CRMar 30, 2019

PILOT: Password and PIN Information Leakage from Obfuscated Typing Videos

arXiv:1904.00188v23 citations
Originality Highly original
AI Analysis

This addresses a security vulnerability for users of password masking interfaces, such as on computers or ATMs, by revealing a novel attack vector that is not incremental but highlights a previously overlooked risk.

The paper tackles the problem of password and PIN leakage from videos of masked typing feedback, showing that their PILOT attack can recover 8-character alphanumeric passwords in as few as 19 attempts and guess about 3% of PINs within 10 attempts, a 26-fold improvement over random guessing.

This paper studies leakage of user passwords and PINs based on observations of typing feedback on screens or from projectors in the form of masked characters that indicate keystrokes. To this end, we developed an attack called Password and Pin Information Leakage from Obfuscated Typing Videos (PILOT). Our attack extracts inter-keystroke timing information from videos of password masking characters displayed when users type their password on a computer, or their PIN at an ATM. We conducted several experiments in various attack scenarios. Results indicate that, while in some cases leakage is minor, it is quite substantial in others. By leveraging inter-keystroke timings, PILOT recovers 8-character alphanumeric passwords in as little as 19 attempts. When guessing PINs, PILOT significantly improved on both random guessing and the attack strategy adopted in our prior work [4]. In particular, we were able to guess about 3% of the PINs within 10 attempts. This corresponds to a 26-fold improvement compared to random guessing. Our results strongly indicate that secure password masking GUIs must consider the information leakage identified in this paper.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes