
Security researchers at Cambridge University have been cracking cell phone passwords using the phone's microphone and camera.
Ross Anderson and Laurent Simon at the university used an application named "PIN Skimmer" to capture passwords on the Samsung Galaxy S3 and Google Nexus S.
The app can tell when you tap keys simply by "listening" to the click through the phone's microphone. It correlates this with your face via the camera. It then analyzes the changes in the phone's orientation from one tap to the next. In this way, the app can easily tell which area of the screen you are touching and which numbers you are pressing.
This type of attack is called a "side-channel attack," meaning it exploits the phone's physical properties. Previous studies used the gyroscope and accelerometer to collect PINs. However, this is the first app to work with the microphone and camera. When they tested the app on a group of 50 four-digit passwords, the researchers found that it accurately inferred 30% of the PINs after just two attempts.
To protect yourself from the PIN Skimmer app, the researchers recommend choosing a longer PIN. Hope this helps.