Your passwords could be cracked using thermal cameras powered by AI

Thermal imaging
(Image credit: Pixabay)

Thermal cameras, with the help of AI, can be used to detect the keys you press when inputting your password on a keyboard.

A team at the University of Glasgow looked at how AI, rather than mere visual inspection, can be used successfully in processing thermal images that pick out traces of heat left on the keycaps of keyboards when passwords were entered.

The researchers demonstrated the effectiveness of the system, known as ThermoSecure, using 1,500 images of keyboards with heat traces leftover from typing. 

ThermoSecure

In their first study, the researchers claim that "ThermoSecure successfully attacks 6-symbol, 8-symbol, 12-symbol, and 16-symbol passwords with an average accuracy of 92%, 80%, 71%, and 55% respectively, and even higher accuracy when thermal images are taken within 30 seconds."

They also said that "typing behavior significantly impacts vulnerability to thermal attacks: hunt-and-peck typists are more vulnerable than fast typists (92% vs. 83% thermal attack success)."

The second study also revealed that the material the keys are made of had a significant impact on the success of thermal attacks. A common material used, the copolymer plastic Acrylonitrile Butadiene Styrene (ABS), resulted in longer lasting heat traces from presses than those on PBT keys. This meant that attacks on ABS keycaps had an average accuracy of 52%, while those on PBT keycaps had only 14%.

When it comes to the equipment used, only a basic thermal camera is needed - the researchers noted that models costing only around $150 suffice. The AI software works via object detection based on Mask RCNN, which maps the thermal image to the keyboard keys. Variables such as keyboard localization are taken into account, before key entry and multi-press detection is factored in, and an algorithm determines the order of the key presses.

Although it is unlikely you'll have a thermal camera trained on your device in the real world, there are a few steps you can take to secure yourself against such attacks. Firstly, as previously indicated, hunt-and-peck typists are at greater risk, so using longer passwords and typing faster where possible may help.

Also, backlit keyboards can emit more heat, which actually helps to mask the heat signatures from pressed keys. And even if you use the most secure passwords created by a password generator, along with the best password manager possible, biometric and other passwordless options will always be better as there are no significant key presses at all from a thermal attack perspective.

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
Person using finger print authentication
Passwords out, passkeys in: The future of secure authentication
Optical system for data encryption
Is it quantum-resistant? Researchers create 'uncrackable' encryption system by pairing AI and holograms produced by laser
Hands typing on a keyboard surrounded by security icons
The psychology of scams: how cybercriminals are exploiting the human brain
Concept art representing cybersecurity principles
Cybercriminals cashing in on holiday sales rush
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras