Smartphone sensors give hackers a way in

Apps do not require user permissions to collect data from accelerometers or gyroscopes

December 31, 2017 09:54 pm | Updated 09:57 pm IST - Singapore

Representational image.

Representational image.

Instruments in smartphones such as the accelerometer, gyroscope and proximity sensors represent a potential security vulnerability as researchers have found that data from these sensors could be used by hackers to guess the security password.

Using a combination of information gathered from six different sensors found in smartphones and analysing them with machine learning and deep learning algorithms, the researchers succeeded in unlocking Android smartphones with 99.5% accuracy within only three tries, said the study.

The researchers believe their work, published in Cryptology ePrint Archive , highlights a significant flaw in smartphone security, as using the sensors require no permissions to be given by the phone user and are available for all apps to access.

Position and light

Led by Shivam Bhasin of Nanyang Technological University, Singapore, the researchers used sensors in a smartphone to model which number had been pressed by its users, based on how the phone was tilted and how much light is blocked by the thumb or fingers. Researchers took Android phones and installed a custom application which collected data from six sensors: accelerometer, gyroscope, magnetometer, proximity sensor, barometer and ambient light sensor. “When you hold your phone and key in the PIN, the way the phone moves when you press 1, 5 or 9, is very different. Likewise, pressing 1 with your right thumb will block more light than if you pressed 9,” Mr. Bhasin said.

The classification algorithm was trained with data collected from a group of people. Although each individual enters the security PIN on their phone differently, the scientists showed that as data from more people is fed to the machine learning algorithm, success rates improved over time.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.