The Investor Sentiment - Equity and investments forum for Sri Lankans
Search
 
 

Display results as :
 


Rechercher Advanced Search

Latest topics
» BLI.N0000 ( Bimputh Finance PLC )
Today at 9:44 am by yellow knife

» රුපියල් රැක ගන්න ඩොලර් මිලියන 1,000 කින් ආනයන සීමා කරන බව අගමැති කියයි
Today at 7:49 am by serene

» නාගරික සංවර්ධනයේ ඉඩමක් රු. බිලියනයකට ඇක්සස් ට බදු දෙයි
Today at 7:46 am by serene

» Amazon Founder Jeff Bezos Influenced By Smarter Sri Lankan
Today at 7:41 am by serene

» Dividend Announcement
Today at 5:37 am by Ethical Trader

» අනං මනං! #/+?.<>
Today at 5:36 am by Ethical Trader

» Dhamma Deshana
Mon Sep 24, 2018 8:05 am by ruwan326

» ඩොලරයේ විකුණුම් මිල රු. 167 ඉක්මවයි
Fri Sep 21, 2018 9:43 am by Ethical Trader

» ඩොලරයේ විකුණුම් මිල රු. 164 ඉක්මවයි
Tue Sep 18, 2018 2:42 pm by yellow knife

» UAL.N0000 ( UNION ASSURANCE PLC )
Sun Sep 16, 2018 6:13 pm by Senarath67

» CAL Securities Facilitates First Cross-Border Share Transaction by a Sri Lankan Stockbroker
Sat Sep 15, 2018 11:04 pm by serene

» මහ බැංකුව රු. බිලියන 60 ක බැඳුම්කර විකුණයි
Fri Sep 14, 2018 12:48 pm by Ethical Trader

» ඩුනාමිස් කොටස් මිල 90% කින් ඉහළට. වැඩි අයිතිය ජනශක්ති අත්පත් කර ගනී
Fri Sep 14, 2018 7:49 am by serene

» නිදහස ලැබීමෙන් පසු රු. ට්‍රිලියන 1.9 ක වැඩිම ණය ආපසු ගෙවීම මෙම වසරේ දී – මංගල
Thu Sep 13, 2018 6:44 pm by Ethical Trader

» ණය අපසු ගෙවීමට අඩු පීඩාකාරී ප්‍රතිපත්ති විකල්ප පවතින්නේ නම් සමාජ වියදම් කපා හැරීම නොකළ යුතුයි – UN විශේෂඥයා පවසයි
Wed Sep 12, 2018 6:14 pm by Ethical Trader

» Banking Sector Outlook-
Wed Sep 12, 2018 8:17 am by serene

» Sri Lankan central bank rejects currency crisis report
Tue Sep 11, 2018 7:31 am by serene

» LOFC Initiating Coverage - STRONG BUY - 29 03 17 - FC Research
Sat Sep 08, 2018 1:53 am by stockback

» අසාමාන්‍ය කොටස් මිල උච්ඡාවචනය ගැන MTD Walkers කරුණු පහදයි
Wed Sep 05, 2018 6:26 pm by Ethical Trader

» ශ්‍රී ලංකා රුපියල
Wed Sep 05, 2018 6:24 pm by Ethical Trader

» සුමල්ගේ සමාගමට කැබිනට් අනුමැතිය. රුපියල් බිලියන 2.7 ක නිවාස ව්‍යාපෘතියක්
Wed Sep 05, 2018 6:22 pm by Ethical Trader

» ධම්මික ලංකා සෙරමික් සභාපති ධූරයෙන් ඉල්ලා අස්වෙයි
Wed Sep 05, 2018 2:26 pm by nihal123

» Sri Lanka car registration up in July, tax not yet hit
Mon Sep 03, 2018 5:14 pm by Ethical Trader

