Thermanator: Thermal Residue-Based Post Factum Attacks On Keyboard Password Entry
Tyler Kaczmarek, Ercan Ozturk, and Gene Tsudik

TL;DR
Thermanator demonstrates that thermal residues on keyboards can be exploited to recover entered passwords within a minute, highlighting a new security vulnerability for keyboard-based authentication.
Contribution
This paper introduces Thermanator, a novel post factum attack method exploiting thermal residues on keyboards to recover passwords, and provides empirical evidence of its effectiveness.
Findings
Passwords can be recovered up to 30 seconds after entry.
Partial password recovery is possible up to 1 minute after entry.
Hunt-and-Peck typists are especially vulnerable.
Abstract
As a warm-blooded mammalian species, we humans routinely leave thermal residues on various objects with which we come in contact. This includes common input devices, such as keyboards, that are used for entering (among other things) secret information, such as passwords and PINs. Although thermal residue dissipates over time, there is always a certain time window during which thermal energy readings can be harvested from input devices to recover recently entered, and potentially sensitive, information. To-date, there has been no systematic investigation of thermal profiles of keyboards, and thus no efforts have been made to secure them. This serves as our main motivation for constructing a means for password harvesting from keyboard thermal emanations. Specifically, we introduce Thermanator, a new post factum insider attack based on heat transfer caused by a user typing a password on a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Physical Unclonable Functions (PUFs) and Hardware Security · Advanced Malware Detection Techniques
