If you're not already mitigating the risk of someone *hearing* you type your passwords, you should probably start... It always seemed like a probable risk, but now it's confirmed:

https://arxiv.org/abs/2308.01074

Reply to this note

Please Login to reply.

Discussion

Holy fuck, guess I'm muting my microphone on stream now while typing pwds

You weren't already? 😅

The harder part to mitigate is when you want to unlock your machine outside your own office...

Don't forget to change your passphrases in case someone recorded a past stream

100% I typed my sudo password to my PC many times, facking hell.

Changing now...

Gotta find an overlay to play while you type your passwords, something that is typing out some choice words 😂

Seriously tho.. this is crazy 😳

I'm not sure an overlay is going to be effective.

I have an extra clicky keyboard next to me when entering passwords Under Siege style

hardware switch on my cam/mic for laptop, trustable toggles on @grapheneos for mobile

wow

They

Who’s they?

Don't use general purpose computers for bitcoin security. https://airgapcomputer.com

Bitcoin isn't the only security that matters

🎯

This is pretty crazy. I guess using biometrics (e.g. Touch ID) and auto fill is now the safer option for performing an action such as logging in from a public place or coffee shop?

Copy/Paste there problem solved.

not a clipboard maxi I see 🤣

https://onlykey.io/

Problem solved. I love mine.

I just shout really loudly as I type in my password

my father does this too. The bad part is: what he shouts is the password

🤣 morte de 🤣

If you're not already mitigating the risk of someone stealing 216.93 BTC because you are stupid and keeping it on a "hot" wallet, you should probably start... It always seemed like a probable risk, but now it's confirmed.

nostr:note1uthf9xhurwlv2kx3xqccqyzf9uwhcnemd3tv49rpclcywwq6gxqqxpnqwz

This is why I always scream as I type it in

Screaming the password is not much better ;-)

Plus sûr

Are you saying we need Neuralink? :)

I'm pondering a retina scanner that combines a hash with a secret salt and does TOTP. Something that won't work if you're asleep ideally

Well, I know how to build a retina scanner if you ever need one :)

But an iris scanner is probably easier. Just keep in mind that both Iris and Retina do slightly change over a long lifespan.

If everything you have is tied to having access to your eyes you might lose everything on a simple cataract surgery.

Catarac surgery? Worldcoin fail trashhhhh 🤣

Passkeys to the Rescue

Are silent keyboards a thing? Seems like the most straightforward countermeasure.

Your hands could make subtle sound.

Might be harder to decipher, but I wouldn't rely on it

A potential workaround is N randomly generated characters . So the screen prompts typing in those random characters and asks the user to insert password letters at random intervals. tr#fdawdftjs (in that case the password was farts and the random stream/intervals were generated by the noises in my head). There are attacks on this based on repetition, potential sound differences in chosen letters, and bad or compromised RNGs. The ratio of noise to filler matters.

nostr:nevent1qqsw9m5jnt7ph0k9trgnqvvqzpyj78tufuakc4k2j3su0uz88qdyrqqpp4mhxue69uhkummn9ekx7mqzyr7at68k4cxms9a7pdca5gzf3svqd95d3fj9j4vuyj0nyta8x3j2wqcyqqqqqqg54zsum

So what to do.... guard? Just ensure nothing running? Hmmmm

If you're on a call, mute.

I'm not sure if you're in public or an untrusted room

Roger makes sense. I like to mute cuz I move a lot lollll

Yooo 🫵, yea?

Phone, other. Pack lol dunno

Setup a hackerspace inside the karaoke bar.

So how are we mitigating this risk? Lol

Get an IBM Model M keyboard and they’ll never figure out what keys you’re hitting with the microphone clipping.

This is why I use a keepass vault with extremely hardened security. Key files, and auto type obfuscation. If they can get past that security they earned it..😆

GM.

nostr:note1uthf9xhurwlv2kx3xqccqyzf9uwhcnemd3tv49rpclcywwq6gxqqxpnqwz

I switched to a permanent offline device for password store and use a QR reader for entering every password on my devices now, never use a physical keyboard. I guess I'll be safe-ish...

I read about those high res cameras in Walmart where the viewer can see whats on the cell phones and finger movements

Yikes

That's creepy

how do you handle this?

Yup. Modern day keyloggers.