Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)PA
Posts
5
Comments
1,786
Joined
2 yr. ago

  • This attack is useless in the real world.

    That said, what gives you the idea a split keyboard (if they had a sample of you typing on it etc) would be any different than a normal one?

    It is just another keyboard with a different sound profile.

  • I would have an easier time infecting someone‘s personal phone than a company machine

    What did you mean by this then other than you, personally, are skilled at such things and have system penetration experience?

  • The problems is that even with up to 95% accuracy that still means the with a password length of 10 there is a 50/50 chance that one character is wrong.

    A password with one character wrong is just as useless as randomly typing.

    Which character is wrong and what should it be? You only have 2 or 3 more guess till most systems will lock the account.

    This is an interesting academic exercise but there are much better and easier ways to gain access to passwords and systems.

    The world is not a bond movie.

    Deploying social engineering is much easier than this sort of attack.

  • You don’t need physical access, just some malware

    Which you still need to have previously installed...

    If the person has allowed malware to be installed just install a keylogger (which gives you 100% accuracy every time) rather than jump through more hoops with this.

  • Because of different placement on the keyboard and different finger pressure, each key press has a slightly different sound.

    The telling thing in this story is this

    with 95 percent accuracy in some cases.

    For some people (those with a very consistent typing style on a known keyboard) they were right 95% of the time.

    In the real world this type of thing is basically useless as you would need a decent sample of the person typing on a known keyboard for it to work.

    To go from keystroke sounds to actual letters, the eggheads recorded a person typing on a 16-inch 2021 MacBook Pro using a phone placed 17cm away and processed the sounds to get signatures of the keystrokes.

    So to do this you need to have physical access to the person (to place a microphone nearby) and know what type of device they are typing on and for it to be a device that you have already analysed the sound profile of.

  • The headline misses these details

    The Biden administration has moved to choke off China’s role in the US’s electric vehicle supply chain

    no US-manufactured EVs that include Chinese-made battery components will be eligible for the full subsidies

    What if china made EV's are still cheaper than US made even with the subsidies?

    I am reminded of the US response to Japanese cars in the 60s and 70s, which worked out so well for the US auto industry.

  • Just because it is internal does not mean she will drop the cheerleading facade. I have worked in large corps and this is totally on brand for the bullshit that gets passed around as staff motivation/ justification for batshit management decisions.

    Quite simply we will never know if she actually believes this shit as we are not part of the in group.

  • Good on you for walking.

    I told him I’m not taking it upon myself to educate him. He can read a book or two about it

    As a guy who has seen several women friends fall for the "I can change him" mindset, well done. It is not your job to fix the world view of a person who does not want to.

    I remember an old joke:

    "How many psychologists does it take to change a light bulb?"

    'One, but the light bulb has got to want to change.'

    I know it sucks right now but at least he showed his cards early and you didn't have to waste too much time on him.