Lasershark: Fast, bidirectional communication into air-gapped systems
intellisec.de
intellisec.de
I mean, sure, if you have the ability to compromise the airgapped device by running code on it then you could presumably be doing a lot of things besides just leveraging potential LED line of sight.
In such a scenario, you're also probably never, ever going to be manually updating the printer's firmware.
Or the FedEx driver who delivered it to the nuclear plant flashed a modded firmware with the same version number?
How often have you disassembled your printer firmware and given it a decent audit?
If your threat model does legitimately consider this to be a "reasonable chance", then your facility will be printer-free.
Vanity attacks with branded names like this "Lasershark" sound sexy and appealing, because they invoke James Bond-style gadgetry and accompanying delusions of grandeur, but real life is decidedly more prosaic: someone is going to discover infinitely more intelligence while expanding exponentially less time and energy by just good old fashioned dumpster diving than by designing and successfully implementing a novel airgap exfiltration methodology.
Air gapped networks and hardware are interesting to powerful organizations. Don’t underestimate the base for “impossibly expensive”
But I don’t know how much of a realistic threat it poses, because in order to control GPIO LEDs the computer already needs to be pwned. Magic Lantern dumped firmware via LED because there wasn’t a known serial link or display driver or anything like that to make it easier.
But it’s a camera, and it’s not designed to be airtight air-gapped. Running arbitrary code is certainly discouraged, but to my knowledge Canon has never fought against consensual hacking of their cameras. (I say “consensual,” because there have been, say, Wi-Fi exploits found and patched, but that’s probably not the way a camera owner would try to get in.)
Anyway, this boils down to the definition of an air gap, because any input/output device is bridging it. A printer was mentioned, of course printing sensitive information is a bridge across the gap. And if the machine has GPIO LEDs then that’s a bridge, too. But what about a hidden camera pointing at the monitor? Frankly the monitor itself is a serious exfiltration risk across the air gap, no?
So as always in security, at some point we have to say “good enough,” and consider it as safe as can be.
Edward Snowdon was recently spied on by cameras installed by a fire extinguisher technician...
Or privilege escalation, so that an insider threat can do more damage than otherwise possible.
I don't think "it's airgapped so vulnerabilities don't matter" really holds water.
I am however interested in the low volume high frequency range sound of "static" that appears over speakers _only_ if the volume is turned up to the max in an otherwise silent office. I've had this occur on one Netherlands based website so far in the last few days, but did it come from the Netherlands based website or was it already on my system waiting for activation when visiting websites without any obvious ties back to the US?
If you didnt have your speakers on max in a silent environment, only your mobile phone would pick it up not you (if you have a mobile phone), so is this some sort of malware which can jump from one device to another like a self contained virus of sorts and is it bringing data back to base, a few bytes at a time over time?
Its a clever exploit because most people have their mobile on their desk, and if they dont have speakers some will be listening to music on their headphones so will never be alerted to the communication taking place within smartphone sound frequency ranges.
ts exploiting human behaviour and exploiting the abilities of smart phones, not your usual bit of malware.
I have also noticed Windows with all its security measures on max is able to control the bridging settings for network adaptors in VMware, which can then prevent a WMware version of Kali and wireshark from working properly in promiscuous mode, making it harder to analyse network traffic on a machine.
"Dial-up and leased-line modems were found to faithfully broadcast data transmitted and received by the device"
Edit: Also it looks like Loughry has proposed similar work, using lasers and LEDs https://arxiv.org/pdf/1907.00479.pdf
Very quickly, major device manufacturers switched to buffered activity LEDs and the attack became useless.
I remember at one point modems switched from flickering with actual traffic to just slow blinking with activity.
Run while(1){sin(cos(tan(rand(1))) for 1, nothing for 0, every half hour, with a correctional bit thrown in for good measure.
measure the heat of the room via remote sensing, power consumption, AC/air frequency analysis.
the NSA will have to add a layer of thermodynamic static noise in addition to their rooms full of stereo's blasting white noise.
a technically proficient attacker could infer the value of a encryption key given the GDP of the nation-state, if the data was granular enough.
