Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

read, and submit a review. The review should be about 300 words (a full page doc

ID: 3914908 • Letter: R

Question

read, and submit a review.

The review should be about 300 words (a full page document). Please organize and elaborate your points. If you feel you need more than 300 words - you are free to do so (but make sure your points are not off-tangent). You will not get extra points for writing a mini-novel. Your grade is based on how well you synthesize the points in the article (including how you express your opinion, thoughts or understanding).

Recovering Keyboard Inputs through Thermal Imaging

Researchers at the University of California, Irvine, are able to recover user passwords by way of thermal imaging. The tech is pretty straightforward, but it's interesting to think about the types of scenarios in which it might be pulled off.

Abstract: As a warm-blooded mammalian species, we humans routinely leave thermal residues on various objects with which we come in contact. This includes common input devices, such as keyboards, that are used for entering (among other things) secret information, such as passwords and PINs. Although thermal residue dissipates over time, there is always a certain time window during which thermal energy readings can be harvested from input devices to recover recently entered, and potentially sensitive, information.

To-date, there has been no systematic investigation of thermal profiles of keyboards, and thus no efforts have been made to secure them. This serves as our main motivation for constructing a means for password harvesting from keyboard thermal emanations. Specifically, we introduce Thermanator, a new post factum insider attack based on heat transfer caused by a user typing a password on a typical external keyboard. We conduct and describe a user study that collected thermal residues from 30 users entering 10 unique passwords (both weak and strong) on 4 popular commodity keyboards. Results show that entire sets of key-presses can be recovered by non-expert users as late as 30 seconds after initial password entry, while partial sets can be recovered as late as 1 minute after entry. Furthermore, we find that Hunt-and-Peck typists are particularly vulnerable. We also discuss some Thermanator mitigation strategies.

The main take-away of this work is three-fold: (1) using external keyboards to enter (already much-maligned) passwords is even less secure than previously recognized, (2) post factum (planned or impromptu) thermal imaging attacks are realistic, and finally (3) perhaps it is time to either stop using keyboards for password entry, or abandon passwords altogether.

Explanation / Answer

Nowadays the work done for the cyber security is very much appreciated and much needed. Because after 2000 the data generation has increased million times, everyone is using smart mobiles, cctv cameras, sensors etc.

First of all investigating the things that are not yet investigated yet is a very good thing and has to be appreciated whole heartedly.

It is an excellent idea and good move to secure our privacy and bank details. A typical human cannot understand about thermal imaging etc. More awareness has to be created among people and if anyone has affected by it has to come front and report it in proper time that will be helpful in preceding this project more successful.

I know about this before from that time I am using a non-technical idea to get away from this thermal imaging technique, I will say it for you know.

More dangerous of thermal imaging will be seen in the ATM transactions that time While we completed our transactions, I think you will left the ATM cabin. But what I can suggest is swipe your hand all over the numbers button in the ATM, so the residue will be all over the button that makes the hackers very difficult to find the pin.

Using an external keyboard is good idea for online surfing of internet outside our home in a net cafe etc. is compatible but in cases like ATM this is not possible, because the keyboards will be in inbuilt condition.

Stop using the keyboard for the password entry is also a best way, replacements like touch screen devices are better than keyboard for the security purpose.

Things we do for the security purpose of the people will come under the service and will be encouraged by the government and other good souls.

If the above solution is helpful to you in any way please rate it Or if you have any concerns please comment it, I will help you through