5 ms·
This is amazing, I don't think I would have ever thought of that. Of course, it's efficacy is a bit mitigated in that if you could manage to get malware onto su
by jds375 11y ago
This is amazing, I don't think I would have ever thought of that. Of course, it's efficacy is a bit mitigated in that if you could manage to get malware onto such a computer, then there are likely easier ways to exfiltrate the data than presented in this paper. The POC model is nonetheless impressive.
This would be a great side project to play around with on an Arduino or something.
- nine_k 11y agoI wonder what easier ways to exfiltrate data do you see? An air-gapped computer is likely devoid of any special radio-frequency hardware (no wi-fi or BT). Acoustic signals (via speaker or mechanical moving parts) and visible light signals (via the screen or various LEDs) are easy to notice. OTOH a GSM frequency signal is not readily visible and also does not look like coming from a computer unless you look pretty hard; a signal at this frequency can be coming from a mobile device of a passer-by across the street.
- jds375 11y agoI mean something simple, such as just using the usb itself or through social engineering to take data. If you can manage to load malware onto the computer, you can probably steal the data in a much easier way. It's also much more efficient given the communication rate in the article is on the order of just bits/s. Of course, if you're looking for a steady stream of data over time, then this is probably the optimal solution.
- a3n 11y agoThe supply chain for the computer and the phones of nearby personnel is hackable, given a sufficiently resourced and un-savory-agency. Which gives you a nice datastream that didn't depend on anyone having done anything obviously stupid, and doesn't depend on social engineering to get usb sticks out of the facility.
- peterfirefly 11y agoAre they? If you can switch the LED fast enough (so the keyboard LEDs are out) and you keep the dark periods brief enough you should be able to hide it quite well. If you modulate it right you might be able to pick the data out of the reflections on walls, whiteboards, etc, perhaps even from outside a window.
- nickpsecurity 11y agoMy design many years ago was for "shielded" cables that would stop EM leaks in testing except for frequencies they wouldn't be looking for and especially upon receipt of a signal. Sent it to a bunch of people including in defense to create awareness of the risk. Last forum I posted it on was Schneier's blog during a discussion on hardware subversion. TAO leaked later to reveal RAGEMASTER, a VGA cable modification for leaking monitor signals to emanation attack gear. Independent invention or thieving bastards? (shrugs) Interesting, though, to see they came up with same solution. Just like old keyboard and pin pad attacks. The user has to enter it (input) or see it (monitor). There are many ways to stop outsiders from getting into that information. So, my idea (and NSA's as well) was to make that raw data come to us in whatever way possible. Simpler methods were available such as cheap bugs at 10Ghz that amateur spectrum tools wouldn't see. However, I found natural emanations to be best risk because (a) they're always there, (b) they often increase for non-suspect reasons, and (c) nobody did detection or defense outside of TEMPEST customers. It's why I keep advising a damn-near Manhattan project on EMSEC all the way from rooms to COTS components down to automating analysis in synthesis tools for ASIC's. The latter already do it quite a bit for non-malicious interference but the game changes going from designing Murphy's ASIC to designing Satan's. ;) Whatever is produced should bring technical sophistication and cost down dramatically with plenty reusable solutions & reference components.
- Niten 11y ago> if you could manage to get malware onto such a computer, then there are likely easier ways to exfiltrate the data than presented in this paper. I'm not so sure. It's much easier to drop an infected thumb drive in a parking lot than to get that thumb drive back after it's been plugged into a facility computer.