Discussion on:

43
Comments

Join the conversation!

Follow via:
RSS
Email Alert
0 Votes
+ -
clever
pgit 9th Oct
More scary news, another arrow to the heart of privacy.

As for "A real attacker would want to identify people with interesting environments worth snooping on, and only collect data from these interesting places to avoid being swamped in too much data." I suppose GPS would help, eg only enable sensing when within a specified radius.

Fascinating stuff.
That something can become that usable from random images is amazing.
0 Votes
+ -
me too
pgit 9th Oct
Definitely the most fascinating aspect. I wonder if there is any input from motion sensors/gyros or GPS in the algorithms that generate the 3D view... That would make it all the more amazing by a factor of ten.
0 Votes
+ -
Contributr
The paper goes into the details, but hang on. It's quite a ride, at least it was for me.
On the device side in paring down duplicitave / non useful images for the backend point cloud generation. Otherwise a user might notice they were infected by their bill for data transmission. happy

I didn't see any IMU type data in the paper and the tools they used for MISFM wouldn't be able to use it.
0 Votes
+ -
Contributr
What is IMU (inertia?) and MISFM?
0 Votes
+ -
Inertial Measurement Unit and Multiple Image Structure from Motion.

What these folks are doing is using your mobile device as an Xbox type kinect sensor, just not in real time. You get the same 3d point cloud data that can be explored with an appropriate viewer. When you see something interesting you can click on the point cloud and the relevant set of images are displayed (ala check number example.) That's what they mean by virtual theft and exploration. Its really a virtual environment.
0 Votes
+ -
Contributr
I can see the relationship. And, what the software accomplishes is impressive.
0 Votes
+ -
Finally the world is waking up.
I first demo;ed this type of attack on an IBM laptop in 1999, listening in on conversations in a global bank. Reception was crystal clear even beyond the dividers in the office. Usual precautions apply.
The ability to develop a 3D reconstruction is new, particularly when it does not require a monster super mainframe to create.
Per 1990s specifications when I was working in active vision. Just so happens we all have them on our desks or entertainment centers now! happy
0 Votes
+ -
Contributr
I just setup several CAD stations that are for solid-modeling videos. The video card had four times the memory of my notebook.
0 Votes
+ -
Pixel pipeline unit hooked up to a dedicated Sun box. As I recall it had a whopping 512 linear processing units. I just noticed that you can get Nvidia cards with three times the pixel units and about 1000 times the memory for $299 on newegg. happy
0 Votes
+ -
Contributr
The card in theCAD units has a huge fan as well and is noisy.
so that really is pretty easy to deal with. And I bet if proof of concept has been done, the black hats will have app waiting or being prepared to load on to your phone. Better cover the lens over.and be careful what you say because audio can give away much.
0 Votes
+ -
Contributr
I wonder if the phone OEM or provider changed the Android setting.
0 Votes
+ -
Wouldn't a cheap fix for this type of attack from the camera standpoint anyway be adding a lens cover on the camera at least for the back camera the front would be a little different.
0 Votes
+ -
Contributr
Or a physical switch, which I have heard mentioned by sources.
1 Vote
+ -
Simple Fix
edjcox 9th Oct
Place and opaque lens cover over your camera unitl needed....
0 Votes
+ -
Pro
And put chewing gum on the microphone every time when finish the call. And if you in US then every time unswerving you have say first - "this call may be recorded by anyone".
0 Votes
+ -
Contributr
But, you have to admit, it would be a pain and I know I'd lose it in a day.
Paper pointer! I guess I'm more optimistic that such pervasive sensor fusion might help mankind. Imagine if phones had temperature and pressure sensors and those could be fed into weather modeling systems. Or radiation sensors feeding into global mapping to determine environmental duress.
That is a good idea. I always prefer a positive take on things. But feel it's important to make everyone aware of what's out there.
...can be flushed with a piece of electrical tape (or a built-in, mechanical lens cover). How productive.
0 Votes
+ -
Contributr
True, Angelo
Michael Kassner Updated - 10th Oct
What if the research team didn't put forth the effort -- only the bad guys would know.
0 Votes
+ -
What If...
AngeloPC 12th Oct
What if the "research team" ARE the bad guys?
That's the weak link in any kind of security, it always reactive.
0 Votes
+ -
in terms of time and money? What is your definition of productive in an applied research situation? BTW if you read the paper you would see that a lot of what they used was OTS except for the Android client end parser.
Bruce Wayne did this int he Second batman movie. Life imitating art??
0 Votes
+ -
Contributr
What were the details?
...the crown jewels my cats leave in the litter box every day!

