Vulnerabilities / Threats
8/11/2010
10:26 AM
50%
50%

Touchscreen Smudges Pose Security Risk

Residual fingerprint oils on smartphones, ATMs, and other devices may reveal passwords and other confidential data, find security researchers.




Slideshow: Cloud Security Pros And Cons
(click for larger image and for full photo gallery)
Prepare for a new mobile security threat: smudges. Or to be more precise, the oily residue left behind by fingers on your iPhone, Android, BlackBerry, or other touchscreen mobile device may help an attacker deduce your password.

That's the message from researchers at the University of Pennsylvania, who presented a paper at this week's Usenix conference analyzing "Smudge Attacks on Smartphone Touch Screens."

Based on their results, "the practice of entering sensitive information via touchscreens needs careful analysis," said the researchers. "The Android password pattern, in particular, should be strengthened." But they cautioned that any touchscreen device, including ATMs, voting machines, and PIN entry devices in retail stores, could be susceptible to smudge attacks.

Touchscreens, of course, are an increasingly common feature of mobile computing devices. According to Gartner Group, 363 million touchscreen mobile devices will be sold in 2010, an increase of 97% over last year's sales. But are passwords entered via touchscreens secure?

To find out, the researchers studied two different Android smartphones, the HTC G1 and the HTC Nexus1, evaluating different photography techniques for discerning a smudge pattern. With the best setup, they saw a complete smudge pattern two-thirds of the time, and could partially identify one 96% of the time. Furthermore, in ideal conditions -- say, if an attacker had physical possession of the device -- the researchers could oftentimes see finger-stroke directionality too, meaning that "the order of the strokes can be learned, and consequently, the precise patterns can be determined," they said.

While Android 2.2 adds an option for alphanumeric passwords, the team tested the numbers-only password protocol, which uses a virtual nine-digit keypad and imposes certain restrictions on repeat "contact points," as well as swipe patterns. The researchers note that numeric passwords are likely to remain the norm, especially for power users who must continuously "swipe in" to their device.

Given the contact point restrictions, the researchers found that "the password space of the Android password pattern contains 389,112 possible patterns." But an attacker will face a lockout -- typically, 30 seconds in duration -- after inputting an incorrect password. That would make manually entering too many passwords laborious. But by comparing smudge patterns with a dictionary of common patterns, an attacker might significantly reduce the password space. Thankfully, there's a failsafe on Android phones, since after 20 failed password attempts, a user must enter his or her Google username and password to authenticate.

The good news is that for now, even with a smudge attack, an attacker typically wouldn't be able to reduce the password space to 20 or fewer possibilities. But going forward, don't rule out the possibility that enterprising attackers may add on additional techniques to help see through smudges.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Join Dark Reading community editor Marilyn Cohodas and her guest, David Shearer, (ISC)2 Chief Executive Officer, as they discuss issues that keep IT security professionals up at night, including results from the recent 2016 Black Hat Attendee Survey.