New AI can hear what you type

With 95 percent accuracy, the method can potentially be used to steal login credentials and other sensitive information.

A group of researchers in the UK say they have successfully trained a sound classification algorithm so that it can use data from commonly used microphones to hear what someone is typing on a keyboard - with as much as 95 per cent certainty. The machine learning model could thus be used to steal login details and other sensitive information.

In the report, the researchers give various suggestions on how to protect oneself against the attack method. For example, by varying their writing style, using randomly generated passwords or a password manager that means that information does not have to be entered manually. Other methods are to play background noise as white noise while typing or to use software-based sound filters for keystrokes. The attack method would also not be able to be used on occasions when biometric authentication is required.

https://www.bleepingcomputer.com/ne...ata-from-keystrokes-with-95-percent-accuracy/

Pretty stupid approach.
Why do you need to "listen" when you can detect which keys have been pressed?
Those British researchers need an "I" upgrade before wasting time on nonsense.
 
With 95 percent accuracy, the method can potentially be used to steal login credentials and other sensitive information.

A group of researchers in the UK say they have successfully trained a sound classification algorithm so that it can use data from commonly used microphones to hear what someone is typing on a keyboard - with as much as 95 per cent certainty. The machine learning model could thus be used to steal login details and other sensitive information.

In the report, the researchers give various suggestions on how to protect oneself against the attack method. For example, by varying their writing style, using randomly generated passwords or a password manager that means that information does not have to be entered manually. Other methods are to play background noise as white noise while typing or to use software-based sound filters for keystrokes. The attack method would also not be able to be used on occasions when biometric authentication is required.

https://www.bleepingcomputer.com/news/security/new-acoustic-attack-steals-data-from-keystrokes-with-95-percent-accuracy/
that's for amateurs. My 251-year-old keyboard bangs which ever fuckin button I click it sounds like a small fart.
 
Just to be safe, I'll start with a knife and live in the forest alone :D
 
Not true. Its HIGHLY unlikely that even the same units will sound exactly the same. Also new keyboard vs used keyboard, there is a big difference. Additional background sounds also make difference. They also didnt take into calculation how it performs with overlapping sounds when someone is typing fast. There is many variables they didnt include in here. Just because its possible in perfect lab environment doesnt mean it makes any sense in real life.
yes its always one thing to test in the lab and "in the wild". ;) just because it works in the lab doesn't mean anything. thats also something many security researchers don't understand...
however this method can be refined and i think they can make it somewhat reliable even if used against real world targets. its smart to use spectrogram from the audio instead of a linear waveform, so they can get much more data points for the model to train even if the key is recorded from different mediums (in their test a zoom call or a phone recording) and with different interferences.
they would have to collect much more data though from thousands of different keyboards and each recorded with many different devices. also they would have to do the same with different distances from the recording device, different furniture, rooms etc etc .. if this would be open sourced as a community effort, it could potentially be fairly accurate in the real world. rightnow however its just a PoC.

especially this shows that its just working in a lab test under very specific conditions:
Phone-recording mode: We used and iPhone 13 mini placed 17cm away
from the leftmost side of the laptop on a folded piece of micro-fibre cloth (shown
in Fig. 6). The purpose of the cloth was to remove some desk vibration in
the recording (as this would vary based on the type of desk used), instead
encouraging the model to learn primarily from acoustics.

another problem they didn't solve (which makes password recording problematic without further bruteforcing):
Also, while multiple methods succeeded in recognising a press of the
shift key, no paper in the surveyed literature succeeded in recognising the ‘release
peak’ of the shift key amidst the sounds of other keys, doubling the search
space of potential characters following a press of the shift key.

They don't need to sound the same, they just need to sound similar. The models can be fine-tuned for all sorts of error correction. It's just a matter of data and signal processing.

Same for background noise and overlapping sounds. Matter of isolation and signal processing.

Also, the model is already capable of detecting sounds from fast typing. They tested it over a zoom call with someone typing at 40 wpm, that's fast enough for overlaps. It's still accurate upto 40% for alphanumeric keys even if you change your typing styles.

It's not an attack your average phising-hacker can pull off, but something for the NSA,CIA and other 3 letter guys to refine and use on a critical target.

