Data Exfiltration from Speakerless Air-Gapped Computers via Hard Drive Noise
arxiv.org
arxiv.org
Each new story supports his model. Energy gapping for the win.
Not so trivial, then.
Scary stuff...
[0] - not sure about some quantum ones, but then again, those that do not radiate information aren't exactly very useful
The other alternative would be to raise the electrical and auditory noise floor to the point where the leaked signals get lost in random noise. Then you'd have to perfectly synchronize the external sensors with the internal clocks to be able to extract any useful information.
Obviously these solutions aren't perfect (what is?) but short of placing a spatially filtered passive radar in the same room, you wouldn't get any usable information leakage.
edit: the company is http://chaologix.com/
In all seriousness, this is nothing new. People have been exfiltrating data from the moving parts of drives for years. Even humble floppy drives can send messages at a great distance. Here some vids of them transmitting sound files to external receivers.
https://www.youtube.com/watch?v=bGSTYvx5c78
https://www.youtube.com/watch?v=G081hD0nwWE
And this guy is does the same with a single HDD.
https://www.youtube.com/watch?v=_kYlZC7hSV0
If you have control of any moving part you can tap out messages to either a microphone or someone watching your power consumption.
- HDD noise
- Ultrasound via speakers
- Electric capacitor sounds
- Power supply analysis
- USB file system
- LED blinking
- EM radiation (CPU, monitor)
- Wireless mouse/keyboard
* underground or otherwise well shielded facilities
* dedicated server rooms, switch rooms, comms rooms etc etc
* manned 2 stage gates for entry into facility + (electronic) access going into any department inside.
* strict regulations on what kind of equipment goes into the facility. (Wireless anything has been taboo since it came I think.)
What this doesn't handle is mostly:
* hostile sysadmins. You can only do so much about hostile insiders. Pair work, swapping peers, only allow updates once they have been vetted by a second crew etc can reduce the risk as can something as simple as being nice.
* hostile contractors that makes it through despite your extensive vetting. They must also be cold enough to bring fancy surveillance gear despite the risk of getting caught.
* stuxnet-levels of effort from a resourceful and determined opponent, piercing your firewall carefully from the inside. Still then it would take time to get anything meaningful from electronic noise (and at this point the attacker can likely just read the data from memory, Target Credit Card style.
http://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-...
You are right. But to our defense: at this point we are again beyond the passive eavesdropping scenario I think we discussed above.
When you own the networking gear it is more or less game over for the victim anyway, isn't it?
http://www.inf.ed.ac.uk/publications/thesis/online/IM100855....
Could this attack be defeated by pumping white noise into a space, or would it have to be too loud to be practical?
Not enough? Have folks play heavy metal with 12 4kw amps. Anyone trying to monitor will have their ears bleed.
(Example) :) https://www.youtube.com/watch?v=w68qZ8JvBds
};-)
"Data Exfiltration from Speakerless Air-Gapped fanless Computers with SSDs via subtle screen color-temperature variation."
I imagine it's easier with stronger emissions (e.g. CRTs), but also still relevant with EM emitting from modern displays
iPads. Kept in a Faraday cage and provisioned with apps over a cable from a neutered host (read-only drive, maybe? Anyway: locked down and firewalled to prevent unapproved software updates).
Alternatively: the market for refurbed LSI-11s is booming.