) — It's a pattern that no doubt repeats itself daily in hundreds of millions of offices around the world: People sit down, turn on their computers, set their mobile phones on their desks and begin to work. What if a hacker could use that phone to track what the person was typing on the keyboard just inches away?

A research team at Georgia Tech has discovered how to do exactly that, using a smartphone accelerometer -- the internal device that detects when and how the phone is tilted -- to sense keyboard vibrations and decipher complete sentences with up to 80 percent accuracy. The procedure is not easy, they say, but is definitely possible with the latest generations of smartphones.

"We first tried our experiments with an iPhone 3GS, and the results were difficult to read," said Patrick Traynor, assistant professor in Georgia Tech's School of Computer Science. "But then we tried an iPhone 4, which has an added gyroscope to clean up the accelerometer noise, and the results were much better. We believe that most smartphones made in the past two years are sophisticated enough to launch this attack."

Previously, Traynor said, researchers have accomplished similar results using microphones, but a microphone is a much more sensitive instrument than an accelerometer. A typical smartphone's microphone samples vibration roughly 44,000 times per second, while even newer phones' accelerometers sample just 100 times per second -- two full orders of magnitude less often. Plus, manufacturers have installed security around a phone's microphone; the phone's operating system is programmed to ask users whether to give new applications access to most built-in sensors, including the microphone. Accelerometers typically are not protected in this way.

The technique works through probability and by detecting pairs of keystrokes, rather than individual keys (which still is too difficult to accomplish reliably, Traynor said). It models "keyboard events" in pairs, then determines whether the pair of keys pressed is on the left versus right side of the keyboard, and whether they are close together or far apart. After the system has determined these characteristics for each pair of keys depressed, it compares the results against a preloaded dictionary, each word of which has been broken down along similar measurements (i.e., are the letters left/right, near/far on a standard QWERTY keyboard). Finally, the technique only works reliably on words of three or more letters.

For example, take the word "canoe," which when typed breaks down into four keystroke pairs: "C-A, A-N, N-O and O-E." Those pairs then translate into the detection system's code as follows: Left-Left-Near, Left-Right-Far, Right-Right-Far and Right-Left-Far, or LLN-LRF-RRF-RLF. This code is then compared to the preloaded dictionary and yields "canoe" as the statistically probable typed word. Working with dictionaries comprising about 58,000 words, the system reached word-recovery rates as high as 80 percent.

"The way we see this attack working is that you, the phone's owner, would request or be asked to download an innocuous-looking application, which doesn't ask you for the use of any suspicious phone sensors," said Henry Carter, a PhD student in computer science and one of the study's co-authors. "Then the keyboard-detection malware is turned on, and the next time you place your phone next to the keyboard and start typing, it starts listening."

Mitigation strategies for this vulnerability are pretty simple and straightforward, Traynor said. First, since the study found an effective range of just three inches from a keyboard, phone users can simply leave their phones in their purses or pockets, or just move them further away from the keyboard. But a fix that puts less onus on users is to add a layer of security for phone accelerometers.

"The sampling rate for accelerometers is already pretty low, and if you cut it in half, you start to approach theoretical limitations that prevent eavesdropping. The malware simply does not have the data to work with," Traynor said. "But most phone applications can still function even with that lower accelerometer rate. So manufacturers could set that as the default rate, and if someone downloads an application like a game that needs the higher sampling rate, that would prompt a permission question to the user to reset the accelerometer."

In the meantime, Traynor said, users shouldn't be paranoid that hackers are tracking their keystrokes through their iPhones.

"The likelihood of someone falling victim to an attack like this right now is pretty low," he said. "This was really hard to do. But could people do it if they really wanted to? We think yes."

The finding is reported in the paper, "(sp)iPhone: Decoding Vibrations From Nearby Keyboards Using Mobile Phone Accelerometers," and will be presented on Oct. 20, at the 18th ACM Conference on Computer and Communications Security in Chicago. In addition to Carter, Traynor's coauthors include Georgia Tech graduate student Arunabh Verman and Philip Marquardt of the MIT Lincoln Laboratory.

