4 ms·
As a practical example, the keys and metadata for a root certificate authority are only a few kilobytes.
by netflixandkill 6y ago
As a practical example, the keys and metadata for a root certificate authority are only a few kilobytes.
- hutzlibu 6y agoAnother practical example, names of secret agents and places of meetings are not long, either.
- kevindong 6y agoThe article says: > In fact, data can be exfiltrated through vibrations at a lowly speed of half a bit per second, making AiR-ViBeR one of the slowest exfiltration methods that Guri and his team have come up with in recent years. My personal private key has a file size of 3,243 bytes. At the quoted speed, it would take ~14.4 hours to steal assuming that the time spent recording is completely continuous. A single ASCII character would take 16 seconds to "steal".
- moonchild 6y agoASCII is a 7-bit encoding, it would take 14 seconds.
- kevindong 6y agoI suppose for plain text files, converting the encoding from extended ASCII (aka 8-bit) to regular ASCII (7-bit) is worthwhile if one really wants to pursue this type of worthwhile. Although in retrospect you can get even higher speedups by condensing the character encoding table down to A-z and 0-9 and omitting quite a few of the ASCII characters from the lookup table.
- maccard 6y agothat's the slowest method of exfiltration (as mentioned in your quote). I looked at USBee (one of the other methods mentioned by the article) and found [0] which says: > USBee transmits data at about 80 bytes per second, fast enough to pilfer a 4096-bit decryption key in less than 10 seconds. These methods are only going to be deployed for very high value data, so it's likely you would want a method of flagging a certain machine as infected (which something like AiR-ViBeR would be very suitable for) so you can use something more high frequency (but maybe more likely to be detected) to get larger amounts of data off the drive. [0] https://arstechnica.com/information-technology/2016/08/meet-usbee-the-malware-that-uses-usb-drives-to-covertly-jump-airgaps/ https://arstechnica.com/information-technology/2016/08/meet-...
- netflixandkill 6y agoIf you're going to the trouble of setting up this kind of exfiltration plan, that 14 hours is probably less than 1% of your expended man hours. But the critical element is that it is nearly unstoppable and undetectable after the fact unless the source is recording all EMF and audio state around it. If your attack code deletes itself when its done, all the "normal" data loss prevention controls are irrelevant.