Sure, it is amazing stuff, and would make a great CSI-style effect in a movie or TV show, but who is going to do this to break into my house? For 98% of us, we should be more afraid of a crack-head breaking in than being the subject of this kind of spying. I got nothing worth this much cost or effort. Crimes of opportunity or crack-heads are a more realistic threat, and even then, mostly for the damage they would do looking for valuables that don't exist, (or tearing out the plumbing in the walls.)

(On a separate note, it takes a very special kind of person to do $30,000 worth of damage to a building to steal $50 worth of copper...)

(Edit: just noticed the Batman post above, That's why he's the friggin' Batman!)
1 Vote
+ -
Contributr
But, what if you left a check out or some sensitive private information. What is the cost of that? And, the real intent of the article was to increase awareness. I am glad you read the piece and now know about it. It allows you to make an informed decision.
Both for writing the article and for replying.
0 Votes
+ -
Contributr
Having people respond is the best part of it.
-1 Votes
+ -
Hello to all the ships at sea. Flash the government has figured out how to use WIFI as radar to see in see through buildings. So give it up they are going to get it anyway. For me I dont care it is after all my government and my country.
"it is after all my government and my country"

The same attitude has allowed every tyranny the world has ever known. You are the 80% who "have eyes but do not see, have ears but do not hear" Jesus spoke of.

"Government" is NOT "my country," the two do not equate, they are polar opposites. People are led by the nose from birth, through "public education" to equate "government" with "society." Governments traditionally seek to enslave, command and control societies to their own (government's) gains, and always most detrimental to the people, in the long run. Learn some history.
0 Votes
+ -
jesus
sarai1313@... 13th Oct
Led through my nose. I dont need to hear from some unintelligent ass . Trying to tell me a values are wrong. Do you have a home ,a job and freedoms that only you can get here in America. Then shut up. I have never broke the law,never done anything against my country and my government I have voted in to office. Drone I have served my country at time of war and peace. Served my community,and my church. . All I hear is some one crying that the government is bad it is out to take are freedoms away by spying on us. You know what kid you sound like all the others. Oh the government is out to get you crap. Dont like it change it. But dont sit in your mothers basement and think you know how the world thinks. I wont even tell you who I am ,were I am from,who I work for,or my credentials. I am one of the folks who do rebel against the machine. I have made changes In the way my government works and to be honest the only thing I like to change is the draft. So you folks who say my government is out to get you would be right . But then again you yes you would run to Canada. You want to reply go for it.
0 Votes
+ -
Contributr
I've been writing here for a long time now and enjoy it when members start a conversation that differs from the topic of the article.

My apologies, but I sense this divergence is not one that will end well. My favor is to respectfully ask each of you to agree to disagree and leave it at that.
0 Votes
+ -
OK
sarai1313@... 14th Oct
What ever. Oh by the way I was not the one who got off subject. I just will not let some one,any one slam my country with paranoid rants. Because the next thing you hear is that they are already doing things that are not happening. I come hear for tech not politics. If I did I would get back in game but would not bring it up here. Peace to all from a very old independent voter. So who ever you want just make sure you do go and vote. Arguing gets you no were. Vote .
0 Votes
+ -
Pro
What are practical applications of such technology, apart of spying ?
0 Votes
+ -
Contributr
The only references I have of practical does not refer to applications. Can you please help me, by point out where you taking the quote from.
"Stupid vision tricks". Or you need a hook to perk up interest in your paper for citation happy.

The real meat was in proving that you didn't need highly controlled rigs and calibration to snap images for the Surface from Motion software/algorithms they already had. That and that you could generate 3D point clouds from really lo-res image sets.

Practical applications would be in automation E.G. robot navigation and kinematics. The paper mentioned it was possible to do SFM on the phone, but it would have snapped up so many resources as to render the phone incapable of doing any other task.

ADDENDUM: The other practical application is using exisiting information which is overwhelming "lots 'O images" into an intuitive point-n-click interface. E.G. Big Data graphical frontend.
0 Votes
+ -
I think you're considering the 3-D modelling of the collected data as being too resource intensive for the phone, not the collection of the data. Collecting the actual data is a piece of cake. Take video of surrounding area, and add rough positional data. That is, if you even really need that positional data in the first place.

If you just want to spy on your target and get as much information as possible about things in the room and potentially theft-worthy information on their desks, you just need to take video without even bothering with positional data.

But then, once you've broken into your target's phone, you can also do things like find out the wireless password for the corporate network, and then snoop the network from afar (or even from the phone), collecting passwords, financial information, or any amount of other data that's being sent on the wireless connection.
Keyboard Shortcuts:
Prev
Next
Toggle
Join the conversation
Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

Join the TechRepublic Community and join the conversation! Signing-up is free and quick, Do it now, we want to hear your opinion.