Finding Radio Frequency Side Channels
duo.com
duo.com
https://github.com/martinmarinov/TempestSDR
https://www.rtl-sdr.com/tempestsdr-a-sdr-tool-for-eavesdropp...
Also I think this paper is amazing - http://s3.eurecom.fr/docs/ccs18_camurati_preprint.pdf
"The well-known electromagnetic (EM) leakage from digital logic is inadvertently mixed with the radio carrier, which is amplified and then transmitted by the antenna. We call the resulting leak “screaming channels”"
You might find this interesting too, leaking AM emissions from a computer by twiddling the memory bus - https://github.com/fulldecent/system-bus-radio
I made a silly program to play .wav files based on that.
This technique is as old as computers themselves, it's well-known back to the mainframe and minicomputer era. For example, here's a video of a DEC PDP-8 (LAB-8/e) minicomputer (1971) playing music using the same technique [0], the software was Richard Wilson's "Music Compiler" written back in 1975, you should watch it. Later it was also rediscovered by the microcomputer hackers, members of the Homebrew Computer Club played Beatles on the Altair 8800.
Acoustic leakage is also possible. Here [1] is a program that runs on a Thinkpad, and here's the video [2]. It changes the Intel CPU P-state to induce a coil whine at a specific frequency, and it plays PC Speaker music via the inductor coil on the switched-mode power supply of the CPU.
On one hand, we can say it's a time-honored tradition in computing and hacking, on the other hand, it means the same huge side-channel exploit is still here despite that it has been half-a-century already...
[0] https://www.youtube.com/watch?v=akvSE5Z474c
In a related note that's what Genkin et. al exploited along with capacitors changing size too, to extract RSA keys:
I have personally tried it on my Thinkpad, I even modified the program to play different tunes. Although my Thinkpad is a different model, it works!
> Genkin et. al exploited along with capacitors changing size too, to extract RSA keys:
In my opinion, the most fascinating work of side-channel attacks by Genkin et. al, is the chassis ground potential side-channel [0]. Apparently, the conducted electromagnetic emission also induces a small voltage on the computer chassis ground (Earthing/Grounding is only for 50 Hz/60 Hz AC, it doesn't do anything at RF). Direct attack by probing the chassis is not the only way to attack, anything connected to the chassis ground, such as a CAT-5 cable, can be used. The most mind-blowing thing is, it even works across a human body! So basically, someone can steal your private key by touching your computer.
I will have to read that properly, but would I be right in thinking they would be able to see their leakage on the earth wire too?
I saw this where they captured PS/2 keystrokes from the earth wire: http://dev.inversepath.com/download/tempest/tempest_2009.pdf
But I'm wondering if using a high sample rate ADC would pick up other emissions like Genkin et. al are doing?
Yes, I think it should work. As you said, the main difference appears to be just the ADC. The PS/2 research only used a 1 Msps ADC on a microcontroller, it's a laughingly simple setup, but already productive (it's literally a 10-dollar instrument today, ideal spy gadget if your victim is still using PS/2 I guess).
> But I'm wondering if using a high sample rate ADC would pick up other emissions like Genkin et. al are doing?
Someone should try again using the latest USRP SDR receiver [0] and see what they are able to get. RTL-SDR can be used but the sampling depth (8-bit) is not ideal for hunting weak signals near a strong signal.
Probing the power earth wiring instead of the chassis or data cable will be noisier, there are a lot of appliances connected. And at higher frequencies, the SNR will be worse due to attenuation, but I think nothing stops one from performing a successful attack.
To my knowledge, using a power line filter is mandatory in many high-security facilitates.
Hackers Hut is an absolutely amazing resource from the University of Eindhoven. And it is fun to know that the Vrije Universiteit isn't the only Dutch university doing security research (also shoutout to Delft! I saw some great work from them as well -- mostly in the form of my teacher Pietro Frigo).
[1] https://www.win.tue.nl/~aeb/linux/hh/
(removed tempest.pdf)
It's also the most interesting part of the document!
The CIA front, for those unfamiliar with the name.