New AI can hear what you type

Dopious

Elite Member
Jr. VIP
Joined
Apr 4, 2009
Messages
13,911
Reaction score
70,951
With 95 percent accuracy, the method can potentially be used to steal login credentials and other sensitive information.

A group of researchers in the UK say they have successfully trained a sound classification algorithm so that it can use data from commonly used microphones to hear what someone is typing on a keyboard - with as much as 95 per cent certainty. The machine learning model could thus be used to steal login details and other sensitive information.

In the report, the researchers give various suggestions on how to protect oneself against the attack method. For example, by varying their writing style, using randomly generated passwords or a password manager that means that information does not have to be entered manually. Other methods are to play background noise as white noise while typing or to use software-based sound filters for keystrokes. The attack method would also not be able to be used on occasions when biometric authentication is required.

https://www.bleepingcomputer.com/ne...ata-from-keystrokes-with-95-percent-accuracy/
 
Laptops with fingerprint sensors will skyrocket in sales if that's the case
 
Its not practical and there is way easier methods for hackers to gain your passwords and what not. Imagine having to get samples of all keystrokes from targets keyboard and gather what target typed when producing those sounds just so your shitty AI can "learn" how it sounds and even the minimal changes on the keyboard can mess up the results then.

Technically, hacker would require a keylogger on your device so he could do this, but since he already has keylogger on your device, why would he do it? :D
 
Its not practical and there is way easier methods for hackers to gain your passwords and what not. Imagine having to get samples of all keystrokes from the target keyboard.
You don't have to get the samples of keystrokes from the target's keyboard specifically. You can get it from any keyboard and it will work on any target as long as the models are same.

Imagine how many people use a macbook. All macbook made in the last 2 years share the same keyboard. That means you can rent one for a day, train your model on it and snoop passwords by sound.

You can go to a local Starbucks, hold a microphone near someone with a macbook, and you can get whatever they type! How crazy is that.
 
You don't have to get the samples of keystrokes from the target's keyboard specifically. You can get it from any keyboard and it will work on any target as long as the models are same.

Imagine how many people use a macbook. All macbook made in the last 2 years share the same keyboard. That means you can rent one for a day, train your model on it and snoop passwords by sound.

You can go to a local Starbucks, hold a microphone near someone with a macbook, and you can get whatever they type! How crazy is that.
Not true. Its HIGHLY unlikely that even the same units will sound exactly the same. Also new keyboard vs used keyboard, there is a big difference. Additional background sounds also make difference. They also didnt take into calculation how it performs with overlapping sounds when someone is typing fast. There is many variables they didnt include in here. Just because its possible in perfect lab environment doesnt mean it makes any sense in real life.
 
. Its HIGHLY unlikely that even the same units will sound exactly the same. Also new keyboard vs used keyboard, there is a big difference. Additional background sounds also make difference. They also didnt take into calculation how it performs with overlapping sounds when someone is typing fast. There is many variables they didnt include in here. Just because its possible in perfect lab environment doesnt mean it makes any sense in real life.
They don't need to sound the same, they just need to sound similar. The models can be fine-tuned for all sorts of error correction. It's just a matter of data and signal processing.

Same for background noise and overlapping sounds. Matter of isolation and signal processing.

Also, the model is already capable of detecting sounds from fast typing. They tested it over a zoom call with someone typing at 40 wpm, that's fast enough for overlaps. It's still accurate upto 40% for alphanumeric keys even if you change your typing styles.

It's not an attack your average phising-hacker can pull off, but something for the NSA,CIA and other 3 letter guys to refine and use on a critical target.

Read the original paper
https://arxiv.org/pdf/2308.01074.pdf
 
They don't need to sound the same, they just need to sound similar. The models can be fine-tuned for all sorts of error correction. It's just a matter of data and signal processing.

Same for background noise and overlapping sounds. Matter of isolation and signal processing.

Also, the model is already capable of detecting sounds from fast typing. They tested it over a zoom call with someone typing at 40 wpm, that's fast enough for overlaps. It's still accurate upto 40% for alphanumeric keys even if you change your typing styles.

It's not an attack your average phising-hacker can pull off, but something for the NSA,CIA and other 3 letter guys to refine and use on a critical target.

Read the original paper
https://arxiv.org/pdf/2308.01074.pdf
NSA, CIA and others already basically have access to all of our devices through intel and amd backdoors and many other ways, i dont mind about them since its almost impossible to protect yourself from them. But i still think you are giving it too much praise.
 
Soon we'll all realize the only way to disconnect is to actually not physically go near any of these devices. For leisure, leave your phone at the hotel, take a photo camera with you instead. Problem fixed. For work there's no way to escape, they're watching us 24x7
 
But i still think you are giving it too much praise.
I do not mean to say it's not error-prone or smth.
It's just very discreet. Other side channel attacks require a lot of info from precision process timing to whatnot. This is just...listening for sound. And has alot of space for refinement.

The fact that you can pull off that much info from such a small signal is worthy of praise imo.
 
I do not mean to say it's not error-prone or smth.
It's just very discreet. Other side channel attacks require a lot of info from precision process timing to whatnot. This is just...listening for sound. And has alot of space for refinement.

The fact that you can pull off that much info from such a small signal is worthy of praise imo.
it is, but i still dont think there is much practical scenarios for regular hackers who are the problem that normal people usually have

if i was having a coffee in public with my laptop i would still worry way more about the wifi im connected to than if someone is close enough to me to record what im typing
 
With 95 percent accuracy, the method can potentially be used to steal login credentials and other sensitive information.

A group of researchers in the UK say they have successfully trained a sound classification algorithm so that it can use data from commonly used microphones to hear what someone is typing on a keyboard - with as much as 95 per cent certainty. The machine learning model could thus be used to steal login details and other sensitive information.

In the report, the researchers give various suggestions on how to protect oneself against the attack method. For example, by varying their writing style, using randomly generated passwords or a password manager that means that information does not have to be entered manually. Other methods are to play background noise as white noise while typing or to use software-based sound filters for keystrokes. The attack method would also not be able to be used on occasions when biometric authentication is required.

https://www.bleepingcomputer.com/news/security/new-acoustic-attack-steals-data-from-keystrokes-with-95-percent-accuracy/
That is a big no no no haha, hope they don't make it
 
Now it's scary using an internet connected device without not been monitored.
 
Back
Top