Hm. So maybe the recent spike in inflation is just a series of ones in an RSA key?
Probably the only way of keeping data secure would be to heavily insulate (noise, thermal, RF, power, etc) the room so that any signal would take weeks to pass through the insulation, and then rotate your key material more often than that. Opening the door would have to dump power to the room before the door can be opened so an attacker couldn't leak data out when people entered/left.
similar to the original reason password rotation exists - that the hashes of passwords to all users were known to all parties, and were assumed cracked after a certain timeframe - passwords were required to be changed before that cyclic window.
similarly, captcha's for high-sensitive sites embed the domain in the captcha, and only allow the captcha for a small timeframe. it then has a delay to show/fetch the captcha challenge, and must be completed/expires quickly. this reduces the chance of a MitM attack or a phishing attack to nil.
ultimately, if you want to prevent information leakage, you'll have to create a event horizon surrounding the secret. and even then, Hawking predicts that black holes sweat, so even then, your 2^^8^^8 key is still derivable from collecting and de-entrophizing the sweated muons of a photon-sphere.
*: unless you use reversible computing to generate the secret, then reverse the computation, but keep the result. this prevents people in the future from collecting information on current wave-states, barring entanglement.
The DT-MF tones exploit a small ACE allowing a POST payload to be reconstructed and curl-ed.
The payphone and nearby homeless are then vaporized for opsec.
I wonder if even knowing every transaction down to the cent is granular enough
If you can get access to the same AC power circuit, or something that's not too far upstream, you could also look at the power consumption directly by watching for very small voltage drops and/or phase shifts. Extra credit if you modulate the data to be exfiltrated with a Gold code or a similar sequence that facilitates recovery below the noise floor.
Bandwidth won't be great but it'll beat IP over HVAC.
They are firing a laser at an LED under the following assumptions.
1. They already have arbitrary code execution on the device but want to open a bidirectional communication channel. 2. It is possible to reprogram the GPIO port to function as an input (not always possible, since ports may be output only). 3. They can induce a large enough current through firing a laser at the LED to exceed the GPIO threshold voltage for said port. 4. They have a suitable line of sight to the LED, ie. it is both facing them and not recessed, and there is no oblique or low-opacity window between them and the air-gapped asset. 5. They can get close enough to launch the attack.
It does, either in films or intelligence lore, but not for all intents and purposes, in regular life (regular life including corporate espionage). As for counter-measures: curtains.
It's a bit like being sold flood protection insurance if your data warehouse is in the desert. In other words, it just doesn't happen realistically, and there are a million and one other much more practical technical surveillance counter measures to spend a likely very-limited security budget on.
When your unit of accounting is such that six figures is a rounding error, they can afford it. And for good reason.
I wouldn't expect you to have knowledge of their operations. The only reason I do is because I was close with the head of security. But I will make sure to pass along your expert advice next time I'm there.
Did all of the countermeasures help? Yes, probably quite often. Were they bullet-proof? Absolutely not, and the director of security would have told you so.
Mmm hmm, okay.
“Tech enthusiasts: My entire house is smart.
Tech workers: The only piece of technology in my house is a printer and I keep a gun next to it so I can shoot it if it makes a noise I don't recognize.”
Honestly I’m starting to operate under the assumption that anything can be hacked with enough focus and determination. Obscurity isn’t such a bad defense in the long run.
https://twitter.com/PPathole/status/1116670170980859905?s=20...
Threat: Ex-girlfriend/boyfriend breaking into your email account and publicly releasing your correspondence with the My Little Pony fan club
Solution: Strong Passwords
Threat: Organized criminals breaking into your email account and sending spam using your identity
Solution: Strong passwords + common sense (don’t click on unsolicited herbal Viagra ads that result in keyloggers and sorrow)
Threat: The Mossad doing Mossad things with your email account
Solution: ◆ Magical amulets?
