Computer security specialists have developed a system capable of guessing computer and smartphone users’ passwords in seconds.
The technology works by analysing the traces of heat their fingertips leave on keyboards and screens.
Researchers from the University of Glasgow developed the ThermoSecure system to demonstrate how falling prices of thermal imaging cameras and rising access to machine learning are creating new risks for ‘thermal attacks.’
In a paper published in the journal ACM Transactions on Privacy and Security, Dr Mohamed Khamis, who led the development of ThermoSecure alongside Norah Alotaibi and Dr John Williamson, set out to harness machine learning to make the attack process more accurate. To do so, they took 1,500 thermal photos of recently used QWERTY keyboards from different angles.
They then trained an AI model to effectively read the images and make informed guesses about the passwords from the heat signature clues using a probabilistic model.
Through two user studies, they found that ThermoSecure could reveal 86% of passwords when thermal images are taken within 20 seconds, and 76% when within 30 seconds, dropping to 62% after 60 seconds of entry.
They also found that within 20 seconds, the tech was capable of successfully attacking even long passwords of 16 characters, with a rate of up to 67% correct attempts.
As passwords grew shorter, success rates increased – 12-symbol passwords were guessed up to 82% of the time, eight-symbol passwords up to 93% of the time, and six-symbol passwords were successful in up to 100% of attempts.
What are thermal attacks?
Thermal attacks can occur when typing a passcode on a computer keyboard, smartphone screen or ATM keypad before leaving the device unguarded.
A passer-by equipped with a thermal camera can take a picture that reveals the heat signature of where their fingers have touched the device.
The brighter an area appears in the thermal image, the more recently it was touched. By measuring the relative intensity of the warmer areas, it is possible to determine the specific letters, numbers or symbols that make up the password and estimate the order in which they were used. From there, attackers can try different combinations to crack users’ passwords.
Previous research by Dr Khamis has already demonstrated that non-experts can successfully guess passwords simply by looking carefully at thermal images taken between 30 and 60 seconds after surfaces were touched.
Recommended
- CodeClan CEO Melinda Matthews-Clarkson to step down
- LiberEat secures six-figure funding to pioneer AI allergen detection
- Tech Nation welcomes 35 companies into Upscale 8.0
Dr Khamis commented: “They say you need to think like a thief to catch a thief. We developed ThermoSecure by thinking carefully about how malicious actors might exploit thermal images to break into computers and smartphones.
“Access to thermal imaging cameras is more affordable than ever – they can be found for less than £200 – and machine learning is becoming increasingly accessible too. That makes it very likely that people around the world are developing systems along similar lines to ThermoSecure in order to steal passwords.
“It’s important that computer security research keeps pace with these developments to find new ways to mitigate risk, and we will continue to develop our technology to try to stay one step ahead of attackers.”
He added: “We’re also keen to highlight to policymakers the risks that these kind of thermal attacks pose for computer security. One potential risk-reduction pathway could be to make it illegal to sell thermal cameras without some kind of enhanced security included in their software. We are currently developing an AI-driven countermeasure system that could help address this issue.”
How to protect yourself
The ThermoSecure team has several suggestions for computer and smartphone users to protect themselves from thermal attacks.
Dr Khamis said: “Longer passwords are more difficult for ThermoSecure to guess accurately, so we would advise using long passphrases wherever possible. Longer passphrases take longer to type, which also makes it more difficult to get an accurate reading on a thermal camera, particularly if the user is a touch typist.
“Backlit keyboards also produce more heat, making accurate thermal readings more challenging, so a backlit keyboard with PBT plastics could be inherently more secure.
“Finally, users can help make their devices and keyboards more secure by adopting alternative authentication methods, like fingerprint or facial recognition, which mitigate many of the risks of thermal attack. In my team we have previously proposed authentication schemes that rely on eye movements for password entry; gaze-based authentication is resistant to thermal attacks by design.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





