{"id":16037,"date":"2012-10-03T09:39:03","date_gmt":"2012-10-03T08:39:03","guid":{"rendered":"http:\/\/rinf.com\/alt-news\/?p=16037"},"modified":"2012-10-03T09:55:04","modified_gmt":"2012-10-03T08:55:04","slug":"smartphones-can-secretly-create-3d-maps-of-your-home","status":"publish","type":"post","link":"http:\/\/rinf.com\/alt-news\/sicence-technology\/smartphones-can-secretly-create-3d-maps-of-your-home\/","title":{"rendered":"Smartphones can secretly create 3D map of your home"},"content":{"rendered":"<p><a href=\"http:\/\/nakedsecurity.sophos.com\/2012\/10\/02\/proof-of-concept-android-malware-creates-3d-maps-of-your-home\/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29\" target=\"_blank\">Paul Roberts<\/a>\u00a0|<\/p>\n<p>Researchers say that they have\u00a0<a title=\"New Android Malware Is A Burglar's Best Friend\" href=\"http:\/\/www.fastcompany.com\/3001699\/new-android-malware-burglars-best-friend\" rel=\"nofollow\">created a malicious Android application\u00a0<\/a>that uses the phone\u2019s embedded camera and other spatial sensors to create 3D visual maps of the owner\u2019s home and other spaces.<\/p>\n<p>The proof of concept malware, dubbed PlaceRaider, was designed by researchers working for the U.S. Navy and the University of Indiana.<\/p>\n<p>Running on Android mobile devices, it was designed to call attention to the ways that rapidly evolving mobile platforms might enable new forms of virtual theft.<\/p>\n<p>Writing in a\u00a0<a title=\"PlaceRaider: Virtual Theft in Physical Spaces with Smartphones\" href=\"http:\/\/arxiv.org\/pdf\/1209.5982v1.pdf\" rel=\"nofollow\">paper (pdf) published Thursday<\/a>, the researchers said more powerful phones have created an opening for what they dub \u201csensory malware\u201d that leverages the growing number of on-board sensors in the latest model mobile phones like the iPhone 5 and Android devices.<\/p>\n<p>To prove their point, the researchers created PlaceRaider to demonstrate how remote hackers could construct \u201crich three-dimensional (3D) models of the smartphone\u2019s owner\u2019s personal indoor spaces\u201d.<\/p>\n<p>The malware uses a phone\u2019s embedded sensors such as its GPS and accelerometer to determine when the victim was moving within the space. The onboard camera was then used to opportunistically snap shots of interior spaces and transfer them to a remote server which then assembles them to form a 3D model of the space.<\/p>\n<p>Androids were particularly well-suited for the task. The authors noted, with surprise, that the Android API doesn\u2019t require any special permissions for an application to access sensor data on the phone, such as the accelerometer or gyroscope.<\/p>\n<p>And users could easily be tricked into granting those permissions that were needed \u2014 such as to access the camera or write to local storage \u2014 by bundling PlaceRaider into a camera app, the authors said.<\/p>\n<p>In a test, the researchers installed PlaceRaider on a subject\u2019s phone and tracked their movements and the spaces they occupied.<\/p>\n<p>Researchers tested the ability of the application to export large quantities of data, and of the test subjects to then use that data to snoop on occupants: zooming in to observe the content of information displayed on computer screens or papers in the target\u2019s home or workplace, according to the research report.<\/p>\n<p>PlaceRaider and other malicious \u201csensory\u201d applications like it are well within the capabilities of modern phones and modern malware authors.<\/p>\n<p>However, they did have to clear some technical hurdles in implementing it. Heuristic sensors were needed to weed out junk photos that didn\u2019t reveal any new information about a space and the volume of data collected by the malware is large enough that it could overwhelm a phone. That required the authors to create a way for PlaceRaider to automatically compress the data it was transmitting.<\/p>\n<p>In addition to the malware, the authors also created tools to exploit the data the application collects. For example: they built a tool that would allow attackers to visually navigate a victim\u2019s 3D space and zoom in on areas that might contain sensitive information. The phone could then be instructed to retrieve new, high resolution images of those spaces.<\/p>\n<p>The authors recommend a number of changes to smartphones to make malware like PlaceRaider harder to implement.<\/p>\n<p>Android and iOS devices could require permissions to access sensor data, and could alert users when applications appear to be using sensors \u2014 including the camera \u2014 in surreptitious ways.<\/p>\n<p>Even small changes would have made it harder for PlaceRaider to achieve its goals. For example: phone makers might require physical interaction with the phone to operate the camera, or make it impossible to take a photo without the shutter sound.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Paul Roberts\u00a0| Researchers say that they have\u00a0created a malicious Android application\u00a0that uses the phone\u2019s embedded camera and other spatial sensors to create 3D visual maps of the owner\u2019s home and other spaces. The proof of concept malware, dubbed PlaceRaider, was designed by researchers working for the U.S. Navy and the University of Indiana. Running on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,18],"tags":[],"class_list":{"0":"post-16037","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-sicence-technology","7":"category-latest-news"},"_links":{"self":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/16037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/comments?post=16037"}],"version-history":[{"count":0,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/16037\/revisions"}],"wp:attachment":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media?parent=16037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/categories?post=16037"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/tags?post=16037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}