{"id":272052,"date":"2021-06-11T14:31:08","date_gmt":"2021-06-11T11:31:08","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/scrambling-against-smudge-attacks\/"},"modified":"2021-06-11T14:31:08","modified_gmt":"2021-06-11T11:31:08","slug":"scrambling-against-smudge-attacks","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/scrambling-against-smudge-attacks\/","title":{"rendered":"#Scrambling against smudge attacks"},"content":{"rendered":"<p>&#8220;<strong>#Scrambling against smudge attacks<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2020\/3-phone.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2020\/3-phone.jpg\" data-sub-html=\"Credit: CC0 Public Domain\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2020\/3-phone.jpg\" alt=\"phone\" title=\"Credit: CC0 Public Domain\" width=\"800\" height=\"530\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Credit: CC0 Public Domain<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>The security-conscious among us use a PIN, a personal identification number, to &#8220;lock&#8221; our smartphones so that if the device is lost or stolen, a third party should not be able to access our contacts, messages, and other information held in myriad <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>s without a lot of effort to guess the PIN.<\/p>\n<p>                                                                                However, so many modern devices that hold our personal and business information are touchscreen and hackers and thieves are always resourceful. Picture the scene you give your phone screen a clean before tapping in your PIN to access your emails etc. The smudges left by your fingertips remain on the screen, marking out the likely numbers from the virtual keypad on your phone that you used to tap in your PIN.<\/p>\n<p>Soon after, the phone is lost or stolen and that malicious third party carries out a &#8220;smudge attack&#8221;\u2014they look at the screen and can have a good guess at the digits in your PIN and try them in various combinations pretty quickly. It is far easier to brute-force a four-digit PIN if you know the four digits rather than having to try all possible combinations of the numbers 0 to 9, after all!<\/p>\n<p>So, how might one avoid a smudge attack? The obvious answer is to clean the phone&#8217;s screen more frequently and im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>tely after entering a PIN, but a less &#8220;onerous&#8221; approach would be for the device itself to have a randomized keypad for unlocking. In a scrambled keypad, the numbers 0 to 9 would be arranged differently each time you go to unlock your phone, so there would be no build-up of your frequently smudged keys as it were and thus far less chance of a successful smudge attack.<\/p>\n<p>At the moment, a scrambled keypad is not a feature of Android nor iOS devices. New work from a team in the U.S. published in the International Journal of Information and Computer Security, demonstrates how a scramble keypad might be implemented to protect smartphones from smudge attacks. Geetika Kovelamudi, Bryan Watson, Jun Zheng, and Srinivas Mukkamala of the New Mexico Institute of Mining and <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">Technology<\/a>, in Socorro, have carried out a usability and security study of a scramble keypad. They explain that it works perfectly to protect from smudge attacks. The scramble keypad also reduces the risk of someone illicitly gleaning your PIN by &#8220;shoulder surfing&#8221; (watching over your shoulder) while you tap it in, because the digits of the pad 0 to 9 will not be in the familiar places for their eye to quickly ascertain as you tap.<\/p>\n<p>The implementation of a scramble pad would require very little additional coding to the touchscreen device&#8217;s boot-up system but would offer a new level of protection from smudge attacks, a degree of protection from shoulder surfers, and potentially some protection from side-channel attacks.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Tricking the eye to defeat shoulder surfing attacks\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                Geetika Kovelamudi et al, On the adoption of scramble keypad for unlocking PIN-protected smartphones, <i>International Journal of Information and Computer Security<\/i> (2021).  <a rel=\"nofollow noopener\" target=\"_blank\" data-doi=\"1\" href=\"http:\/\/dx.doi.org\/10.1504\/IJICS.2021.115345\">DOI: 10.1504\/IJICS.2021.115345<\/a><\/p><\/div>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Scrambling against smudge attacks (2021, June 11)<br \/>\n                                                 retrieved 11 June 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-06-scrambling-smudge.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-06-scrambling-smudge.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Scrambling against smudge attacks&#8221; Credit: CC0 Public Domain The security-conscious among us use a PIN, a personal identification number, to &#8220;lock&#8221; our smartphones so that if the device is lost or stolen, a third party should not be able to access our contacts, messages, and other information held in myriad apps without a lot of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":272053,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2020\/3-phone.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-272052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/272052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=272052"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/272052\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/272053"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=272052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=272052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=272052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}