Author Topic: "Mic-E-Mouse" attack demonstrated - optical mice used to eavesdrop audio  (Read 1363 times)

0 Members and 1 Guest are viewing this topic.

Offline NE666Topic starter

  • Frequent Contributor
  • **
  • Posts: 895
  • Country: gb
"Researchers show how high DPI gaming mice can capture desk vibrations and reconstruct speech with neural networks."

Time to go through the attic for your old foam mouse mats and ball mice..

 
The following users thanked this post: golden_labels

Offline golden_labels

  • Super Contributor
  • ***
  • Posts: 2454
  • Country: pl
Re: "Mic-E-Mouse" attack demonstrated - optical mice used to eavesdrop audio
« Reply #1 on: October 12, 2025, 03:01:47 pm »
Evidence some people can be trivially replaced by algorithms. :D We see a biological text-to-speech device, that finally summarizes the video with LLM style nonsense: “they already worked out how to do this and how to attack computers by running open source software, in example, and extracting speech from your mouse.”



The preprint on ArXiv: “Invisible Ears at Your Fingertips: Optical Eavesdropping via Mouse Sensors” by Fakih, Dharmaji, Mahmoud, Bouzidi, Al Faruque

I find the setup beautiful. Regardless of its applicability outside lab, they just did a great job and created something bringing smile to my face. 👏

They also did great job correctly identifying the threat model and prominently exposing it.


I’m bit less concerned about the practical applications at this point. This class of attacks isn’t new and all its members generally share the same ailment. Most fail to bridge the gap between the controlled environment of a laboratory and the real world. These which don’t fail often offer poor performance on the edge of usefulness. A mouse placed over a loudspeaker reproducing clear words is one thing. A mouse placed on a desk, with somebody chatting in the background is a very different story.

This is not to say the risk isn’t there. In particular in the threat model the authors pointed to: even 0.01% true positive is bad news in this scenario. But it seems like news are once again going crazy over a dud.

Here’s the original demonstration video:
Why 📎 | We live in times when half of people have IQ below 100.
 

Offline SiliconWizard

  • Super Contributor
  • ***
  • Posts: 17793
  • Country: fr
Re: "Mic-E-Mouse" attack demonstrated - optical mice used to eavesdrop audio
« Reply #2 on: October 12, 2025, 04:04:02 pm »
Yes, I see zero practical application of this due to the conditions necessary to make it work.

It's all the more a nothing burger that people now have countless devices around them containing proper microphones that can very, very easily be used to spy on them with minimal resources.
 
The following users thanked this post: Stray Electron

Offline Bud

  • Super Contributor
  • ***
  • Posts: 7928
  • Country: ca
Re: "Mic-E-Mouse" attack demonstrated - optical mice used to eavesdrop audio
« Reply #3 on: October 12, 2025, 04:05:22 pm »
Still can be useful, like detecting people presense in the room, how many, men/women, temper of conversations.
Facebook-free life and Rigol-free shack.
 

Offline golden_labels

  • Super Contributor
  • ***
  • Posts: 2454
  • Country: pl
Re: "Mic-E-Mouse" attack demonstrated - optical mice used to eavesdrop audio
« Reply #4 on: October 12, 2025, 05:36:46 pm »
What I tried to underline towards the end. Low ≠ zero, and not reliable ≠ not viable.

News sites seem to peddle this as another serious vulnerability. The kind making NSA know mom is angry one didn’t wash socks for a week. This attack scenario is indeed nonsensical at this point. Even if occasionally possible in the wild, it’s too unreliable. This applies to this entire class of attacks.

This doesn’t discredit the authors in any way. During wars, both in proper military warfare and in Cold War, even less reliable methods were deployed and countermeasures against them designed. Because at some point even 1 in 1000 attempts may be a gold nugget. Equally, making a thousand attempts on a high-value target is not a problem in politics and business. Remember you need just one incriminating recording to destroy opponent in a presidental race or blackmail competition in the board.

Most importantly, the authors did correctly outline the threat model. The assumption is: the machines are already compromised, the data exfiltrated and already collected in large quantities. Now, 0.01% may seem tiny until you multiply this by a billion data instances. It’s still not the same level as a reliable RCE, which is a threat from both individual and population perspectives, but it’s also not nothing.
Why 📎 | We live in times when half of people have IQ below 100.
 

Offline ejeffrey

  • Super Contributor
  • ***
  • Posts: 4841
  • Country: us
Re: "Mic-E-Mouse" attack demonstrated - optical mice used to eavesdrop audio
« Reply #5 on: October 12, 2025, 07:16:50 pm »
Yes, I see zero practical application of this due to the conditions necessary to make it work.

The main thing seems to be that browsers limit JavaScript access to the mouse data to 60-144 Hz or less which isn't enough for their attack.  If that wasn't the case this would be a 10/10 hair on fire emergency vulnerability.

As is it's mostly a curiosity.  Any software that can implement this probably already has access to a real microphone. 

It's still good to demonstrate because otherwise there is no telling when browsers would add a new "gaming" API with high frequency mouse access.
 

Offline 5U4GB

  • Super Contributor
  • ***
  • Posts: 1739
  • Country: au
Re: "Mic-E-Mouse" attack demonstrated - optical mice used to eavesdrop audio
« Reply #6 on: October 13, 2025, 08:39:50 am »
News sites seem to peddle this as another serious vulnerability. The kind making NSA know mom is angry one didn’t wash socks for a week. This attack scenario is indeed nonsensical at this point. Even if occasionally possible in the wild, it’s too unreliable. This applies to this entire class of attacks.

It's a very nice technical stunt, but like 90+% of all attacks that make it to conference papers and then media headlines it's a stunt attack, nice piece of work with zero chance of practical use.

OTOH the ones with 100% chance of practical use, things like XSS and SQLI and so on, never make it because they're not newsworthy.  Leading to an interesting hypothesis, if a technical attack makes it to a conference paper you'll never have to worry about it in practice unless you're the sort of person who worries about Mossad doing Mossad things to you.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->