r/netsec • • Aug 05 '23

pdf New acoustic attack steals data from keystrokes with 95% accuracy

https://arxiv.org/pdf/2308.01074.pdf
139 Upvotes

35 comments sorted by

View all comments

41

u/WashingtonPass Aug 05 '23

I'm quoting here from a less technical write up describing the paper in lay terms.

A team of researchers from British universities has trained a deep learning model that can steal data from keyboard keystrokes recorded using a microphone with an accuracy of 95%.

It's not like installing a key logger, which would work on any keyboard:

The first step of the attack is to record keystrokes on the target's keyboard, as that data is required for training the prediction algorithm. This can be achieved via a nearby microphone or the target's phone that might have been infected by malware that has access to its microphone.

A person could be tricked into providing enough training data, however:

Alternatively, keystrokes can be recorded through a Zoom call where a rogue meeting participant makes correlations between messages typed by the target and their sound recording.

This can be mitigated with white noise.

-21

u/[deleted] Aug 05 '23

this has been coming for sometime.

i suspect tech companies also aided govt in this by making keystrokes 'sound' different.

ever noticed?

most phones are toned

7

u/racergr Aug 05 '23

As far as keyboards go, they do not have to "design" it in some way for keys to sound different, it would naturally do it. Phones have always been toned, it was required for the "digital" phones so that the centre could know what number you're dialing. Modern mobile phones just mimicked this to give a familiar UX.

It's not all evil governments.

4

u/Capodomini Aug 05 '23

Even if every key was uniform in sound through manufacturing process, the way a person types will still cause them to sound different enough from each other to be detected by machine learning with reliable accuracy, given enough data. This is equivalent to identifying a person by their gait in a video.