青岛专科学校有哪些:安全系统存漏洞 ATM机或泄露密码

来源:百度文库 编辑:九乡新闻网 时间:2024/05/17 07:45:19

安全系统存漏洞 ATM机键盘余温或泄露密码

http://www.sina.com.cn  2011年09月01日 16:04   环球网



ATM机会泄露你的银行卡密码?

  The heat your fingers leave behind on an ATM keypad can tell the hacker who comes after you exactly the code you keyed in。

  The PIN digits you punch into an ATM’s keypad are leaving traces ofthemselves behind in the form of heat, says a paper recently presentedby a team of UC San Diego security researchers. Someone followingimmediately behind an ATM user can use a digital infrared camera todetermine what keys were pushed with about 80 percent accuracy. Even afull minute later the camera can pick up the correct digits about halfthe time。

  But while it’s easy enough for a criminal type to determine thedigits in your pin with an IR camera, it’s fairly difficult to determinethe order. And the hack only seems to work on plastic keypads--metalreturns too much heat noise for the IR camera to reliably discern withkeys were just pressed。

  Then there’s the fact that an IR camera isn't exactly an implementof petty crime. By the time one amassed the princely sum (around $18,000to buy a good rig) necessary to acquire one, he or she probablywouldn’t need to steal ATM PINs anymore。

  But none of that changes the fact that a security scheme on whichmost people regularly rely has a fairly exploitable hole. And it doesn’tjust go for ATM machines--keypad safes, security doors, keypadactivated garage doors, even the keypads that open up some car doors aresusceptible to the IR hack, particularly where plastic keypads areinvolved。

  Of course, to thwart the scheme you could simply place your handover the entire keypad to impart heat to every key after you punch inyour PIN。

  据美国《大众科学》网站8月30日报道,你的手指在ATM机上留下的余温能让尾随你而来的黑客准确获知你的密码。

  加利福尼亚大学圣地亚哥分校的研究小组在近日发表的论文中指出,你在ATM机上键入的密码会以你手指余温的形式留下线索。紧随在你身后的ATM使用者用数码红外摄相机就可以确定你按了哪些键,准确率在80%左右。即使在一分钟之后,摄相机还会有50%的准确率。

  虽然罪犯能用红外摄相机测定你按了哪些键,不过要确定(按键的)顺序却非常困难。而且黑客似乎只能在塑料键盘上运用这个方法,因为金属会反射出大量的热量干扰波,从而使得红外摄相机无法准确识别。

  而且红外摄相机不是小偷小摸的人用得起的设备,如果他能攒够这笔巨款(一套像样的设备大约需要1.8万美元),应该也不需要去ATM机上盗窃了。

  但这并不能改变这个事实:大多数人所信赖的那个安全系统其实还存在着不小的漏洞。而且这不仅限于ATM机,保险箱、防盗门、需键盘启动的车库门、甚至用来打开车门的小键盘也易受到使用红外的黑客的影响,特别是当键盘是塑料质地时。

  当然,想要破坏这个阴谋,你就只需在键入密码后将整个手掌放在键盘上,这样分布在键盘上的热量就均匀了。