Typing sounds can be used to determine keystrokes, new research shows -- your keyboard can reveal passwords, even in noisy environments

(Image credit: Cherry)

Researchers have found a way ( PDF link ) to determine keystrokes from the sound of input from keyboards, making PC users vulnerable to hackers. This type of attack can also determine keystroke patterns, even in noisy conditions and has an overall 43% success rate.

The method was tested by collecting unknown keystrokes from a recording of more than 20 people. The attack uses an English dictionary to enhance its text detections and is tested with various environmental acoustics.

Acoustic-based attacks have been extensively investigated by others. Researchers at Cornell used AI to listen to keyboard emissions to determine keystrokes with 95% accuracy, which in this case used a Macbook Pro. The difference is that this attack method is platform agnostic and only needs a device with a microphone to be near a physical keyboard. This could be a smartphone, laptop, or IoT device. What makes this attack more effective is when:

  • The recordings contain environmental noise
  • The recorded typing sessions for the same target take place on different keyboards
  • The recordings were taken using a low-quality microphone
  • The target is free to use any typing style

This was discovered by Alireza Taheritajar and Reza Rahaeimehr from Georgia's Augusta University, who published a paper detailing this acoustic side-channel attack method. The attack relies on the sound emissions and the user's typing. Once it captures adequate samples from the targeted user, it correlates the sound patterns with keystrokes, allowing the attacker to retrieve sensitive information such as login credentials.

Multiple Delivery Methods for Acoustic Attack

The delivery of such attack methods can be deployed as malware from websites, browser extensions, apps, cross-site scripting, and compromised USB keyboards. USB input devices can store and deliver malware just like any USB storage drive, as they usually have enough computing capacity and storage to run pre-installed scripts. Keyboards have been known to contain keyloggers installed by manufacturers and sold from websites like Amazon by many companies and drop shippers. Therefore the thought of having an auto-executable attack from keyboards is not far-fetched.

While such attacks could be deterred with quieter keyboards, hacking methods are improved over time and with the success rate of 43%, it shows the feasibility of having such an attack method. Apart from not using a physical keyboard, professional typists can make it extremely difficult as they can type extremely fast and have overlaps between multiple keystrokes, according to the research paper.

However, the research also mentioned in the conclusion intends to use LLMs in its future projects to improve the success rate, further highlighting the potential consequences of AI to compromise digital security .

Stay on the Cutting Edge

Join the experts who read Tom's Hardware for the inside track on enthusiast PC tech news — and have for over 25 years. We'll send breaking news and in-depth reviews of CPUs, GPUs, AI, maker hardware and more straight to your inbox.

Freelance News Writer