Loose wrists shake chips: Your wrist-job could be a PIN-snitch

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Smart watch, dumb botch: sensor sensitivity equals insecurity say boffins

watch_098437083483.jpg

Chinese scientists have brewed a way to steal -- with 80 percent accuracy -- automatic teller machine PINs by infecting wearable devices.

Five university boffins demonstrated the trick in a laboratory, finding even the slight hand movements a person makes while entering PINs can be captured through infected smart watches.

The sniffed telemetry data could be later crunched by algorithms to reveal the correct PIN. Subsequent monitoring increases the PIN guessing accuracy to upwards of 90 percent.

Chen Wang of Birmingham University, together with Xiaonan Guo, Yan Wang, Yingying Chen, and Bo Liu of Stevens Institute of Technology, New Jersey, describe their work in the paper "Friend or Foe?: Your Wearable Devices Reveal Your Personal PIN [paywalled].

They say they achieved the accuracy rating over 5,000 pin-entry tests on ATMs and other systems. Twenty subjects wore various wearable devices during the 11-month study in which hardware accelerometers, gyroscopes, and other standard smart device componentry allowed millimeter-accuracy in reading PINs.

"Wearable devices can be exploited," said Wang. "Attackers can reproduce the trajectories of the user's hand then recover secret key entries to ATM cash machines, electronic door locks and keypad-controlled enterprise servers."

An internally-developed backward PIN-sequence inference algorithm then turned the data into PINs with between 80 percent to 90 percent accuracy.

Full Article. Loose wrists shake chips: Your wrist-job could be a PIN-snitch
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Ok, so next is the way my boxers rumple ? lol
so much for the nice smart watch I have been eyeing.
Nice share FrOg.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Main fault of those attacks is because of compromise out dated version of firmware or OS. So nothing safe at all.
 
  • Like
Reactions: frogboy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top