Recommend this story on Facebook, Twitter,
and Google +1:

Other bookmarking and sharing tools:

Story Source:

The above story is reprinted from materials provided by Georgia Institute of Technology.

Note: ScienceDaily reserves the right to edit materials for content and length. For further information, please contact the source cited above.

Note: If no author is given, the source is cited instead.

Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.


View the original article here

Sunday, 13 November 2011

iPhone turned into spiPhone: Smartphone senses nearby keyboard vibrations and deciphers sentences

ScienceDaily (Oct. 18, 2011) — It's a pattern that no doubt repeats itself daily in hundreds of millions of offices around the world: People sit down, turn on their computers, set their mobile phones on their desks and begin to work. What if a hacker could use that phone to track what the person was typing on the keyboard just inches away?

A research team at Georgia Tech has discovered how to do exactly that, using a smartphone accelerometer -- the internal device that detects when and how the phone is tilted -- to sense keyboard vibrations and decipher complete sentences with up to 80 percent accuracy. The procedure is not easy, they say, but is definitely possible with the latest generations of smartphones.

"We first tried our experiments with an iPhone 3GS, and the results were difficult to read," said Patrick Traynor, assistant professor in Georgia Tech's School of Computer Science. "But then we tried an iPhone 4, which has an added gyroscope to clean up the accelerometer noise, and the results were much better. We believe that most smartphones made in the past two years are sophisticated enough to launch this attack."

Previously, Traynor said, researchers have accomplished similar results using microphones, but a microphone is a much more sensitive instrument than an accelerometer. A typical smartphone's microphone samples vibration roughly 44,000 times per second, while even newer phones' accelerometers sample just 100 times per second -- two full orders of magnitude less often. Plus, manufacturers have installed security around a phone's microphone; the phone's operating system is programmed to ask users whether to give new applications access to most built-in sensors, including the microphone. Accelerometers typically are not protected in this way.

The technique works through probability and by detecting pairs of keystrokes, rather than individual keys (which still is too difficult to accomplish reliably, Traynor said). It models "keyboard events" in pairs, then determines whether the pair of keys pressed is on the left versus right side of the keyboard, and whether they are close together or far apart. After the system has determined these characteristics for each pair of keys depressed, it compares the results against a preloaded dictionary, each word of which has been broken down along similar measurements (i.e., are the letters left/right, near/far on a standard QWERTY keyboard). Finally, the technique only works reliably on words of three or more letters.

For example, take the word "canoe," which when typed breaks down into four keystroke pairs: "C-A, A-N, N-O and O-E." Those pairs then translate into the detection system's code as follows: Left-Left-Near, Left-Right-Far, Right-Right-Far and Right-Left-Far, or LLN-LRF-RRF-RLF. This code is then compared to the preloaded dictionary and yields "canoe" as the statistically probable typed word. Working with dictionaries comprising about 58,000 words, the system reached word-recovery rates as high as 80 percent.

"The way we see this attack working is that you, the phone's owner, would request or be asked to download an innocuous-looking application, which doesn't ask you for the use of any suspicious phone sensors," said Henry Carter, a PhD student in computer science and one of the study's co-authors. "Then the keyboard-detection malware is turned on, and the next time you place your phone next to the keyboard and start typing, it starts listening."

Mitigation strategies for this vulnerability are pretty simple and straightforward, Traynor said. First, since the study found an effective range of just three inches from a keyboard, phone users can simply leave their phones in their purses or pockets, or just move them further away from the keyboard. But a fix that puts less onus on users is to add a layer of security for phone accelerometers.

"The sampling rate for accelerometers is already pretty low, and if you cut it in half, you start to approach theoretical limitations that prevent eavesdropping. The malware simply does not have the data to work with," Traynor said. "But most phone applications can still function even with that lower accelerometer rate. So manufacturers could set that as the default rate, and if someone downloads an application like a game that needs the higher sampling rate, that would prompt a permission question to the user to reset the accelerometer."

