Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Friday, February 15th, 2013

    Time Event
    6:48a
    Guessing Smart Phone PINs by Monitoring the Accelerometer

    "Practicality of Accelerometer Side Channels on Smartphones," by Adam J. Aviv. Benjamin Sapp, Matt Blaze, and Jonathan M. Smith.

    Abstract: Modern smartphones are equipped with a plethora of sensors that enable a wide range of interactions, but some of these sensors can be employed as a side channel to surreptitiously learn about user input. In this paper, we show that the accelerometer sensor can also be employed as a high-bandwidth side channel; particularly, we demonstrate how to use the accelerometer sensor to learn user tap and gesture-based input as required to unlock smartphones using a PIN/password or Android's graphical password pattern. Using data collected from a diverse group of 24 users in controlled (while sitting) and uncontrolled (while walking) settings, we develop sample rate independent features for accelerometer readings based on signal processing and polynomial fitting techniques. In controlled settings, our prediction model can on average classify the PIN entered 43% of the time and pattern 73% of the time within 5 attempts when selecting from a test set of 50 PINs and 50 patterns. In uncontrolled settings, while users are walking, our model can still classify 20% of the PINs and 40% of the patterns within 5 attempts. We additionally explore the possibility of constructing an accelerometer-reading-to-input dictionary and find that such dictionaries would be greatly challenged by movement-noise and cross-user training.

    Article.

    12:52p
    Jacob Appelbaum's 29C3 Keynote Speech

    This speech from last December's 29C3 (29th Chaos Communication Congress) is worth listening to. He talks about what we can do in the face of oppressive power on the Internet. I'm not sure his answers are right, but am glad to hear someone talking about the real problems.

    4:09p
    Friday Squid Blogging: More on Flying Squid

    Japanese squid researchers have confirmed flying squid can fly, and how they do it. (Note: I have written about flying squid before.)

    As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered.

    << Previous Day 2013/02/15
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org