» 2018 මාස 08 කදී කොළඹ කොටස් 4.54% කින් පසුබසී
Mon Sep 03, 2018 5:11 pm by Ethical Trader

» Sri Lanka rupee ends steady, stocks flat
Mon Sep 03, 2018 7:26 am by The Invisible

» Sri Lanka's August inflation in Colombo hits 5.9-pct
Mon Sep 03, 2018 7:24 am by The Invisible

» ජනාධිපතිවරණයට තවත් අපේක්ෂකයෙක්. සුමල්, ධම්මිකව යෝජනා කරයි VIDEO August, 30, 2018
Mon Sep 03, 2018 7:22 am by The Invisible

» Pictures & Stories ........
Sat Sep 01, 2018 6:57 pm by malanp

» සිංහ රෝහලට අසාධ්‍යයි
Fri Aug 31, 2018 7:56 pm by nihal123

» මාස 06 කදී වෙළෙඳ හිඟය ඩොලර් මිලියන 5,700 ඉක්මවයි
Tue Aug 28, 2018 8:01 pm by spw19721

» Billionaire Ashok Pathirage controlled Asiri Health to launch an MBBS degree Program
Tue Aug 28, 2018 5:26 pm by Ethical Trader

» දිගින් දිගටම වැඩි වෙමින් ඇති උද්ධමනය ගැන ආර්ථික විශේෂඥයින් අනතුරු අඟවයි
Mon Aug 27, 2018 11:47 am by Ethical Trader

» මැල්කම් ටර්න්බුල් පහකිරීමෙන් පසු ඕස්ට්‍රේලියාවේ අගමැති ධූරයට ස්කොට් මොරිසන්
Fri Aug 24, 2018 6:06 pm by Ethical Trader

» Sri Lanka rupee opens at new low, stocks gain 0.15-pct
Fri Aug 24, 2018 5:55 pm by Ethical Trader

» Sri Lanka's John Keells fine-tunes hotel strategy
Fri Aug 24, 2018 5:53 pm by Ethical Trader

» Sri Lanka's The Finance struggle to recover Ceylinco assets
Fri Aug 24, 2018 5:51 pm by Ethical Trader

» Sri Lanka increases planting subsidies for rubber
Thu Aug 23, 2018 10:34 am by The Invisible

» Sri Lanka eyes Euro, Yen and Renminbi bonds to cut costs
Thu Aug 23, 2018 10:33 am by The Invisible

» Sri Lanka to start first boat service in Colombo canals with navy
Thu Aug 23, 2018 10:32 am by The Invisible

» ලොකුම සමාගම් ලැයිස්තුව අලුත් වෙයි. ජෝන් කීල්ස් අභිබවා CTC අංක 1 ට
Thu Aug 23, 2018 8:41 am by Ethical Trader

» යෙන්, යුවාන්, යූරෝ බැඳුම්කර අලෙවියට ආණ්ඩුවේ සූදානමක්
Thu Aug 23, 2018 8:39 am by Ethical Trader

» හැරී ගේ මීළඟ ඉලක්කය
Wed Aug 22, 2018 5:23 pm by Ethical Trader

» Sri Lanka pension fund to value hotel stake eyed by HPL Hotels
Wed Aug 22, 2018 11:29 am by The Invisible

» Sri Lanka's Hemas Holdings profitability seen improving: Fitch
Wed Aug 22, 2018 11:27 am by The Invisible

» Sri Lanka's LMF to invest Rs2bn in new dairy farm
Wed Aug 22, 2018 11:26 am by The Invisible

» Sri Lanka’s national inflation accelerates to 3.4-pct in July
Wed Aug 22, 2018 11:23 am by The Invisible

» Sri Lanka rupee ends at new low, stocks flat
Wed Aug 22, 2018 11:22 am by The Invisible

» Elsewhere vs SL : Honesty, Social responsibility , Word twisting and Decency
Tue Aug 21, 2018 11:00 pm by Expert

