WindTalker: Stealing mobile PINs through the WiFi signal
Full article607 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
An adversary "can exploit the strong correlation between CSI fluctuation and keystrokes to infer the user’s number input," the researchers say.
Security researchers have discovered a way to use WiFi to eavesdrop on passwords and other sensitive data as they’re being entered onto a mobile phone touch screen — without requiring sight of the device or even the user.
“WindTalker,” as the scientists have dubbed their attack, works by inferring a password or PIN from WiFi interference caused by the user’s hand as it moves across the screen. It can be run against anyone using a WiFi connection controlled by the attacker and renders any encryption the target is employing irrelevant.
In a recent academic presentation, the researchers explained that WindTalker works because different “keystrokes on mobile devices will lead to different hand coverage and finger motions, which will introduce a unique interference to the [WiFi] signals and can be reflected by the channel state information,” or CSI. CSI is a comprehensive picture of the way a signal is propagated from the transmitter to the receiver.
“The adversary can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user’s number input,” the researchers say.
WindTalker is not the first hack that uses collateral information inadvertently broadcast by devices or users to infer sensitive data. Known as “side-channel” attacks, such methods have been demonstrated repeatedly by academics and other researchers.
But WindTalker is the first CSI side-channel attack that doesn’t require either a device being compromised or any special hardware.
Instead, the CSI data is collected by a public WiFi network, “which is easy-to-deploy and difficult-to-detect.”
Moreover, the system devised by academics analyzes the public WiFi traffic alongside the CSI data — making it possible to perform the most challenging part of the hack — inferring the hand movements and the keyboard input — “only for the sensitive [time] period where password-entering occurs.”
The researchers say they carried out “a detailed case study to evaluate the practicality of the password inference” using Alibaba’s Alipay, the largest mobile payment platform in the world.
“The evaluation results show that the attacker can recover the key with a high successful rate,” the researchers conclude.
The study: “When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi Signals,” was presented Oct. 24 at the Association for Computing Machinery’s 23rd annual Conference on Computer and Communications Security in Vienna, Austria.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/windtalker-smartphone-hack-wifi-acm-side-channel-attacks/