Skip to main content

Scientists just proved your phone’s PIN can be cracked using its gyroscope data

It’s no secret that smartphone PIN codes are not perfect, but new research suggests they might be next to worthless. A team of scientists at Newcastle University in the U.K. was able to guess a user’s phone PIN code with nothing more than data from the device’s sensors.

In a paper published in International Journal of Information security, researchers demonstrated how a phone’s gyroscope — the sensor that tracks the rotation and orientation of your wrist — could be used to guess a four-digit PIN code with a high degree of accuracy. In one test, the team cracked a passcode with 70 percent accuracy. By the fifth attempt, the accuracy had gone up to 100 percent.

Recommended Videos

It takes a lot of data, to be sure. The Guardian notes users had to type 50 known PINs five times before the researchers’ algorithm learned how they held a phone when typing each particular number. But it highlights the danger of malicious apps that gain access to a device’s sensors without requesting permission.

“Most smartphones, tablets, and other wearables are now equipped with a multitude of sensors,” Dr. Maryam Mehrnezhad, a research fellow in the Newcastle University School of Computing Science and lead author on the paper, said. “But because mobile apps and websites don’t need to ask permission to access most of them, malicious programs can covertly ‘listen in’ on your sensor data.”

The risk extends beyond PIN codes. In total, the team identified 25 different smartphone sensors which could expose compromising user information. Worse still, only a small number — such as the camera and GPS — ask the user’s permission before granting access to that data.

It’s precise enough to track behavior. Using an “orientation” and “motion trace” data, the researchers were able to determine what part of a web page a user was clicking on and what they were typing.

“It’s a bit like doing a jigsaw — the more pieces you put together, the easier it is to see the picture,” Dr. Siamak Shahandashti, a senior research associate in the School of Computing Science and co-author on the study, said.

Mehrenzhad said the team reached out to leading browser providers to alert them of the issue and that Mozilla and Safari have implemented fixes. But she said that researchers are still working with the industry to find a better fix.

“We all clamor for the latest phone with the latest features and better user experience but because there is no uniform way of managing sensors across the industry, they pose a real threat to our personal security,” Mehrenzhad said. “It’s a battle between usability and security.”

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Cost-cutting strips Pixel 9a of the best Gemini AI features in Pixel 9
Person holds Pixel 9a in hand while sitting in a car.

The Pixel 9a has been officially revealed, and while it's an eye candy, there are some visible cutbacks over the more premium Pixel 9 and 9 Pro series phones. The other cutbacks we don't see include lower RAM than the Pixel 9 phones, which can limit the new mid-ranger's ability to run AI applications, despite running the same Tensor G4 chipset.

Google's decision to limit the RAM to 8GB, compared to the 12GB on the more premium Pixel 9 phones, sacrifices its ability to run certain AI tasks locally. ArsTechnica has reported that as a result of the cost-cutting, Pixel 9a runs an "extra extra small" or XXS variant -- instead of the "extra small" variant on Pixel 9 -- of the Gemini Nano 1.0 model that drives on-device AI functions.

Read more
Does the Google Pixel 9a come with a charger? Here’s what’s in the box
A woman holding a purple Google Pixel 9a.

After much speculation in recent months, the Google Pixel 9a has finally been announced. Google's Pixel A series is an excellent choice for those seeking a reliable Android smartphone at a lower price point, and the latest model follows this trend. While it is undeniably part of the Google Pixel 9 series, it has fewer features than its higher-end counterparts.

One question you might have when considering the Pixel 9a is whether it comes with a charger. We’ve got the answer
The Pixel 9a does not come with a charger.
The short answer is that the Pixel 9a does not have a charger. This has become common practice for most smartphones today, including other models in the Pixel 9 series, like the Pixel 9 Pro. While this may be disappointing, it's not surprising.

Read more
Google Pixel 9a vs. Pixel 8a: should you upgrade?
Google Pixel 9a vs Pixel 8a.

Google has released a new budget phone, the Pixel 9a. How does it compare to its predecessor, the Pixel 8a? We've got the answers, and the changes are significant in some ways. In others, not so much. If you have a Pixel 8a and are considering upgrading, read this first.
Google Pixel 9a: vs. Google Pixel 8a: specs

Google Pixel 9a
Google Pixel 8a

Read more