Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Hackers could reconstruct your typing by listening to your keystrokes over Skype

Add as a preferred source on Google

Chances are that if you have been on a teleconference call at some point, you will have had the distracting experience of hearing another member of the party typing loudly without muting their microphone.

Such a scenario can be annoying, but did you know it could also make the typist vulnerable to electronic eavesdropping? That is the worrying conclusion reached by researchers at the University of California, Irvine and in Italy.

Recommended Videos

“Around 16 months ago, I was on a Skype conference call with some colleagues,” Gene Tsudik, Chancellor’s Professor of computer science at UCI, told Digital Trends. “In the background, you could hear someone typing away. Eventually it got to the point where I said, ‘Whoever is doing that needs to stop it, because it’s causing all kinds of interference.’”

As Tsudik spoke, however, he immediately had another thought: ‘I wonder if I could work out what that person is writing?’

“There’s been prior research showing that if you place a microphone directly next to someone’s keyboard to record the sound of the keystrokes, you can distinguish the different keystrokes, and reconstruct what someone is typing,” he continued. “Since I was hearing the typing sounds loud and clear over Skype, I thought it may be possible to do the same thing in that setting.”

Using some smart machine learning tools, the resulting study discovered that if attackers have some advance knowledge — such as information about the keyboard a person is using — they can establish which key is being pressed at any time with an accuracy of 91.7 percent.

Even if they have no information about a person’s typing style or keyboard, there is still a 41.89 percent chance of identifying which keys are being pressed — partially due to to the fact that English has a well-known frequency distribution of letters.

The fact that services like Skype are encrypted, and therefore it is virtually impossible for unwanted outsiders to gain access to a call, means potential attacks like this are unlikely to be widespread. But as Tsudik pointed out, there are scenarios in which it could.

“Sometimes you’re talking to a party you don’t necessarily trust completely,” he said. “That might be politicians or commercial rivals having a teleconference, for example. In that scenario, there’s not always mutual trust. Whenever that’s the case, the other party could potentially be an adversary, and use technology like this to determine what other people on the call are typing.”

Whether it is passwords or confidential notes, the message is loud and clear: if you’re not 100 percent certain about the trustworthiness of the person you are communicating with, do not Skype and type!

Luke Dormehl
I'm a UK-based tech writer covering Cool Tech at Digital Trends. I've also written for Fast Company, Wired, the Guardian…
Substack now lets you check if a post was written by AI
A new Pangram-powered scanner lets you check posts, notes, and replies for signs of AI writing.
Video playing on Substack.

Substack is giving readers a way to check whether the post they're reading was written by a human or by a chatbot. The company has partnered with AI-detection firm Pangram to introduce new tools that will let users scan posts, notes, and replies for AI-generated text. CEO Chris Best introduced the features in a post titled "Against Claudefishing," his term for content that leans on AI while presenting itself as human work.

How the scanning tool works

Read more
China’s AI talent shortage has tech giants recruiting teenagers
Forget campus recruiting, china's biggest tech firms are betting on teenage coders.
Artificial Intelligence

A 13-year-old boy in Hangzhou has already won national AI competitions and built a following of more than 136,000 people online, all while his dad tries to figure out how to guide him through a field that barely existed when he himself was growing up. That family's situation, first reported by Rest of World, says a lot about where China's tech industry is heading right now.

Companies used to wait for graduates to walk through the door. Now they're reaching further back, first to undergrads, and increasingly to teenagers, hoping to spot rare talent before anyone else gets to them.

Read more
OpenAI says AI models autonomously pulled off a major hack, but only a Chinese AI helped recovery
OpenAI

OpenAI’s latest cybersecurity test produced a result that sounds like a cautionary sci-fi script. Its AI models managed to escape their sandbox and reached the open internet. This is where things took a scary turn as it began hacking Hugging Face to steal the answers to the test they were taking.

The company says GPT-5.6 Sol and a more capable unreleased model autonomously chained together vulnerabilities across OpenAI’s research systems and Hugging Face’s production infrastructure. OpenAI has described the event as an unprecedented cyber incident.

Read more