◆ Fake your own death, move into a submarine?
◆ YOU’RE STILL GONNA BE MOSSAD’ED UPON
All credit to James Mickens for the above.
My point being that if someone is that committed to compromising your air gapped system they're going to find a way. Especially if they can just slip the janitor $10,000 to put a USB labelled "Barely Legal Gone Wild" into the machine while vaccumming.
Part of Defensive Depth includes vetting and requiring the janitor who cleans the SCIF to themselves also hold a security clearance.
Your cited example is also why Counterintelligence is a thing. It's not enough to trust your processes; you also have to probe them.
When I was in the military I met a guy whose job was to pentest (among other things) nuclear weapons facilities and NORAD defense installations, specifically their computer equipment. He had some pretty wild stories; suffice it to say the ladder trick doesn't work when you are trying to access an ICBM solo.
Sure, but no amount of vetting is going to be perfect. Maybe the vetting missed something, maybe some circumstance changed between now and the most recent re-up, maybe instead of $10k it's $10M, etc.
A better solution is to physically disable the USB ports.
It's not an either/or situation.
I'm still not sure why he was worried about that.
I don't think Mossad would find it all that easy to compromise an ordinary bank vault.
Correct, and education can be seen as a form of mass brain washing employed by the state on the population. With that in mind, are private schools & colleges a breeding ground for criminals or certain beliefs and their easy access into strategic parts of society? https://en.wikipedia.org/wiki/School_tie#Old_school_tie https://en.wikipedia.org/wiki/Old_boy_network
I wonder how hard it would be to make this dual use and have it working as a laser microphone that can detect the sound vibrations on materials like glass windows?
Suddenly non contact blackout blinds become useful even in a conservatory!
A given LED color below will only detect colors to the right of it
Infrared < Red < Orange < Yellow < Green < Blue < Ultraviolet
Back in the 1990s I breadboarded an alarm circuit that used a normal cheap bicolor LED as both transmitter and receiver, feeding some BiFET op amps. I could detect a bicycle reflector to about 6 feet
https://cris.bgu.ac.il/en/publications/xled-covert-data-exfi...
> While LEDs are designed to emit light and can thus unnoticeably encode information through high-frequency flickering, their ability to also perceive light is largely unknown in the security community. In particular, by directing a laser on the LEDs of office devices, we induce a measurable current in the hardware that can be picked up by its firmware and used to receive incoming data.
In high security settings the buildings have no windows or have fake windows to keep external laser signals out so that's not new. That's been true since about the time someone figured out you can reconstruct audio from the doppler of a laser reflected off windows.
Correct, and not just line of sight, but static line of sight. The potential scenario here is something like if there is a desk phone on someone's desk visible from the window that you want to monitor (and you also manage to successfully install custom firmware on the phone).
The Newtons had grayscale LCDs with manually adjusted contrast. The MP130 and later also had an electro-luminescent backlight but it was not always active. So the user contrast setting was very important to maintain for screen visibility.
How many air gapped systems are running next to a Window?
Although I guess you can use this as evidence: if it needs to be air-gapped it also needs to be in a windowless room or some kind of sealed container.
Windows are discouraged in SCIF construction, though not outright against spec. Aside from visual controls like blinds/curtains, IR/RF controls like RF film over the glass panes are also mandatory.
That being said it might be enough just to compromise ANY system within the air gapped network - and then escalate from there. Data could still be routed through the computer with line of site (although now we are talking about an increasingly sophisticated automated hack)
That leads to the obvious question for high-value systems that may be targeted - presumably fixed systems not laptops/notebooks/tablets - are the activity/power LEDs commonly connected via software-controlled GPIOs or mostly part of the electronic circuit only ?
Looks like it's all doable digitally.
For a lot of chips changing the purpose of a pin may not be possible unless you are a nation state and have all of the design info on an ASIC.