Hackers can steal PINs, passwords from your brainwaves: study

July 1, 2017

Washington, Jul 1: Hackers can guess a user's passwords by monitoring their thoughts, according to scientists including those of Indian origin who suggest that brainwave-sensing headsets need better security.brain

Electroencephalograph (EEG) headsets allow users to control robotic toys and video games with the mind.

Researchers at the University of Alabama at Birmingham in the US found that a person who paused a video game and logged into a bank account while wearing an EEG headset was at risk for having their passwords or other sensitive data stolen by a malicious software programme.

"These emerging devices open immense opportunities for everyday users," said Nitesh Saxena, associate professor from University of Alabama. "However, they could also raise significant security and privacy threats as companies work to develop even more advanced brain-computer interface technology," said Saxena.

The team, including PhD student Ajaya Neupane, used one EEG headset currently available to consumers online and one clinical-grade headset used for scientific research to demonstrate how easily a malicious software programme could passively eavesdrop on a user's brainwaves.

While typing, a user's inputs correspond with their visual processing, as well as hand, eye and head muscle movements. All these movements are captured by EEG headsets.

The team asked 12 people to type a series of randomly generated PINs and passwords into a text box as if they were logging into an online account while wearing an EEG headset, in order for the software to train itself on the user's typing and the corresponding brainwave.

"In a real-world attack, a hacker could facilitate the training step required for the malicious program to be most accurate, by requesting that the user enter a predefined set of numbers in order to restart the game after pausing it to take a break, similar to the way CAPTCHA is used to verify users when logging onto websites," Saxena said.

The team found that, after a user entered 200 characters, algorithms within the malicious software programme could make educated guesses about new characters the user entered by monitoring the EEG data recorded.

The algorithm was able to shorten the odds of a hacker's guessing a four-digit numerical PIN from one in 10,000 to one in 20 and increased the chance of guessing a six-letter password from about 500,000 to roughly one in 500.

"Given the growing popularity of EEG headsets and the variety of ways in which they could be used, it is inevitable that they will become part of our daily lives, including while using other devices," Saxena said.

"It is important to analyse the potential security and privacy risks associated with this emerging technology to raise users' awareness of the risks and develop viable solutions to malicious attacks," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
February 26,2020

New Delhi, Feb 26: With the government pushing for the disinvestment of Air India, industrial conglomerate Adani Group may emerge as one of the bidders for the debt-laden national carrier, sources said.

According to highly placed sources, the Group has held internal rounds of deliberations on whether or not to submit an Expression of Interest (EoI) and the discussions are still in the preliminary stage.

If the company actually submits an EoI, it would be a major move towards further diversification of the company which has business interests across sectors right from edible oil, food to mining and minerals. 

It also entered into airport operations and maintenance business and won bids for privatisation of six airports, Ahmedabad, Lucknow, Jaipur, Guwahati, Thiruvananthapuram and Mangaluru in 2019. 

On being contacted by IANS, the company did not comment on the matter.

Air India is one of the most important divestment proposals for the current fiscal to reach the huge Rs 2.1 lakh crore target.

The government in January restarted the divestment process of the airline and invited bids for selling 100 per cent of its equity in the state-owned airline, including Air India's 100 per cent shareholding in AI Express Ltd. and 50 per cent in Air India SATS Airport Services Private Ltd.

After its unsuccessful bid to sell Air India in 2018, the government this time has decided to offload its entire stake. In 2018, it had offered to sell its 76 per cent stake in the airline.

Of the total debt of Rs 60,074 crore as of March 31, 2019, the buyer would be required to absorb Rs 23,286 crore.

Air India, along with its subsidiary Air India Express, has a total operational fleet of 146 aeroplanes.

Further, the disinvestment department has extended the last date for submission of written queries on the Performance Information Memorandum and Share Purchase Agreement to March 6.

The last date for submission of written queries on PIM and SPA was originally set for February 11, following which the Department of Investment and Public Asset Management (DIPAM) on February 21 issued 20 clarifications on the queries raised and expected.

Any delay in the tentatively rolled out timeline would also delay DIPAM's plan to identify the pre-qualified bidders by March 31 and the financial bids invitation as well. It is expected to take more than two months after the selection of the pre-qualified bidders to complete Air India's sale.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 13,2020

New Delhi, Jul 13: The Income Tax Department has facilitated a new functionality for banks and post offices to ascertain TDS applicability rates on cash withdrawal of above Rs 20 lakh in case of a non-filer of the income-tax return and that of above Rs 1 crore in case of a filer of the income-tax return.

In a statement, the Central Board of Direct Taxes (CBDT) said that now banks and post offices have to only enter the PAN of the person who is withdrawing cash for ascertaining the applicable rate of TDS.

So far, more than 53,000 verification requests have been executed successfully on this facility, a statement by the CBDT said.

"CBDT today said that this functionality available as 'Verification of applicability u/s 194N' on www.incometaxindiaefiling.gov.in since 1st July 2020, is also made available to the Banks through web-services so that the entire process can be automated and be linked to the Bank's internal core banking solution," it said.

On entering PAN by the bank or the post office, a message will be instantly displayed on the departmental utility: "TDS is deductible at the rate of 2 per cent if cash withdrawal exceeds Rs 1 crore", in case the person withdrawing cash is a filer of the income-tax return.

In case the person withdrawing cash is a non-filer of income tax return, the message shown would be: "TDS is deductible at the rate of 2 per cent if cash withdrawal exceeds Rs 20 lakh and at the rate of 5 per cent if it exceeds Rs 1 crore."

The CBDT said that the data on cash withdrawal indicated that huge amount of cash is withdrawn by the persons who have never filed income-tax returns.

To ensure filing of return by these persons and to keep track on cash withdrawals by the non-filers, and to curb black money, the Finance Act, 2020 with effect from July 1, 2020 further amended IT Act to lower threshold of cash withdrawal to Rs 20 lakh for the applicability of this TDS for the non-filers and also mandated TDS at the higher rate of 5 per cent on cash withdrawal exceeding Rs 1 crore by the non-filers.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
July 28,2020

Bengaluru, Jul 28: Congress leader Siddaramaiah on Monday alleged that BJP is trying to destabilise the Congress government in Rajasthan.

"It is the duty of the Governor to act according to the decision of the state cabinet. But he is acting like a central government puppet," he said at a protest organised here by Karnataka Pradesh Congress Committee (KPCC).

He said the Congress is protesting across the country to save democracy and save the constitution.

"We are not fighting through violence. We are protesting peacefully. The Constitution has given the right to protest in a democratic system," he said.

He accused the BJP of "being disrespectful" to the Constitution.

"Governments must walk within the framework of the Constitution. The Constitution gives everyone rights and duties. BJP destabilises elected governments and buys our legislators by horse-trading by spending crores of money. The same thing happened in Karnataka as well," he alleged.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.