Hackers Can Guess Your PIN by Using Smartphone Sensor Data: Report

Advertisement
By Press Trust of India | Updated: 27 December 2017 18:23 IST
Highlights
  • The latest study shows the highest accuracy for guessing PINs
  • Gyroscopes and proximity sensors can be tapped for motion details
  • Using these sensors requires to permission from users

Data from your smartphone sensors can reveal PINs and passwords to hackers and allow them to unlock your mobile devices, according to a study led by an Indian-origin scientist.

Instruments in smartphones such as the gyroscope and proximity sensors represent a potential security vulnerability, said researchers from Nanyang Technological University (NTU) in Singapore.

Smartphone Motion Sensors Could Reveal User's PIN, Passwords: Report

Advertisement

Using machine learning algorithms and a combination of information gathered from six different sensors found in smartphones, researchers succeeded in unlocking Android smartphones with a 99.5 percent accuracy within only three tries, when tackling a phone that had one of the 50 most common PIN numbers.

Advertisement

The previous best phone-cracking success rate was 74 percent for the 50 most common PIN numbers, but NTU's technique can be used to guess all 10,000 possible combinations of four-digit PINs.

Led by Shivam Bhasin, NTU Senior Research Scientist, researchers used sensors in a smartphone to model which number had been pressed by its users, based on how the phone was tilted and how much light is blocked by the thumb or fingers.

Advertisement

The researchers believe their work highlights a significant flaw in smartphone security, as using the sensors within the phones require no permissions to be given by the phone user and are openly available for all apps to access.

The team of researchers took Android phones and installed a custom application which collected data from six sensors: accelerometer, gyroscope, magnetometer, proximity sensor, barometer, and ambient light sensor. "When you hold your phone and key in the PIN, the way the phone moves when you press 1, 5, or 9, is very different.

Advertisement

Likewise, pressing 1 with your right thumb will block more light than if you pressed 9," said Bhasin. The classification algorithm was trained with data collected from three people, who each entered a random set of 70 four-digit pin numbers on a phone.

At the same time, it recorded the relevant sensor reactions.

Known as deep learning, the classification algorithm was able to give different weightings of importance to each of the sensors, depending on how sensitive each was to different numbers being pressed.

This helps eliminate factors which it judges to be less important and increases the success rate for PIN retrieval.

Although each individual enters the security PIN on their phone differently, the scientists showed that as data from more people is fed to the algorithm over time, success rates improved.

So while a malicious application may not be able to correctly guess a PIN immediately after installation, using machine learning, it could collect data from thousands of users over time from each of their phones to learn their PIN entry pattern and then launch an attack later when the success rate is much higher.

The study shows how devices with seemingly strong security can be attacked using a side-channel, as sensor data could be diverted by malicious applications to spy on user behaviour and help to access PIN and password information, said Professor Gan Chee Lip from NTU.

To keep mobile devices secure, Bhasin advises users to have PINs with more than four digits, coupled with other authentication methods like one-time passwords, two-factor authentications, and fingerprint or facial recognition.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi K90 Pro Max, Redmi K90 Launched With Bose Audio: See Price, Features
  2. Garmin D2 Air X15, Garmin D2 Mach 2 Launched With PlaneSync Technology
  3. iQOO Neo 11 Arrives on Geekbench With This Snapdragon Chipset
  4. Here's Why the OnePlus 15 Won't Sport a 2K Resolution Display
  5. OnePlus Ace 6 Key Specifications Confirmed Ahead of China Launch
  6. iQOO 15 Microsite Confirms Availability on Amazon Ahead of Launch
  7. OnePlus Tipped to Launch New Smartphone With This Upcoming Qualcomm Chip
  8. Vivo X300 Series Surfaces on BIS Website, Could Launch in India Soon
  9. Here's When the Vivo X300 Pro and Vivo X300 Could Launch in India
  1. Physicists Reveal a New Type of Twisting Solid That Behaves Almost Like a Living Material
  2. James Webb Telescope Finds Early Universe Galaxies Were More Chaotic Than We Thought
  3. Microsoft Introduces Major Copilot Upgrade, Brings Avatar, Groups and Health Features
  4. Next-Gen Xbox Will Be 'Very Premium, Very High-End Curated Experience', Says Xbox President Sarah Bond
  5. ChatGPT's Voice Mode Could Soon Support Rich Content Including Links, Maps: Report
  6. Redmi Watch 6 Launched With 2.07-Inch AMOLED Screen, Up to 24-Day Battery Life: Price, Features
  7. UK FCA Cracks Down on Crypto Firms, Hundreds of Exchanges Receive Warnings
  8. Google Pixel 10 Series GPU Driver Update Reportedly Confirmed by Company
  9. Honor Magic 8 Lite Key Specifications Revealed via Product Listings, Could Launch Soon
  10. Hong Kong’s Securities Regulator Approves First Spot Solana ETF
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.