Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

ATMs open to thermal imaging attack, researchers confirm

Heat from keypresses can be used to work out PINs

Article comments

Researchers have documented a method for working out ATM PIN numbers using residual traces of heat left on keypads after they have been touched by a person’s fingers.

The technique described (note: slow download) by Keaton Mowery, Sarah Meiklejohn and Stefan Savage of the University of California at San Diego explains how a thermal imaging camera could be used to visually record the heat left on each key as a way of snooping PINs.

Using this simple principle it would be possible to record the numbers entered, including their exact order (more recent keypresses appearing as warmer), for up to a minute after they are entered. Even without being able to detect the precise order of the PIN entered, just knowing which four numbers were involved would reduce the number of PINs from 10,000 combinations to only 24.

According to the researchers, if used in large-scale attacks the technique would in some cases outperform the tradition criminal method of shoulder-surfing PINs or recording them from a distance.

The limitations of the attack included the weight with which the keys were pressed by a user (only heavier presses left enough heat) and the material from which it was made with plastic keypads relatively easy to detect and metal ones resisting the attack.

“Based on our current results, the obvious approach to prevent our (and essentially any thermal-camera-based) attack would be to use metal keypads exclusively,” conclude the researchers.

The air temperature culd also play a part in the success of detecting keypresses on metal ATM keypads, which could reduce the security advantage of using this defence in some circumstances.

The research (credit to Chester Wisniewski of Sophos for noticing it on USENIX) was inspired by a 2005 study in which white hat researcher Michael Zalewski who tested the thermal imaging principle against safe keypad security.


More from Techworld

More relevant IT news


Rafael Prado Rocchi said: Old technic but easy to protect Instead of using a keyboard a touch screen should be used on the ATM and showing a keypad image And each time the ATM shows the keypad on the screen the keys would change position Nine years ago ATMs in Brazil have changed to this way because of this kind of atack Nowadays the protection is even better someone can screen-record what is being pressed and they would not know what was the numbersRafael Prado

Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *