3 ms·
> 1) if your air-gapped computer has malware that can do this, you've already lost Ughh...no? Delivering malware to airgapped computers is not the difficult t
by badrabbit 6y ago
> 1) if your air-gapped computer has malware that can do this, you've already lost
Ughh...no? Delivering malware to airgapped computers is not the difficult task. If you have sophisticated persistent attackers then they will figure out how you get data in/out of that system and find a way to execute code on it. "At this stage you have bigger problems" is a terrible thing to say especially by a security researcher. You know why there is always a plethora of unpatched systems in corporate networks you can move laterally to? Because IT admins have the same mindset "if we have hackers in the network, we have bigger problems to worry about". Real attacks against airgapped systems exist and are documented, research that assumes initial access and execution on airgapped systems to focus on hardening against C2/exfil channel establishment is very useful in my opinion.
> 2) if you need to be resilient to that, your "air gap" needs to be a sealed vault insulated from sound, EMI, and any other physical transmission medium, then this whole body of research becomes purely academic.
Academic or not, research like this helps people that actually need airgapped systems with threat modeling. Knowing what is possible is critical when evaluating what possible attackers might do to attack a system. 10bits/second sucks but it is usable for attackers and just like crypto attacks this can be improved over time.