4 ms·
> The interesting side channel papers are those where you can get information from emissions (e.g. crypto keys) without malware on the target computer, during n
by studius 6y ago
> The interesting side channel papers are those where you can get information from emissions (e.g. crypto keys) without malware on the target computer, during normal operation.
What about using GSM on cell phones to steal data? (2015): https://www.sciencedaily.com/releases/2015/07/150728123634.htm https://www.sciencedaily.com/releases/2015/07/150728123634.h...
Also, here's a nifty resource for exfiltration; leakage through DNS would seem like a big one after any airgap is bridged:
https://github.com/rmusser01/Infosec_Reference/blob/master/Draft/Exfiltration.md https://github.com/rmusser01/Infosec_Reference/blob/master/D...
Or maybe you could use one of NYU's robotic geese to insert a USB key into an airgap'd PC and have it use it's webbed foot to hold lower keys down then peck type a command to copy files.
- marcan_42 6y agoThat GSM one is.... exactly the same as this attack. Literally. DDR3-1600 RAM, 800MHz I/O bus, 800MHz GSM frequencies. Pump out data encoded in bursts of noise by exercising RAM. Receive it with a hacked phone. They built on all the work of OsmocomBB (which already is a completely open source GSM stack on a commercial phone baseband). Even building on such a powerful and well-documented platform, they only got a, quite honestly, pathetic ~1.5 bit/second speed out of it, making excuses about "inadequate access to the DSP's full capabilities" and it being an old phone (which is nonsense, the entire point is that it's an open stack, thus much easier to build powerful software on even with hardware limitations, they just weren't capable). Then they gave up on OsmocomBB and just used an SDR as a receiver to get 1kbps. Sorry, this is just sad. Anyone actually experienced in these fields would be able to do orders of magnitude better, guaranteed, with that kind of hardware. Oh yeah, there's an appendix to the paper where they got it to work with an unmodified Android phone... by putting it 10cm from the motherboard, so the emission jams the cell signal, and you see the bars drop. No actual bitrate attempted, but it looks like you wouldn't get more than 0.5bps out of that from their graph. And now 5 years later he's rehashing the same exact technique, on a different frequency. Sigh.