愛污传媒

Skip to main content

Thermal imaging and AI can be used to crack passwords in seconds, study finds

Mohamed Khamis, an associate professor of computing science at the University of Glasgow, helped develop a system that uses thermal imaging and artificial intelligence to guess computer and smartphone passwords in seconds. (University of Glasgow)
Mohamed Khamis, an associate professor of computing science at the University of Glasgow, helped develop a system that uses thermal imaging and artificial intelligence to guess computer and smartphone passwords in seconds. (University of Glasgow)
Share

Computer security experts in Scotland have developed a system that uses thermal imaging and artificial intelligence to guess computer and smartphone passwords in seconds.

"They say you need to think like a thief to catch a thief," , an associate professor of computing science at the University of Glasgow, said in a . "We developed ThermoSecure by thinking carefully about how malicious actors might exploit thermal images to break into computers and smartphones."

Results of the research were published in in the peer-reviewed journal ACM Transactions on Privacy and Security.

ThermoSecure essentially works by analyzing the traces of heat left by your fingertips when you enter your password on a keyboard or mobile device. Since brighter areas on a heat-sensing thermal image show places that were touched more recently, it is then possible to discern the order in which specific letters, numbers and symbols were used. To do so, Khamis and his team used machine learning and 1,500 thermal images of recently used QWERTY keyboards to train an artificial intelligence model to read heat signatures and then make informed decisions about potential passwords.

The system was able to reveal 86 per cent of passwords when a thermal image was taken within 20 seconds of typing. Within 30 seconds, the success rate fell to 76 per cent, while after 60 seconds it dropped to 62 per cent.

The team found that longer passwords offered more protection. Within 20 seconds, ThermoSecure could only crack 67 per cent of 16-character passwords, but its success rate climbed to 82 per cent for passwords with 12 symbols, 93 per cent for eight symbols and 100 per cent for six symbols.

Typing style had an impact as well. Slow-searching "hunt-and-peck" keyboard users tended to linger more on keys, creating longer-lasting heat signatures than speedy "touch-typists." After 30 seconds, ThermoSecure could guess the first groups' passwords with 92 per cent accuracy, versus 80 per cent for the faster group.

The heat-absorption properties of different keyboard materials even played a role. ThermoSecure could guess passwords from keys made with ABS plastics 52 per cent of the time, but only 14 per cent of the time when they were made with PBT plastics, which are .

With thermal imaging cameras becoming more affordable, and machine learning becoming more accessible, the team behind ThermoSecure suggests the types of 'thermal attacks" conducted for their study could become increasingly common. In addition to suggesting alternative digital authentication methods like fingerprint or facial recognition, they offer several tips for protecting your passwords.

"Longer passwords are more difficult for ThermoSecure to guess accurately, so we would advise usinglong passphrases wherever possible," Khamis explained."Backlit keyboards also produce more heat, making accurate thermal readings more challenging, so a backlit keyboard with PBT plastics could be inherently more secure."

CTVNews.ca Top Stories

The president and CEO of New Brunswick-based Covered Bridge Potato Chips is taking an 'extended leave of absence' after being charged with domestic violence this past weekend.

A memorial is growing outside a Walmart in Halifax after a 19-year-old employee was found dead inside an oven in the store Saturday night.

A search has started at Prairie Green Landfill for the remains of two victims of a serial killer.

He is a familiar face to residents of a neighbourhood just west of Roncesvalles Avenue.

Canada's discount airline is suspending operations to and from Saskatoon.

A new report suggests that Canadians' exposure to a radioactive gas is increasing, putting millions of people at a higher risk of developing lung cancer.

Local Spotlight

He is a familiar face to residents of a neighbourhood just west of Roncesvalles Avenue.

A meteor lit up our region's sky last night 鈥 with a large fireball shooting across the horizon over Lake Erie at around 7:00 p.m.

Residents of Ottawa's Rideauview neighbourhood say an aggressive wild turkey has become a problem.

A man who lost his life while trying to rescue people from floodwaters, and a 13-year-old boy who saved his family from a dog attack, are among the Nova Scotians who received a medal for bravery Tuesday.

A newly minted Winnipegger is hoping a world record attempt will help bring awareness for the need for more pump track facilities in the city.

A Springfield, Ont. man is being hailed a 'hero' after running into his burning home to save his two infant children.

Hortense Anglin was the oldest graduate to make her way across the platform at York University's Fall Convocation ceremony this week. At the age of 87, she graduated with an Honours degree in Religious Studies.

Looking for a scare with good intentions this Halloween season? The ghosts and ghouls of Eganville, Ont. invite families to tour the Haunted Walk at Lekbor Manor.

The image of a sleepy Saskatchewan small town with 'not a lot going on' is a well-known anecdote. However, one Saskatchewan company is hoping to change that 鈥 and allow communities both on and off the beaten path to share their stories and advertise what they have to offer.