5 ms·
If I may speculate about why those ICs were destroyed, then I'd wager on, that the decision about which ICs to destroy was not made by an engineer, but by some
by datenwolf 12y ago
If I may speculate about why those ICs were destroyed, then I'd wager on, that the decision about which ICs to destroy was not made by an engineer, but by some overseeing manager who went through a number of PowerPoint slides (like they were leaked over the past year) and identified those as a threat, because those ICs have been mentioned for being an active part in data exfiltration.
Let me explain: What those ICs have in common is, that each of them bases their function on fast switching of voltages:
The keyboard controller IC rapidly (at several hundred kHz) switches voltage through the key matrix row-lines (addressing the row) so that on the column lines the voltage is read out and thereby telling if a key is pressed, hence making the connection.
The touchpad controller IC does the same, but not for reading out electrical connection made by keys, but the change of capacitance caused by a dielectric (=finger).
The voltage inverter IC is switching a voltage to drive an induction coil for a voltage converter.
Now the (often unwanted) side effect of switching voltages is, that they create electromagnetic waves, that radiate away. Unless you're building a radio transmitter you don't want that, as this is then EMI (electromagnetic interference). EMI is a big concern in the design of keyboard, touchpad and voltage conversion controller.
But for spooks the EMI caused by regular device operation can be a great covert channel to exfiltrate information. To the unwary it just looks like the regular, random EMI but a spy agency may know how to cleverly use it.
Now making use of keyboard row-column switching caused EMI to eavesdrop on user input is by no way something new. This kind of tempest attack is as old as it gets. You can nicely see on an oscilloscope when the controller begins reading out the keypad (there's some pause before) and every row switching produces a pulse; if there's a key pressed the pulse looks different; also the shape of the pulse depends on the amount of wire closing the circuit, so this gives you the key position on the row and column, thereby telling you which key is pressed. When voting computers were about to introduced in the Netherlands European hackers demonstrated, that the entry system of the machines used could be eavesdropped on by their EMI. Unless you got yourself a super EMI optimized keyboard on your computer, you're likely giving away your inputs by EMI.
The touchpanel controller is similar.
Now the inverter controller is interesting, because those normally drive a display's backlight, which is more or less independent from the data displayed on the display. But then the display brightness can be controlled by software! So by having a spy program run on the computer that modulates the display brightness with some data you want to exfiltrate you can make use of that channel. However the bitrate will not be very high; if I had to make an educated guess, I'd say about 100 Baud to 1 kBaud.
Anyway I think those techniques may have been presented or documented somewhere and a person without the technical understanding at GCHQ command thought those particular controllers would maybe hold some secrets or are something special, while in fact the really interesting stuff happened somewhere else. It's not even clear that the laptop computer had display modulating spyware installed. But that's what I was looking for on suspect computers first, because the keyboard and touch controllers are boring and their principal vulnerability to eavesdropping by EMI emission is well known.