{"id":11046,"date":"2022-10-19T08:22:05","date_gmt":"2022-10-19T11:22:05","guid":{"rendered":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=11046"},"modified":"2022-10-19T08:22:05","modified_gmt":"2022-10-19T11:22:05","slug":"ataque-termico-e-inteligencia-artificial-para-leer-contrasenas-a-partir-del-calor-que-dejan-los-dedos-al-tocar-pantallas-tactiles","status":"publish","type":"post","link":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=11046","title":{"rendered":"&#8216;Ataque t\u00e9rmico&#8217; e Inteligencia Artificial para leer contrase\u00f1as a partir del calor que dejan los dedos al tocar pantallas t\u00e1ctiles"},"content":{"rendered":"<p>Llamado\u00a0ThermoSecure, los investigadores de la Facultad de Ciencias de la Computaci\u00f3n de la Universidad de Glasgow desarrollaron el sistema para mostrar c\u00f3mo la ca\u00edda del precio de las c\u00e1maras termogr\u00e1ficas y el aumento del acceso a los algoritmos de aprendizaje autom\u00e1tico e inteligencia artificial (IA) est\u00e1n creando nuevas oportunidades para lo que describen como ataques t\u00e9rmicos.<\/p>\n<hr \/>\n<p>Computer security researchers say they&#8217;ve developed an AI-driven system that can guess computer and smartphone passwords in seconds by examining the heat signatures that fingertips leave on keyboards and screens when entering data.<\/p>\n<p>Called ThermoSecure, researchers at the\u00a0<a href=\"https:\/\/www.gla.ac.uk\/news\/headline_885914_en.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">University of Glasgow&#8217;s School of Computing Science<\/a>\u00a0developed the system to show how the falling price of thermal-imaging cameras and increasing access to\u00a0<a href=\"https:\/\/www.zdnet.com\/article\/what-is-ai-heres-everything-you-need-to-know-about-artificial-intelligence\/\" target=\"_blank\" rel=\"follow noopener\">machine-learning and artificial intelligence<\/a>\u00a0(AI) algorithms are creating new opportunities for what they describe as thermal attacks.<\/p>\n<p>By using a thermal-imaging camera to look at a computer keyboard, smartphone screen or ATM keypad, it&#8217;s possible to take a picture that reveals the recent heat signature from fingers touching the device.<\/p>\n<p>The brighter the area appears in the thermal image, the more recently it was touched \u2013 meaning that the image could be used to crack a password or pin code by analyzing where the keyboard or screen was touched, and when.<\/p>\n<p>Earlier research by the University of Glasgow into thermal attacks has suggested that humans without expertise can guess passwords by looking at thermal images, and now \u2013 by adding artificial intelligence \u2013 passwords could be cracked even faster by specialist attackers.<\/p>\n<p>Using ThermoSecure to analyse images using AI, 86% of passwords were revealed when thermal images were taken within 20 seconds, 76% could be guessed using images within 30 seconds, and 62% could be discovered after 60 seconds.<\/p>\n<p>The longer the\u00a0<a href=\"https:\/\/www.zdnet.com\/article\/were-still-making-terrible-choices-with-passwords-even-though-we-know-better\/\" target=\"_blank\" rel=\"follow noopener\">password<\/a>, the more difficult it was to reveal, but it still proved possible in the majority of cases. ThermoSecure could crack two-thirds of passwords of up to 16 characters and, as passwords get shorter, the more success the system had \u2013 12-character passwords were guessed up to 82% of the time and eight-character passwords were guessed up to 93% of the time.<\/p>\n<p>Passwords made up of six characters or less were successfully cracked 100% of the time \u2013 something that could make ATM PIN codes or shorter codes that are used to protect smartphones particularly vulnerable to attacks.<\/p>\n<p>By using this clever technique, a malicious attacker observing potential victims could take a thermal photo of a keyboard, smartphone or ATM and use that to guess passwords. In some cases, they&#8217;d also need to physically access the device themselves \u2013 but it&#8217;s also possible that the target could leave their computer unattended.<\/p>\n<p>There&#8217;s also the possibility that an attacker could already know the username of their target&#8217;s online account \u2013 or they could potentially use the thermal attack to uncover that, too.<\/p>\n<p><a href=\"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3563693\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">The paper on ThermoSecure<\/a>\u00a0\u2013 authored by the University of Glasgow&#8217;s Dr Mohamed Kham, Dr John Williamson and Norah Alotaibi \u2013 has been released in the hope that it shows the potential risk posed by thermal imaging attacks as the technology used to power them becomes cheaper and more widely available.<\/p>\n<p>&#8220;Access to thermal-imaging cameras is more affordable than ever \u2013 they can be found for less than \u00a3200 \u2013 and machine learning is becoming increasingly accessible, too. That makes it very likely that people around the world are developing systems along similar lines to ThermoSecure in order to steal passwords,&#8221; said Dr Mohamed Khamis, reader in computer science at the University of Glasgow, who led the development of ThermoSecure.<\/p>\n<p>&#8220;It&#8217;s important that computer security research keeps pace with these developments to find new ways to mitigate risk, and we will continue to develop our technology to try to stay one step ahead of attackers,&#8221; he added.<\/p>\n<p>But while the research demonstrates some advanced techniques that could be used to crack passwords, for users, protecting their accounts is possible by doing one relatively simple thing \u2013\u00a0<a href=\"https:\/\/www.zdnet.com\/article\/want-a-strong-password-youre-probably-still-doing-it-the-wrong-way\/\" target=\"_blank\" rel=\"follow noopener\">using stronger passwords<\/a>.<\/p>\n<div class=\"g-outer-spacing-bottom-large\"><\/div>\n<p>&#8220;Longer passphrases take longer to type, which also makes it more difficult to get an accurate reading on a thermal camera, particularly if the user is a touch typist,&#8221; said Dr Khamis, who also suggested that\u00a0<a href=\"https:\/\/www.zdnet.com\/article\/face-fingerprint-passwords-or-pin-whats-the-best-way-to-keep-your-smartphone-secure\/\" target=\"_blank\" rel=\"follow noopener\">biometric verification<\/a>\u00a0also adds protection.<\/p>\n<p>&#8220;Users can help make their devices and keyboards more secure by adopting alternative authentication methods, like fingerprint or facial recognition, which mitigate many of the risks of thermal attack.&#8221;<\/p>\n<p><strong>Fuente:<\/strong> <a href=\"https:\/\/www.zdnet.com\/article\/this-thermal-attack-can-read-your-password-from-the-heat-your-fingertips-leave-behind\/\" target=\"_blank\" rel=\"noopener\"><em>https:\/\/www.zdnet.com<\/em><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Llamado\u00a0ThermoSecure, los investigadores de la Facultad de Ciencias de la Computaci\u00f3n de la Universidad de Glasgow desarrollaron el sistema para mostrar c\u00f3mo la ca\u00edda del&hellip; <\/p>\n","protected":false},"author":1,"featured_media":11047,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,23],"tags":[],"_links":{"self":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/11046"}],"collection":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11046"}],"version-history":[{"count":1,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/11046\/revisions"}],"predecessor-version":[{"id":11048,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/11046\/revisions\/11048"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/media\/11047"}],"wp:attachment":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11046"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11046"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11046"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}