PILOT: Password and PIN Information Leakage from Obfuscated Typing Videos
Kiran Balagani, Matteo Cardaioli, Mauro Conti, Paolo Gasti, Martin, Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas,, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu

TL;DR
This paper introduces PILOT, an attack that exploits inter-keystroke timing information from obfuscated typing videos to recover passwords and PINs, revealing significant security vulnerabilities in masked input methods.
Contribution
The study presents a novel attack method, PILOT, that effectively extracts timing information from videos to compromise masked passwords and PINs, demonstrating substantial security risks.
Findings
PILOT recovers 8-character passwords in as few as 19 attempts.
It guesses about 3% of PINs within 10 attempts, a 26-fold improvement over random guessing.
Leakage varies across scenarios, being minor in some cases and substantial in others.
Abstract
This paper studies leakage of user passwords and PINs based on observations of typing feedback on screens or from projectors in the form of masked characters that indicate keystrokes. To this end, we developed an attack called Password and Pin Information Leakage from Obfuscated Typing Videos (PILOT). Our attack extracts inter-keystroke timing information from videos of password masking characters displayed when users type their password on a computer, or their PIN at an ATM. We conducted several experiments in various attack scenarios. Results indicate that, while in some cases leakage is minor, it is quite substantial in others. By leveraging inter-keystroke timings, PILOT recovers 8-character alphanumeric passwords in as little as 19 attempts. When guessing PINs, PILOT significantly improved on both random guessing and the attack strategy adopted in our prior work [4]. In particular,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Advanced Malware Detection Techniques · Interactive and Immersive Displays
