Site navigation

Glasgow Uni Researchers Advise on How to Combat “Thermal Attacks”

Michael Edgar

,

thermal attacks recommendations Glasgow University
Glasgow Uni computer security experts unveil 15 recommendations to combat “Thermal Attacks”.

The recommendations come from a team of computer scientists from the University of Glasgow, who created an AI-powered system that demonstrated the unique vulnerabilities presented by “thermal attacks,” where passwords could be deciphered from heat-trace imaging. 

This form of thermal imaging can decipher two thirds of passwords that consist of up to 16 characters, 82% of 12-character passwords, and 100% of six-character passwords, according to a paper by the researchers. Victims can have passwords and pins lifted from smartphone screens, keyboards, and PIN pads. 

Now, the team has released a comprehensive set of 15 recommendations to defend against such attacks which are: 

  • Using Biometrics – like fingerprints or facial recognition –  which don’t leave heat traces.
  • Blowing on the interface to cool down left what traces. 
  • Feed filtering the keyboard to conjure the thermal camera. 
  • Changing the input method to a touchless alternative, such as a computer mouse. 
  • Heated element behind or below the interface to obfuscate the input. 
  • Wear gloves to serve as a barrier between the user’s fingers and the interface. 
  • Use graphical cues, where the user’s credentials consist of a series of images to choose from. 
  • Improve the credentials, making them harder by adding overlapping characters or longer inputs. 
  • Change material of used interfaces to lower thermal conductivity. 
  • Add multimodal or multi-factor authentication. 
  • Use privacy enhancing keyboards which shuffle the layout of the input keys. 
  • Use something to cover the interface until the heat traces decay. 
  • Touch something cold before interaction to leave fewer heat traces. 
  • Cover the interface with your hands to leave additional heat traces. 
  • Use thimblettes as a non-conductive barrier between the finger and the interface. 

The team who developed the study ran an online survey with 306 participants looking to determine the preference of strategies among users. The study found that users suggested some strategies that were not in the literature such as waiting until the surrounding area seemed safe at an ATM, or agreed to double down on existing methods like two-factor authentication. 

“We also saw that they considered issues like hygiene, which made the strategy of breathing on devices to mask heat traces very unpopular, and privacy, which some users considered when thinking about additional security measures like face or fingerprint recognition,” said Dr. Mohamed Khamis, who led the research from the University of Glasgow’s School of Computing Science.


Recommended reading


Authors of the research also put forward recommendations for manufacturers of devices used in the public sphere, taking thermal attacks into consideration during the design phase. For devices already in circulation, they recommend software updates to help remind users to take action against thermal cameras. 

Dr Khamis added, “Our final recommendation is to the manufacturers of thermal cameras, who could stop attacks by integrating new software locks to prevent thermal cameras from taking pictures of surfaces like PIN pads on bank machines.”

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data