How can hackers hear our passwords?

A new academic study shows that a regular smartphone can act as a sonar system and steal sensitive information based on the victim’s finger movement on the screen.

Researchers from Lancaster and Linköping University set out to capture the unlock pattern of an Android phone (Samsung S4) using the principle of a sonar: emitting sound waves and catching their echoes produced as they bounce off nearby objects.

Named SonarSnoop, the framework they developed relies on the phone’s speakers to issue acoustic signals and its microphones to catch the reflections. In this regard, SonarSnoop is the first active acoustic side-channel attack because it does not wait for the victim to generate the acoustic signal.

“The received signals are represented by a so-called echo profile matrix which visualizes this shift and allows us to observe movement. Combining observed movement from multiple microphones allows us to estimate strokes and inflections,” the study clarifies.

source: bleepingcomputer.com

 

Comments are closed.