Researchers warn that current password-based security protections could deteriorate if hijackers start using artificial intelligence-assisted thermal imaging to determine passwords shortly after they are entered. Researchers at the University of Glasgow have unveiled a method to guess recently entered passwords on keyboards and phone screens with high accuracy by imaging the heat signature of users' fingers.
The technique's success rate varies with time, materials and password length, but could worsen a recent uptick in device thefts.
Thieves have recently begun stealing and breaking into phones and other devices by watching users enter their passwords in public places. Logging in with a victim's password is a straightforward way to overcome all the security measures that companies like Apple and Google have painstakingly put in place, and once someone steals and logs into their device, there's nothing the victim can do.
However, a successful identity theft requires the perpetrator to remember the password as they see it, or to record the victim as they enter it. The researchers' new method could give thieves a wider window into deciphering passwords after someone types them in.
If a person takes a picture of the screen or keyboard with a thermal camera within a minute of entering their password, the AI can reliably guess the sequence of key presses. The system, called ThermoScure, has a success rate of at least 62 percent, depending on the conditions.
Timing is of the essence, and ThermoSecure had an 86% success rate when analyzing photos taken within 20 seconds of entering a password. The success rate dropped to 76% at 30 seconds and to 62% after one minute.
Longer passwords reduce the effectiveness of the system to some extent. ThermoSecure can guess a 16-character password 67 percent of the time in images taken within 20 seconds of someone entering the password. The guess rate rose to 82% for 12-character passwords, 93% for 8-character passwords, and 100% for 6-character passwords. These results make any non-alphanumeric iPhone passcode a prime target for the system, as simple passcodes for the device can be up to six numbers.
As with keyboards, other factors such as typing style and materials can also affect ThermoSecure's accuracy. From a 30-second thermal signature image, the system could guess the passwords of touch-typists 80% of the time and the passwords of predatory users 92% of the time. Meanwhile, keys made of PBT plastic reduce the success rate to 14%, while ABS plastic only reduces it to about 50%. Backlit keyboards are also safer because they generate more heat and hide thermal fingerprints.
Identity thieves already have easy and cheap access to thermal cameras. While methods to combine them with AI-driven guesswork are not yet available, this study appears to prove the theory, giving users more reason to enact strong security measures. They should avoid entering passwords where others can see them and use other authentication methods, such as biometrics, where possible.
Previous article:How much does it cost to hack a Starlink satellite terminal? $25
Next article:Quantum lidar acquires 3D images underwater and is expected to be used in fields such as security and defense
- Popular Resources
- Popular amplifiers
- These exhibits at the Zhuhai Air Show are eye-catching
- Mir T527 series core board, high-performance vehicle video surveillance, departmental standard all-in-one solution
- Akamai Expands Control Over Media Platforms with New Video Workflow Capabilities
- Tsinghua Unigroup launches the world's first open architecture security chip E450R, which has obtained the National Security Level 2 Certification
- Pickering exhibits a variety of modular signal switches and simulation solutions at the Defense Electronics Show
- Parker Hannifin Launches Service Master COMPACT Measuring Device for Field Monitoring and Diagnostics
- Connection and distance: A new trend in security cameras - Wi-Fi HaLow brings longer transmission distance and lower power consumption
- Smartway made a strong appearance at the 2023 CPSE Expo with a number of blockbuster products
- Dual-wheel drive, Intellifusion launches 12TOPS edge vision SoC
- Intel promotes AI with multi-dimensional efforts in technology, application, and ecology
- ChinaJoy Qualcomm Snapdragon Theme Pavilion takes you to experience the new changes in digital entertainment in the 5G era
- Infineon's latest generation IGBT technology platform enables precise control of speed and position
- Two test methods for LED lighting life
- Don't Let Lightning Induced Surges Scare You
- Application of brushless motor controller ML4425/4426
- Easy identification of LED power supply quality
- World's first integrated photovoltaic solar system completed in Israel
- Sliding window mean filter for avr microcontroller AD conversion
- What does call mean in the detailed explanation of ABB robot programming instructions?
- Breaking through the intelligent competition, Changan Automobile opens the "God's perspective"
- The world's first fully digital chassis, looking forward to the debut of the U7 PHEV and EV versions
- Design of automotive LIN communication simulator based on Renesas MCU
- When will solid-state batteries become popular?
- Adding solid-state batteries, CATL wants to continue to be the "King of Ning"
- The agency predicts that my country's public electric vehicle charging piles will reach 3.6 million this year, accounting for nearly 70% of the world
- U.S. senators urge NHTSA to issue new vehicle safety rules
- Giants step up investment, accelerating the application of solid-state batteries
- Guangzhou Auto Show: End-to-end competition accelerates, autonomous driving fully impacts luxury...
- Lotus launches ultra-900V hybrid technology "Luyao" to accelerate the "Win26" plan
- Learn about the MSP430F5438A interrupt system
- ADI Award-winning Live Broadcast: Things about Inertial MEMS Applications
- Ask about EG8010 comparator positive feedback
- Design of multi-rate electric energy meter based on SD2000 series chip
- Topology Selection of Bidirectional DCDC Converter
- Keep flooding and send a MMDS high gain antenna
- [Second Batch of Shortlist] 2022 Digi-Key Innovation Design Competition
- Will MakeCode support Python?
- What are the specific differences between triodes and MOS tubes?
- Teach you how to design an accurate and thermally efficient wearable body temperature detection system?