» මහජන බැංකුවෙන් ජෙහාන් ගේ සමාගමට දුන් රු. බිලියන 10 ගැන මහ බැංකුව මෙසේ කියයි
Tue Aug 21, 2018 9:26 pm by Rana

» මැරියට් ආයෝජනයෙන් ඉවත් වන්නේ ප්‍රමාණවත් ප්‍රතිලාභයක් ලැබුණොත් පමණයි – EPF අවධාරණය කරයි
Tue Aug 21, 2018 6:07 pm by Ethical Trader

September 2018
SunMonTueWedThuFriSat
      1
2345678
9101112131415
16171819202122
23242526272829
30      

Calendar Calendar

Disclaimer


Information posted in this forum are entirely of the respective members' personal views. The views posted on this open online forum of contributors do not constitute a recommendation buy or sell. The site nor the connected parties will be responsible for the posts posted on the forum and will take best possible action to remove any unlawful or inappropriate posts.
All rights to articles of value authored by members posted on the forum belong to the respective authors. Re-using without the consent of the authors is prohibited. Due credit with links to original source should be given when quoting content from the forum.
This is an educational portal and not one that gives recommendations. Please obtain investment advises from a Registered Investment Advisor through a stock broker

Spatio-temporal dynamics - Sounds Greek to me.

Go down

Spatio-temporal dynamics - Sounds Greek to me.

Post by කිත්සිරි ද සිල්වා on Tue Apr 21, 2015 7:11 pm

At a restaurant, you pull out your phone to check email. Without even thinking about it, you tap in a PIN to unlock your phone. Your back’s to the wall and nobody can see what you’re typing, so there’s no reason to worry that somebody could intercept your passcode.

Except, sadly, there is. Researchers at Syracuse University have demonstrated that hackers can guess PINs by analyzing video of people tapping on their smartphone screens -- even when the screen itself isn’t visible. Software used to analyze such video relies on “spatio-temporal dynamics” to gauge the distance from the fingers to the phone’s screen, and then approximate which characters the fingers tap on a keypad. “It’s like lip reading,” says Vir Phoha, an engineering and computer science professor at Syracuse and co-author of a paper on the technology. “Based on hand movement and the known geometry of the phone, we can see which keys are pressed.”

There don’t appear to be any known instances of hackers stealing PINs this way, but technologists think it’s only a matter of time. “We believe that it is very likely to be adopted by adversaries who seek to stealthily steal sensitive private information,” Phoha and three others Syracuse researcherswrote in their paper, published last year by the Association for Computing Machinery. The technology is fairly simple for anybody familiar with programming, and the exploding use of smartphones provides many millions of targets.

On top of that, the increased use of phones for banking and managing other financial accounts makes PINs a lucrative prize for hackers. And the same video-analysis technology can be used to infer PINs punched into ATMs, smart locks on the front doors of homes, garage door openers and other gizmos requiring similar codes.

Publicizing such black-hat technology through articles such as this one can obviously tip fraudsters to possible new methods of ripping people off. Security experts and some of their criminal foes already know about it, however, since such research has been published in technical journals. So Yahoo Finance decided it’s appropriate to alert consumers to this new form of hacking. National security and law enforcement agencies could also use it to keep track of bad guys; DARPA, the Pentagon’s technology skunk works, for instance, partly funded the Syracuse research.

The Syracuse experiments involved 50 volunteers typing PINs into HTC One smartphones, in a variety of different settings and postures. For each volunteer, researchers shot four different videos. The recordings were made using two off-the-shelf devices: a Google Nexus 5 smartphone camera and a Sony camcorder. All the videos were shot from the side or back of the phone, from 12 to 15 feet away. None of the videos captured the phone screen or explicitly showed what users were typing.