In the meantime, Traynor said, users shouldn't be paranoid that hackers are tracking their keystrokes through their iPhones.

"The likelihood of someone falling victim to an attack like this right now is pretty low," he said. "This was really hard to do. But could people do it if they really wanted to? We think yes."

The finding is reported in the paper, "(sp)iPhone: Decoding Vibrations From Nearby Keyboards Using Mobile Phone Accelerometers," and will be presented on Oct. 20, at the 18th ACM Conference on Computer and Communications Security in Chicago. In addition to Carter, Traynor's coauthors include Georgia Tech graduate student Arunabh Verman and Philip Marquardt of the MIT Lincoln Laboratory.

Recommend this story on Facebook, Twitter,
and Google +1:

Other bookmarking and sharing tools:

Story Source:

The above story is reprinted from materials provided by Georgia Institute of Technology.

Note: ScienceDaily reserves the right to edit materials for content and length. For further information, please contact the source cited above.

Note: If no author is given, the source is cited instead.

Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.


View the original article here

Friday, 11 November 2011

Smartphone Accelerometers Could Be Used To Eavesdrop On Nearby Devices

Smartphone Accelerometers Could Be Used To Eavesdrop On Nearby Devices | Popular Science@import "/files/css/1857af3413d9ad8bd2f9d3926af8ec39.css";@import "/files/css/33f6b7ecb4513ed2fe6c670880a27187.css"; home Login/Register Newsletter Subscribe RSS GadgetsComputersCamerasSmartphonesVideo GamesCarsConceptsHybridsElectric CarsScienceFuture of the EnvironmentEnergyHealthPopSci Eco TourTechnologyMilitaryAviationSpaceRobotsEngineeringDIYProjectsHacksToolsAuto DIYMore From Our Partner: Toolmonger GalleriesVideosColumnsThe GrouseSex FilesGreen Dream Innovation ChallengesHow It WorksFeatures Tweet Digg Smartphone Accelerometers Could Be Used To Eavesdrop On Nearby Devices By Rebecca Boyle Posted 10.19.2011 at 11:07 am 3 Comments
SpyPhone Patrick Traynor shows off the "SpiPhone" app he created to tap keystrokes with phone accelerometers. Georgia Tech

As you logged in to write a comment this morning, think about where your smartphone was sitting. Was it next to your keyboard, where you could ensure you didn’t miss any notifications? If so, your phone could track everything you wrote. It could use the accelerometer to detect keyboard vibrations, deciphering every word of your insightful anonymous commentary. A hacker could conceivably use it to find out everything you write, with up to 80 percent accuracy, researchers say.

Here’s how it would work: An accelerometer samples a phone’s vibration about 100 times per second, so it would be able to detect pairs of keystrokes, according to a Georgia Tech news release about this research. It would model “keyboard events” and determine where the pairs of keys are located on the keyboard, and how far apart they are. Then it would compare the results against a dictionary the researchers developed for this demonstration. The dictionary defines words based on their locations on a typical QWERTY keyboard, like left/right or near/far. So in Georgia Tech’s example, the word “canoe” would translate to c-a, a-n, n-o, o-e possibilities. That works out to left-left-near, and so on. The location code is checked against the dictionary, and it turns up “canoe” as the most likely word.

Related ArticlesA DIY UAV That Hacks Wi-Fi Networks, Cracks Passwords, and Poses as a Cell Phone TowerYour iPhone Keeps a Secret Log of Everywhere You Go, Security Experts FindLast Shuttle Mission Will Carry iPhones to the Space StationTagsTechnology, Rebecca Boyle, accelerometer, iphone, keystrokes, malware, smartphones, spying, spyware, typingUsing a dictionary of about 58,000 words, the researchers were able to decipher typing with about 80 percent accuracy.

Researchers have studied smartphone as spy-phone before, using the phones’ microphones to sample vibrations and decipher keystrokes. But they are very sensitive and so a much more obvious security risk — many smartphones now will ask users to give a new app permission to access sensors like microphones. Not accelerometers, however. So how would an app with this capability get onto your smartphone? The authors of this study say it would probably be included as malware on an innocent-seeming app. Then when the phone is placed next to a keyboard, the malware turns on and starts listening, sending data to a hacker who wants to know what you have to say.

Granted, this all works only if your phone is pretty proximate to your keyboard, admits Patrick Traynor, an assistant professor in Georgia Tech’s School of Computer Science who was involved in the study. So just keep it elsewhere on your desk or in your bag. Plus it’s unlikely that anyone has to worry about this right now, he added.

“This was really hard to do. But could people do it if they really wanted to? We think yes.”

The work is being presented Thursday at the ACM Conference on Computer and Communications Security in Chicago.

Previous Article: Wearable Projector and Kinect-Like Camera Turns Any Object Into a TouchscreenNext Article: Germany's ROSAT Satellite Could Come Crashing Down Somewhere On Earth As Soon As Friday 3 Comments Link to this comment Midoman 10/19/11 at 11:39 am

SuperPhones take Phreaking to a whole new level.

Link to this comment Q 10/19/11 at 12:42 pm

The CIA, FBI, others and other countries have been doing this for years, but with big large electronics. I suppose what is novel today it's now an App.

Besides Governmental offices locking down what type of cell phones can be brought into their areas, this also applies to civilian companies.

This will open the door to gaining access to logins and passwords, everywhere.

Just listen and record the clicks several days in a row. Will an average 80% copy quality; it should only take a few days of listening to find the login and password.

To comment, please Login. Popular TagsTechnology NASA International Space Station robots space DARPA computers UAVs drones Boeing satellites All Tags All Photos All Videos Photo GalleriesRSS LinkTechnologyArchive Gallery: Classic Thrill Rides and Carnival AttractionsGallery: The X Prize Oil Cleanup ChallengeGallery: Inside a Knife Factory+ More Photo Galleries


138 years of Popular Science at your fingertips.

Innovation Challenges Make your ideas part of the revolutionNovel Barrier Materials or Formulations for Paper PackagingAward: $20,000 USDReducing Metal–Metal FrictionAward: $10,000 USDLearn morePowered by Innocentive



Popular Science+ For iPad

Each issue has been completely reimagined for your iPad. See our amazing new vision for magazines that goes far beyond the printed page



Download Our App

Stay up to date on the latest news of the future of science and technology from your iPhone or Android phone with full articles, images and offline viewing



Follow Us On Twitter

Featuring every article from the magazine and website, plus links from around the Web. Also see our PopSci DIY feed


October 2011: The Search for Alien Life

This month, we examine all the ways we're looking for extraterrestrial life, within our solar system and beyond.

Plus: Our annual Brilliant 10 list of young researchers, the story behind that "arsenic-based life form found" story, birth control for wildlife, and much more.

Read the issue here.



Find out more
Enter here
Learn more

Popular on Popsci Most Viewed TechnologyGallery: The X Prize Oil Cleanup ChallengeArchive Gallery: Classic Thrill Rides and Carnival AttractionsNavy’s Distinctly UFO-Like X-47B War Drone Makes First Flight in Cruise ModeWinner of Million-Dollar X Challenge Cleans Up Oil Spills Three Times Better Than Existing TechHomeland Security Application Monitors Crowds' Faces, Races, and Eye Movements to Detect Would-Be CriminalsAwesome but Creepy Japanese Product of the Day: Realistic 3-D Face Replicas The World's Most Failsafe Wireless Bicycle Brake Could Seed a Variety of Super-Safe TechnologiesVideo: A Homemade Rocket Soars 121,000 Feet in 92 SecondsThank You to Dennis Ritchie, Without Whom None of This Would Be HereUpdate: Iran Tried and Failed to Launch a Monkey Into Space Last Month Most Commented TechnologyVideo: Google Finally Explains the Tech Behind Their Autonomous CarsNavy’s Distinctly UFO-Like X-47B War Drone Makes First Flight in Cruise ModeThe World's Most Failsafe Wireless Bicycle Brake Could Seed a Variety of Super-Safe TechnologiesAerospace Entrepreneur/Motelier Robert Bigelow Thinks the Chinese Will Take Over the MoonNetflix Abandons Qwikster; DVDs Will Stay at NetflixVideo: South Korea's Small Robot Dog Quietly Prances AroundHomeland Security Application Monitors Crowds' Faces, Races, and Eye Movements to Detect Would-Be CriminalsVideo: A Homemade Rocket Soars 121,000 Feet in 92 SecondsPR2 Robot Learns to Scoop Up Distasteful MatterVideo: A 4,500-Pound Minesweeping, Drone-Launching, Armored Autonomous Mini-Tank Most Emailed TechnologyChinese Rare Earth Company Strokes Mustache, Cuts Off World's Access to Rare Earths to Inflate PricesVideo: A 4,500-Pound Minesweeping, Drone-Launching, Armored Autonomous Mini-TankAerospace Entrepreneur/Motelier Robert Bigelow Thinks the Chinese Will Take Over the MooniPhone Includes Russia's GLONASS Nav System Alongside GPSPretty Space Pics: A Skywatcher Captures the Cosmos Blowing a Beautiful Gas BubbleEuropean Alternative to GPS Lifts Off Tomorrow From South America, Via Russian RocketVideo: Google Finally Explains the Tech Behind Their Autonomous CarsFoambot Creates Itself Out of Sprayable Foam, Becoming Whatever Robot You NeedGermany's ROSAT Satellite Could Come Crashing Down Somewhere On Earth As Soon As FridaySmartphone Accelerometers Could Be Used To Eavesdrop On Nearby Devices circ-top-header.gif circ-cover.gif Name Address 1   City State STATE Alabama Alaska Arizona Arkansas California Colorado Connecticut Delaware DC Florida Georgia Hawaii Idaho Illinois Indiana Iowa Kansas Kentucky Louisiana Maine Maryland Massachusetts Michigan Minnesota Mississippi Missouri Montana Nebraska Nevada New Hampshire New Jersey New Mexico New York N. Carolina N. Dakota Ohio Oklahoma Oregon Pennsylvania Rhode Island S. Carolina S. Dakota Tennessee Texas Utah Vermont Virginia Washington W. Virginia Wisconsin Wyoming Zip Code Email Today on PopSci.com Archive Gallery: Steve Jobs in the Pages of Popular Science, Over Three Decades575701071Futuristic Predictions From the Past That Steve Jobs Fulfilled575381072Can Animals Really Be Gay?574881073Video: Solar Sinter Project Turns the Desert's Free Abundance of Sand and Sun into 3-D-Printed Glass 551421074Five Reasons You Should Care About the New Ozone Hole Over the Arctic574171075Archive Gallery: PopSci's Most Gigantic Portable Gadgets573651076Inside the Factory: How a Chef's Knife Is Made571741077Windows Phone 7.5 "Mango" Review: Getting Closer Now573451078Scientist in a Strange Land568431079What Is the Point of the Female Orgasm?5711610710Archive Gallery: Mail Order Kits, From the Back Pages of PopSci5719710711Baffling CERN Results Show Neutrinos Moving Faster Than the Speed of Light5720010712 Footer Menu Subscribe to the Print EditionSubscribe to the Digital EditionRenew SubscriptionCustomer ServiceSite MapAbout UsContact UsAdvertisingPrivacy PolicyTerms of UseAbuseRSS FeedsPS Showcase

 

Copyright © 2009 Popular Science

A Bonnier Corporation Company. All rights reserved. Reproduction in whole or in part without permission is prohibited.

bmxmag-ps

View the original article here