My Google Glass Sees Your Passwords!
نویسندگان
چکیده
In this white paper, we introduce a novel computer vision based attack that automatically discloses inputs on a touch enabled device. Our spying camera, including Google Glass, can take a video of the victim tapping on the touch screen and automatically recognize more than 90% of the tapped passcodes from three meters away, even if our naked eyes cannot see those passcodes or anything on the touch screen. The basic idea is to track the movement of the fingertip and use the fingertip’s relative position on the touch screen to recognize the touch input. We carefully analyze the shadow formation around the fingertip, apply the optical flow, deformable part-based model (DPM) object detector, k-means clustering and other computer vision techniques to automatically track the touching fingertip and locate the touched points. Planar homography is then applied to map the estimated touched points to a software keyboard in a reference image. Our work is substantially different from related work on blind recognition of touch inputs. We target passcodes where no language model can be applied to correct estimated touched keys. We are interested in scenarios such as conferences and similar gathering places where a Google Glass, webcam, or smartphone can be used for a stealthy attack. Extensive experiments were performed to demonstrate the impact of this attack. As a countermeasure, we design a context aware Privacy Enhancing Keyboard (PEK) which pops up a randomized keyboard on Android systems for sensitive information such as password inputs and shows a conventional QWERTY keyboard for normal inputs.
منابع مشابه
ChaMAILeon: Simplified email sharing like never before!
While passwords, by definition, are meant to be secret, recent trends in the Internet usage have witnessed an increasing number of people sharing their email passwords for both personal and professional purposes. As sharing passwords increases the chances of your passwords being compromised, leading websites like Google strongly advise their users not to share their passwords with anyone. To ca...
متن کامل“Typing” passwords with voice recognition: How to authenticate to Google Glass
Augmented-reality glasses like Google Glass present a new set of user-interface trade-offs which must be carefully considered in crafting user authentication protocols. First, it lacks a keyboard or touchscreen; second, the most prominent input mechanisms, voice recognition and a swipe sensor, are both easily observable by bystanders and thus are not suitable for password entry. Fortunately, th...
متن کاملGlass OTP: Secure and Convenient User Authentication on Google Glass
Wearable computing devices have become increasingly popular and while these devices promise to improve our lives, they come with new challenges. This paper focuses on user authentication mechanisms for the Google Glass device (Glass). Glass only has three sources of input: a camera, a microphone, and a touchpad. This limited set of interfaces makes the use of standard passwords infeasible or cu...
متن کاملWhy Clouds Give Me a Case of the Vapors
A ccording to Apple, “ ... certain celebrity accounts were compromised by a very targeted attack on user names, passwords, and security questions.”1 Didn’t we cover defensive privacy tactics in my January column?2 Color me dazed and confused! Hacking in cyberspace? Nothing like that’s ever happened before. (I’ve got another heads-up for you iPhone users—Siri talks about you behind your back. I’...
متن کاملRe-envisioning the business of information: Policies, practices and procedures
KENNEALLY: The future, said the science fiction author William Gibson, is already here. It’s just not evenly distributed. And Gibson also said that the problem with the future is you can’t Google it. Now, we’ve all seen the Google Glass, but you can’t Google the future, although I did try to do that this morning. On my Google, the first result page was the bio for a rapper named Future. (laught...
متن کامل