Read the original paper
https://arxiv.org/pdf/2308.01074.pdf
well like i said above, you need a lot of data first and even then there are problems and extra variables outside of a lab environment.
its more of a PoC in general rightnow. for 3 letter agencies well like paja93 said, they have much better ways ;) however they could use it as additional method for air-gap networks maybe, but again they have more reliable ways. well still, you are right, its just a matter of data. with much more training data for the model and more research to optimize the technic, it would indeed be something to worry about.
 
wow AI is getting to the next level, now we are not secure and every day cibersecurity is getting worse one miss click and that's it you already gave all your information, that is really scary
 
yes its always one thing to test in the lab and "in the wild". ;) just because it works in the lab doesn't mean anything. thats also something many security researchers don't understand...
however this method can be refined and i think they can make it somewhat reliable even if used against real world targets. its smart to use spectrogram from the audio instead of a linear waveform, so they can get much more data points for the model to train even if the key is recorded from different mediums (in their test a zoom call or a phone recording) and with different interferences.
they would have to collect much more data though from thousands of different keyboards and each recorded with many different devices. also they would have to do the same with different distances from the recording device, different furniture, rooms etc etc .. if this would be open sourced as a community effort, it could potentially be fairly accurate in the real world. rightnow however its just a PoC.

especially this shows that its just working in a lab test under very specific conditions:


another problem they didn't solve (which makes password recording problematic without further bruteforcing):



well like i said above, you need a lot of data first and even then there are problems and extra variables outside of a lab environment.
its more of a PoC in general rightnow. for 3 letter agencies well like paja93 said, they have much better ways ;) however they could use it as additional method for air-gap networks maybe, but again they have more reliable ways. well still, you are right, its just a matter of data. with much more training data for the model and more research to optimize the technic, it would indeed be something to worry about.
Absolutely it can be refined, but im sure it will be irrelevant because by then AI and similar technologies will probably be able to do much better and useful attacks that we will definitely have to worry about.
In lab you can make almost any attack to work, and its all just a theory, just testing all the possibilities.

In reality, most hacks are done not by hacking machines but by "hacking" humans, and AI or not AI, humans are always the weakest link. All these sophisticated hacks are fun to play with, but instead of worrying about this i think people should FINALLY learn some security basics because its becoming ridiculous that there is so much uneducated people after so many decades. In my eyes its almost like not being able to write.
 
Striking of course the growth of AI. Soon AI will both defend and attack, and the person will become dumb
 
That's scary
I always put my finger on all the keyboard when I type the password on the ATM
I don't think that's used at ATM.

I'm covering whole keyboard on ATM.
I can blindly type the pin.
Same when shopping.
 
Absolutely it can be refined, but im sure it will be irrelevant because by then AI and similar technologies will probably be able to do much better and useful attacks that we will definitely have to worry about.
In lab you can make almost any attack to work, and its all just a theory, just testing all the possibilities.

In reality, most hacks are done not by hacking machines but by "hacking" humans, and AI or not AI, humans are always the weakest link. All these sophisticated hacks are fun to play with, but instead of worrying about this i think people should FINALLY learn some security basics because its becoming ridiculous that there is so much uneducated people after so many decades. In my eyes its almost like not being able to write.
indeed, there are better things AI can do. though humans are the weakest link, remote exploits are still a big part of hacking as often no user interaction is needed. even if the users would have a basic understanding of security, it wouldnt protect them from 0days... but then again most people wouldnt have to worry about that, as nobody is going to waste an 0day on a normal person unless they have access to something that is being targeted (company network etc).
 
With 95 percent accuracy, the method can potentially be used to steal login credentials and other sensitive information.

A group of researchers in the UK say they have successfully trained a sound classification algorithm so that it can use data from commonly used microphones to hear what someone is typing on a keyboard - with as much as 95 per cent certainty. The machine learning model could thus be used to steal login details and other sensitive information.

In the report, the researchers give various suggestions on how to protect oneself against the attack method. For example, by varying their writing style, using randomly generated passwords or a password manager that means that information does not have to be entered manually. Other methods are to play background noise as white noise while typing or to use software-based sound filters for keystrokes. The attack method would also not be able to be used on occasions when biometric authentication is required.

https://www.bleepingcomputer.com/ne...ata-from-keystrokes-with-95-percent-accuracy/
now this is some troubling information. I know some keys on the keyboard sound slightly different. The larger keys like spacebar, shift, enter and caps lock tend to sound a bit louder with spacebar being the loudest.
How does this AI predict accurately what key?

Does it work only on physical keyboards, what about on-screen keyboards.

I believe it would heavily rely on stereo audio(or similar tech) to locate and isolate what section of the keyboard the sound is coming from, then decide what exact key it is.
 
Back
Top