ADVERTISEMENT

A scary new hack created by researchers can accurately guess your password by listening to the sound of your fingers tapping the phone screen

Academic researchers have found a new way to determine the passcodes used on smartphones and tablets.

cell phone smartphone bacteria hands
  • The technique they describe in a recent paper relies on the microphones found in most handheld devices to detect the sound waves users generate when they tap on their screens.
  • The technique they created was able to guess nearly three-fourths of the four-digit PINs used within 10 tries in one test.
  • Visit Business Insider's homepage for more stories .
ADVERTISEMENT

Hackers may be able to figure out the passcode to your smartphone by just listening in.

Malware can be designed to take advantage of the microphones in handheld devices to compromise their users' passwords and PINs, researchers at the University of Cambridge in England and Sweden's Linkping University reported in a recent paper . The technique they describe, which relies on machine learning, isn't foolproof, but was able to accurately guess more than half of four-digit PINs used on Android tablets in one test case.

"We showed that the attack can successfully recover PIN codes, individual letters and whole words," researchers Ilia Shumailov, Laurent Simon, Jeff Yan, and Ross Anderson said in the paper, which was first reported by the Wall Street Journal on Wednesday . "We have shown a new acoustic side-channel attack on smartphones and tablets," they continued, and described how to exploit it effectively."

ADVERTISEMENT

The paper has yet to be peer reviewed, but was published on a site Cornell University maintains for academic research studies.

When people tap on the screens of their smartphones and tablets, they generate sound waves. Most contemporary handheld devices have multiple microphones that they use for voice calls, recording voice memos, and more.

The researchers used the devices' microphones to detect the soundwaves generated by passcode taps. By tracking which microphone heard the sound first a difference that could be measured in fractions of a second the software they created could make educated guesses about where on the screen the sound originated, allowing it to predict which key a user tapped.

ADVERTISEMENT

The system they created was able to correctly guess a four-digit passcode 73% of the time after 10 tries in one test. In another test, it was able to identify 30% of passwords ranging from seven to 13 characters in length after 20 tries.

In order for hackers to exploit the vulnerability researchers found, they'd have to get their targets to install malware on their phones first, and the potential victims would have to allow that software to have access to their microphones. That could make the technique difficult to use in the real world, security researchers told the Journal. Most modern operating systems bar applications from using a device's microphone unless users allow it.

Got a tip about a security vulnerability or another the tech issue? Contact this reporter via email at twolverton@businessinsider.com, message him on Twitter @troywolv , or send him a secure message through Signal at 415.515.5594. You can also contact Business Insider securely via SecureDrop .

ADVERTISEMENT

See Also:

SEE ALSO: An internet pioneer is doubtful Mark Zuckerberg can refocus Facebook on privacy. Here's why.

FOLLOW BUSINESS INSIDER AFRICA

Unblock notifications in browser settings.
ADVERTISEMENT

Recommended articles

Indian billionaire Narendra Raval pushes to establish his business in Kenya

Indian billionaire Narendra Raval pushes to establish his business in Kenya

10 African countries with the smallest merchant marine fleet

10 African countries with the smallest merchant marine fleet

Beyond the reels: How augmented reality could revolutionize online slots

Beyond the reels: How augmented reality could revolutionize online slots

Effective real estate arbitrage strategies for wealth building

Effective real estate arbitrage strategies for wealth building

Amazon online shopping comes to South Africa

Amazon online shopping comes to South Africa

Nigerian officials accused of seeking $150 million bribe from Binance to dissolve case

Nigerian officials accused of seeking $150 million bribe from Binance to dissolve case

Accelerating insurance penetration: A digital revolution in emerging markets

Accelerating insurance penetration: A digital revolution in emerging markets

Nigeria's action against Binance execs sets a dangerous precedent, CEO says

Nigeria's action against Binance execs sets a dangerous precedent, CEO says

5 African cities with the most financially stable people

5 African cities with the most financially stable people

ADVERTISEMENT