2017
DOI: 10.1007/s10207-017-0369-x
|View full text |Cite
|
Sign up to set email alerts
|

Stealing PINs via mobile sensors: actual risk versus user perception

Abstract: In this paper, we present the actual risks of stealing user PINs by using mobile sensors versus the perceived risks by users. First, we propose PINlogger.js which is a JavaScript-based side channel attack revealing user PINs on an Android mobile phone. In this attack, once the user visits a website controlled by an attacker, the JavaScript code embedded in the web page starts listening to the motion and orientation sensor streams without needing any permission from the user. By analysing these streams, it infe… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

4
44
0

Year Published

2018
2018
2024
2024

Publication Types

Select...
5
1

Relationship

1
5

Authors

Journals

citations
Cited by 48 publications
(48 citation statements)
references
References 26 publications
4
44
0
Order By: Relevance
“…Furthermore, it is expected that app stores such as the Apple app store and Google Play will screen the apps and impose severe penalties if the app is found to contain malicious content. However, in the browser-based attacks described in [11][12][13][14], we have demonstrated that these measures are ineffective. Apart from academic efforts, there are industrial solutions (e.g., Navenio (navenio.com)) that use some of these sensors such as the accelerometer to track users precisely indoors and outdoors.…”
Section: Sensor Management Challengesmentioning
confidence: 85%
See 4 more Smart Citations
“…Furthermore, it is expected that app stores such as the Apple app store and Google Play will screen the apps and impose severe penalties if the app is found to contain malicious content. However, in the browser-based attacks described in [11][12][13][14], we have demonstrated that these measures are ineffective. Apart from academic efforts, there are industrial solutions (e.g., Navenio (navenio.com)) that use some of these sensors such as the accelerometer to track users precisely indoors and outdoors.…”
Section: Sensor Management Challengesmentioning
confidence: 85%
“…In our previous research [11][12][13][14], we have shown that the sensor management problem is spreading from apps to browsers. We proposed and implemented the first JavaScript-based side channel attack revealing a wide range of sensitive information about users such as phone calls' timing, physical activities (sitting, walking, running, etc.…”
Section: Introductionmentioning
confidence: 99%
See 3 more Smart Citations