AI and Residual Finger Heat Could Be a Password Cracker’s Latest Tools

Share:

New research demonstrates the use of thermal camera images of keyboards and screens in concert with AI to correctly guess computer passwords faster and more accurately.

Password-cracking and guessing attempts are successful enough as it is to put more than a little gray in the hair of experienced cybersecurity professionals. Now new research shows even more effective cracking attempts could be perpetrated by attackers equipped with a cheap thermal camera and some simple deep-learning models.

The AI-driven attacks were conceptualized and refined by Dr. Mohamed Khamis of the University of Glasgow School of Computing Science and his colleagues at the school, Norah Alotaibi and Dr. John Williamson, who are set to publish their results in an upcoming issue of the ACM Transactions on Privacy and Security journal.

The paper details their work to use off-the-shelf thermal cameras and a probabilistic model that utilized 1,500 thermal images they took of recently used keyboards to create a method of accurately cracking passwords — even in uncontrolled settings. Dubbed ThermoSecure, the method captures heat signatures via thermal cameras and analyzes them with the researchers’ AI modeling to guess a password with 86% accuracy when the images are taken within 20 seconds of input, and 62% accuracy within 60 seconds of input.

“Even without knowing the order of the keys, it is possible to significantly reduce the search space, which means fewer attempts are required to guess a password,” the researchers wrote in their paper.

Khamis pointed to the accessible price of thermal cameras — which can be picked up for less than $200 — as a cue for why his team wanted to explore this as a potential threat vector. As he explains, this is likely an area where the bad guys are already innovating to develop ways to leverage these tools to their advantage.

“They say you need to think like a thief to catch a thief. We developed ThermoSecure by thinking carefully about how malicious actors might exploit thermal images to break into computers and smartphones,” he said. “It’s important that computer security research keeps pace with these developments to find new ways to mitigate risk, and we will continue to develop our technology to try to stay one step ahead of attackers.”

Not the First Thermal Rodeo

While this is not the first piece of research touching on the use of thermal imaging to guess passwords, previous studies took pictures in highly controlled settings. This latest one focused on how the layering of AI can bridge the gap in accuracy in uncontrolled conditions that might be affected by different camera angles and user behavior. The study also examined how factors like password length and typing styles could impact the accuracy of this technique, offering some hints for mitigation measures.

For example, the jump from eight-symbol passwords up to 16-symbol passwords cut the accuracy of the attack by 26 points when images were taken 20 seconds after input. Similarly, faster-touch typists left less of a heat signature than slower “hunt-and-peck” typists, meaning that the accuracy was about 12 points lower for the former compared with the latter.

Some other mitigating factors included the use of backlit keyboards — which heat up keys enough to “light up” a thermal image enough to flummox the AI model — and the kind of plastic used in a keyboard. For example, ABS plastic retains heat for significantly less time than PBT plastic.

Of course, one of the most reliable mitigations are the ones that are cited for just about any kind of password-cracking or guessing attacks: that is, seeking out alternative login methods.

“Users can help make their devices and keyboards more secure by adopting alternative authentication methods, like fingerprint or facial recognition, which mitigate many of the risks of thermal attack,” Khamis said. “In my team, we have previously proposed authentication schemes that rely on eye movements for password entry; gaze-based authentication is resistant to thermal attacks by design.”

https://www.darkreading.com/endpoint/ai-and-residual-finger-heat-could-be-a-password-cracker-s-latest-tools

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:07 pm, Jul 7, 2025
weather icon 20°C
L: 19° | H: 21°
broken clouds
Humidity: 51 %
Pressure: 1012 mb
Wind: 11 mph NNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 60%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:52 am
Sunset: 9:18 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
19° | 21°°C 0 mm 0% 13 mph 51 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
12° | 24°°C 0 mm 0% 12 mph 76 % 1019 mb 0 mm/h
Wed Jul 09 10:00 pm
weather icon
15° | 25°°C 0.2 mm 20% 5 mph 68 % 1023 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 6 mph 74 % 1024 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 11 mph 60 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 13 mph 48 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 21°°C 0 mm 0% 10 mph 41 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 51 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 15°°C 0 mm 0% 11 mph 65 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
12° | 12°°C 0 mm 0% 12 mph 76 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0 mm 0% 10 mph 72 % 1016 mb 0 mm/h
Tomorrow 10:00 am
weather icon
18° | 18°°C 0 mm 0% 10 mph 46 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
22° | 22°°C 0 mm 0% 8 mph 35 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,390.74
0.13%
Ethereum(ETH)
€2,173.51
1.20%
Tether(USDT)
€0.85
-0.02%
XRP(XRP)
€1.94
0.03%
Solana(SOL)
€129.37
2.05%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.144547
1.78%
Shiba Inu(SHIB)
€0.000010
-0.22%
Pepe(PEPE)
€0.000009
0.43%
Scroll to Top