Software filled in the gaps, however, with a combination of image analysis and motion tracking algorithms being remarkably effective at “guessing” the PINs users typed in. On the first guess, software determined the correct password between 40% and 62% of the time, depending on the quality of the video and the zoom ratio. The highest-quality video produced an 82% accuracy rate after 5 guesses and 94% accuracy after 10 guesses. Using more than one video for each phone raises the odds of success even further.

“We can do it in about 30 minutes once we capture the video,” says Phoha. “We have almost 100% accuracy.” This graph lays out the results of computer guesswork for video shot using the Nexus smartphone and the Sony camcorder at zoom levels of 2x, 4x and 6x:

Hackers could shoot the necessary video without phone users ever noticing, especially in busy settings such as a bar, restaurant, bus, train, airport or shopping mall. Thieves have long nabbed people’s credit card numbers or ATM PINs by “shoulder snooping” during a transaction, or even looking on from a distance with binoculars or a camera with a zoom lens. So in a way, hacking via video—which can be done surreptitiously on a smartphone while the perpetrator appears to be harmlessly tapping on the screen—is nothing more than a new variation on an old theme.

There are still several additional steps hackers would have to take to steal or vandalize with a captured PIN. For starters, they’d have to crack into separate bank or financial accounts. They might be able to do that by stealing the phone, logging in with the hacked PIN and opening apps that aren’t password protected because the user assumed the smartphone PIN was protection enough.

Hackers could also glean additional information about targeted individuals, like email addresses and account numbers, and use those to log into accounts. If acquaintances or work colleagues were the target, some of that information might already be available. Since hackers already have partial information on millions of consumers, a smartphone PIN could be a crucial missing piece -- especially if it doubles as a passcode for other accounts.

They'll eventually get lucky enough

The odds of any one person getting digitally robbed in this fashion are low, but hackers would probably get lucky often enough to make it worth the trouble, since a lot of people use the same PIN for multiple accounts and devices. On top of that, the same technology used to crack 4- to 7-digit smartphone PINs could be refined to decode longer passwords such as those often required for computer access.

There are limits to such image-analysis technology. It’s harder to detect PINs when people type them with two fingers rather than one, for example. The use of a full keyboard instead of a 10-character phone-style keypad makes it harder still, as does the use of capital letters and symbols that aren’t on a 10-character pad. And fingerprint validation in lieu of a PIN solves the whole problem, even though it’s available on only a small portion of smartphones at the moment, and not at all on ATMs and other gadgets requiring PINS.

As always, countermeasures will ensue if unseen PIN hacking were to grow into a major problem. Smartphone makers could create keypads that appear in different locations on the screen every time, foiling pattern-recognition algorithms that rely on consistent spatio-temporal dynamics. Keypads that jumble the 10 numerals in a different random order during each use might also do the trick, though they could also drive users crazy and encourage them to ditch the passcode because it’s too much trouble.

Meanwhile, protecting yourself against sneaky PIN hacking wouldn’t be difficult, once you know what to do. Keeping your phone completely out of sight when entering a PIN or other sensitive data is the most obvious step. Newer iPhone and Android devices allow you to choose a longer, more complex alphanumeric passcode over a simple 4-digit one (although typing it in can be a pain). And practicing good security—by using two-factor authentication, password-tracking apps and so on—helps improve security and speed the notification time if somebody has infiltrated your accounts. It’s probably safe to assume somebody is always watching. Sooner or later, they will be.

http://finance.yahoo.com/news/an-alarming-new-way-to-steal-your-passwords-135027327.html
avatar
කිත්සිරි ද සිල්වා
Top contributor
Top contributor

Posts : 7355
Join date : 2014-02-23
Age : 60
Location : රජ්ගම

Back to top Go down

Re: Spatio-temporal dynamics - Sounds Greek to me.

Post by serene on Tue Apr 21, 2015 8:18 pm

Thanks kith.
Ane manda. .

serene
Top contributor
Top contributor

Posts : 3722
Join date : 2014-02-26

Back to top Go down

Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum