The Register® — Biting the hand that feeds IT

Feeds

SHOCK: Brainwave readers work as advertised

Put away the tinfoil hat, there's no 'brain hack' here

  • print
  • alert

A little-reported (at first) bit of research presented at this month’s Usenix conference makes the startling claim that consumer-grade EEG-based interface devices – like Emotiv and NeuroSky headsets – could be used to gain private information from users.

The combination of sexy gadget and sci-fi attack was too much for the hipsters over at ExtremeTech, with the headline “Hackers backdoor the human brain”, and CrazyEngineers, which took an axe to language with “Hackers Unauthorizedly Access Human Brain”.

Actually, what the researchers demonstrate might be considered unremarkable when you deconstruct it:

1. A consumer peripheral doesn’t secure its communications with its host (other peripherals that use unsecured communications include your keyboard, mouse, and headphones).

2. These particular peripherals actually do what the package says they do.

OK, so what’s actually taken place? In this presentation, “On the Feasibility of Side-Channel Attacks with Brain-Computer Interfaces” the Usenix presenters put a set of cognitive tests in front of people wearing the headsets, and checked the responses recorded by the devices.

Hence, if a photograph of President Obama showed up among a set of random pics of people, the brain responded. The particular response, a spike in what’s called the P300 event-related potential, has been associated with what’s called a “guilty knowledge test” since the 1990s.

If a similar test is applied to credit cards, bank logos and birthdays, a strong P300 response would indicate that a user holds a Bank of America Visa card and has a September birthday – if a test can be contrived that can elicit this information without anybody catching on.

However: P300 responses are not only known to the two manufacturers, they’re part of what’s in the box. Emotive not only believes its device captures the P300 “brain-wave” (an imprecise term but good enough here), it helpfully publishes a 2011 test paper here, complete with instructions on how to repeat the experiment for yourself. Various other discussions about using both Emotiv and NeuroSky to detect P300 waves exist at the OpenVibe brain-computer interface forum.

It’s a nice enough piece of work from the Usenix presenters, but a malicious cracker would get further, faster, with a keylogger. Or a skimmer on a credit card machine. ®

I can't wait until I can go to my GP and get an annual injection of Norton Internet Security for Human Brains! That'll be fun - especially the chronic upgrade reminder cluster headaches ten month's later!

6
0

How was your day, Visa, MasterCard, Amex, Coffee?

Tying to get into your mind, second guessing your thoughts, inner response to females, recording it all in a permanent database for later use.

But less about the wife, this looks quite cool.

3
0

It's not worth it!

You'll start crashing and running very slowly.

2
0
Anonymous Coward

Don't even think about ....

.... sending that nice Nigerian businessman some money!

2
0

Re: Good luck

" I wish them every success in generating the 12 digit card number"

<cough> 16 digits...

I'll get my coat..

1
0

More from The Register

Is the next-gen console war already One?
Microsoft’s new Xbox - and more
 breaking news
Apple cored: Samsung sells 10 million Galaxy S4 in a month
Beware of South Koreans bearing Android
US boffin builds 32-way Raspberry Pi cluster
Beowulf cluster built for the price of a single PC
STROKE this mouse to make apps POP, says Microsoft
Windows 8 Start button comes to Redmond's rodents
Nintendo throws flaming legal barrel at YouTubing fans
All your walk-through vid revenue are belong to us
Fairphone goes on sale to all
The Android handset that's PC can be yours
Microsoft reveals Xbox One, the console that can read your heartbeat
Upgrades Live service – and no always-on requirement

Hands on with Hyper-V 3.0 and virtual machine movement

Our award-winning Regcasts have teamed up with training provider QA for the deepest of deep dives into Hyper-V, including a live demo.

Understand VM movement - just click to play, or go here for a bigger version.