Hackers Can Guess PINs, Passwords From Brainwaves: Study

Advertisement
By Press Trust of India | Updated: 30 June 2017 17:54 IST
Highlights
  • Hackers can guess a user's passwords by monitoring their thoughts
  • Electroencephalograph (EEG) headsets allow users to control robotic toys
  • EEG headset is currently available to consumers online

Photo Credit: UAB

Hackers can guess a user's passwords by monitoring their thoughts, according to scientists including those of Indian origin who suggest that brainwave-sensing headsets need better security.

Electroencephalograph (EEG) headsets allow users to control robotic toys and video games with the mind.

Researchers at the University of Alabama at Birmingham in the US found that a person who paused a video game and logged into a bank account while wearing an EEG headset was at risk for having their passwords or other sensitive data stolen by a malicious software programme.

Advertisement

"These emerging devices open immense opportunities for everyday users," said Nitesh Saxena, associate professor from University of Alabama.

Advertisement

"However, they could also raise significant security and privacy threats as companies work to develop even more advanced brain-computer interface technology," said Saxena.

The team, including PhD student Ajaya Neupane, used one EEG headset currently available to consumers online and one clinical-grade headset used for scientific research to demonstrate how easily a malicious software programme could passively eavesdrop on a user's brainwaves.

Advertisement

While typing, a user's inputs correspond with their visual processing, as well as hand, eye and head muscle movements. All these movements are captured by EEG headsets.

The team asked 12 people to type a series of randomly generated PINs and passwords into a text box as if they were logging into an online account while wearing an EEG headset, in order for the software to train itself on the user's typing and the corresponding brainwave.

Advertisement

"In a real-world attack, a hacker could facilitate the training step required for the malicious programme to be most accurate, by requesting that the user enter a predefined set of numbers in order to restart the game after pausing it to take a break, similar to the way CAPTCHA is used to verify users when logging onto websites," Saxena said.

The team found that, after a user entered 200 characters, algorithms within the malicious software programme could make educated guesses about new characters the user entered by monitoring the EEG data recorded.

The algorithm was able to shorten the odds of a hacker's guessing a four-digit numerical PIN from one in 10,000 to one in 20 and increased the chance of guessing a six-letter password from about 500,000 to roughly one in 500.

"Given the growing popularity of EEG headsets and the variety of ways in which they could be used, it is inevitable that they will become part of our daily lives, including while using other devices," Saxena said.

"It is important to analyse the potential security and privacy risks associated with this emerging technology to raise users' awareness of the risks and develop viable solutions to malicious attacks," he said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a Series Tipped to Launch Globally on This Date
  2. How to Reset Your Instagram Reels Algorithm
  3. Oakley Meta Glasses Now Available in India for Athletes
  4. Google Might Be Making It Hassle-Free to Switch From ChatGPT to Gemini
  5. Realme Buds Air 8 Review: Big on Features, but There's A Catch
  6. Oppo Find X10 Pro Tipped to Arrive With This Camera Upgrade
  7. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra
  8. Infinix Note 60, Note 60 Pro, Note 60 Ultra May Be Sold in These Variants
  9. OpenAI Introduces Codex App With Agentic Coding for macOS
  10. Sampradayini Suppini Suddapoosani Now Streaming Online: What You Need to Know
  1. Mozilla Firefox Will Let You Decide How Much AI You Want in Your Browser
  2. Oppo Find X10 Pro Will Launch With Two 200-Megapixel Rear Cameras, Tipster Claims
  3. Psych Siddhartha OTT Release Date: When and Where to Watch it Online?
  4. Parasakthi OTT Release Revealed: When and Where to Watch Sivakarthikeyan Starrer Movie Online?
  5. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra: Expected Specifications, Features
  6. Sampradayini Suppini Suddapoosani Now Streaming Online: What You Need to Know
  7. Lucky The Superstar OTT Release Date Revealed: Know When and Where to Watch This Upcoming Tamil Comedy Drama Film
  8. Redmi K Pad 2 Tipped to Launch With MediaTek Dimensity 9500 SoC, Bose-Tuned Speakers
  9. Nioh 3 Will Be a PS5 Console Exclusive for 6 Months, Could Launch on Other Platforms Later This Year
  10. Nothing Phone 4a Series Tipped to Launch Globally Next Month: Expected Specifications, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.