this post was submitted on 12 Sep 2024
85 points (96.7% liked)

Cybersecurity

5686 readers
48 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
 

The Vision Pro uses 3D avatars on calls and for streaming. These researchers used eye tracking to work out the passwords and PINs people typed with their avatars.

Archived version: https://web.archive.org/web/20240912100207/https://www.wired.com/story/apple-vision-pro-persona-eye-tracking-spy-typing/

top 11 comments
sorted by: hot top controversial new old
[–] [email protected] 22 points 2 months ago (2 children)

That should be an easy fix in a future software update by simply not replicating eye movement as soon as the user is looking at the keyboard.

[–] Plopp 25 points 2 months ago (1 children)

The solution is constant googly eyes.

[–] [email protected] 15 points 2 months ago (1 children)

Let's be honest: the solution is always googly eyes.

[–] GamingChairModel 6 points 2 months ago (1 children)

Sounds like what they already did: as soon as the virtual keyboard pops up the eye movement isn't transmitted as part of the avatar.

[–] [email protected] 5 points 2 months ago

Oh I see. According to the article:

The GAZEpolit researchers reported their findings to Apple in April and subsequently sent the company their proof-of-concept code so the attack could be replicated. Apple fixed the flaw in a Vision Pro software update at the end of July, which stops the sharing of a Persona if someone is using the virtual keyboard.

An Apple spokesperson confirmed the company fixed the vulnerability, saying it was addressed in VisionOS 1.3.

[–] [email protected] 5 points 2 months ago

Seems like we're going to be stuck in the uncanny valley of telepresence. The more fidelity we add, the more we're able to pick up on microexpressions, subtle eye movements, and breathing, which helps trigger oxytocin and promote trust. But also, the more fidelity we add, the more attack surface we open up for malicious actors to exploit.

[–] [email protected] 3 points 2 months ago
[–] [email protected] 2 points 2 months ago

bet same for video calls.

[–] [email protected] 1 points 2 months ago (1 children)

Sounds like you could do this to a person in a normal zoom call with no headset.

[–] GamingChairModel 4 points 2 months ago

Most people don't look while typing, especially things with muscle memory like passwords, when using a physical keyboard. And a zoom call doesn't convey facial data in three dimensions. The unique nature of the virtual keyboard, plus the three dimensional avatar, makes this new attack more feasible.