Home That wearable might accidentally reveal your PIN number

That wearable might accidentally reveal your PIN number

Motion data that your wearable collects from accelerometers, gyroscopes, and magnetometers could be used to break into your bank account or any other keypad lock, according to a paper co-authored by the Stevens Institute of Technology and the Thomas J. Watson School of Engineering and Applied Science at Binghamton University.

Researchers were able to develop an algorithm that uses the motion data to create the exact pattern of a PIN or passcode with impressive accuracy. According to the paper, the algorithm guessed the PIN in one attempt 80 percent of the time, and that went up to 90 percent after three attempts.

See Also: Microsoft wearables pack cyclists’ suitcase of courage

That is worrying, though for ATM transactions and keycard doors you typically need the card as well as the passcode to gain access. That may be too many processes for most hackers.

Two ways you reveal your PIN

In the paper, Yan Wang, an assistant professor at Binghamton University, laid out two ways to steal the motion data stored on the wearable:

  • Infiltrate the wearable sensors using malware, possibly through a corrupt update sent via email.
  • Intercept data sent via Bluetooth from the wearable to the smartphone, using a wireless sniffer.

If someone goes through all of the steps (and then creates a forged card) to gain entry into a building or account, you are probably a valuable person.

There are plenty of security firms that build programs to defend valuable targets and plenty of hackers that attempt to circumvent these programs to offload a huge amount of money or information, so revealing this information is worthwhile to a small sub-section of wearable owners.

Even if hackers are incapable of pulling off an entire attack, we could see hackers use ransomware—one of the fastest growing cyber attacks—to snatch some money from wearable owners. If a hacker told you your PIN, I’m sure a few would comply instead of gambling on the hacker not stealing your savings.

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the tech industry for major developments, new product launches, AI breakthroughs, video game releases and other newsworthy events. Editors assign relevant stories to staff writers or freelance contributors with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Get the biggest tech headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Tech News

    Explore the latest in tech with our Tech News. We cut through the noise for concise, relevant updates, keeping you informed about the rapidly evolving tech landscape with curated content that separates signal from noise.

    In-Depth Tech Stories

    Explore tech impact in In-Depth Stories. Narrative data journalism offers comprehensive analyses, revealing stories behind data. Understand industry trends for a deeper perspective on tech's intricate relationships with society.

    Expert Reviews

    Empower decisions with Expert Reviews, merging industry expertise and insightful analysis. Delve into tech intricacies, get the best deals, and stay ahead with our trustworthy guide to navigating the ever-changing tech market.