Side-Channel Attacks on physical User Input

No ratings

Presented at Securi-Tay 2025 by

In the world of cybersecurity, we often focus on traditional defense mechanisms, but the truth is, attackers may not even need to directly hack into your device to steal sensitive information—they might just be listening in. From the subtle sounds of keypresses to the vibrations of your phone, side-channel attacks exploit the very data we unknowingly leak through seemingly innocent actions. In this talk, we'll explore the fascinating realm of user input side-channel attacks, delving into the acoustic, motion, vibration, visual, and Wi-Fi Channel-State-Information methods used by attackers to eavesdrop on everything from emails and passwords to PINs. We will discuss these different mediums for such a side-channel attack and then we'll dive into my work, which recovers typed passphrases via the acoustic side-channel using machine learning and dictionary attacks. Get ready to hear the sound of security—it’s not as quiet as you think.