I mean, sure, if you have the ability to compromise the airgapped device by running code on it then you could presumably be doing a lot of things besides just leveraging potential LED line of sight.
I mean, sure, if you have the ability to compromise the airgapped device by running code on it then you could presumably be doing a lot of things besides just leveraging potential LED line of sight.
Or privilege escalation, so that an insider threat can do more damage than otherwise possible.
I don't think "it's airgapped so vulnerabilities don't matter" really holds water.
I am however interested in the low volume high frequency range sound of "static" that appears over speakers _only_ if the volume is turned up to the max in an otherwise silent office. I've had this occur on one Netherlands based website so far in the last few days, but did it come from the Netherlands based website or was it already on my system waiting for activation when visiting websites without any obvious ties back to the US?
If you didnt have your speakers on max in a silent environment, only your mobile phone would pick it up not you (if you have a mobile phone), so is this some sort of malware which can jump from one device to another like a self contained virus of sorts and is it bringing data back to base, a few bytes at a time over time?
Its a clever exploit because most people have their mobile on their desk, and if they dont have speakers some will be listening to music on their headphones so will never be alerted to the communication taking place within smartphone sound frequency ranges.
ts exploiting human behaviour and exploiting the abilities of smart phones, not your usual bit of malware.
I have also noticed Windows with all its security measures on max is able to control the bridging settings for network adaptors in VMware, which can then prevent a WMware version of Kali and wireshark from working properly in promiscuous mode, making it harder to analyse network traffic on a machine.
In such a scenario, you're also probably never, ever going to be manually updating the printer's firmware.
Or the FedEx driver who delivered it to the nuclear plant flashed a modded firmware with the same version number?
How often have you disassembled your printer firmware and given it a decent audit?
If your threat model does legitimately consider this to be a "reasonable chance", then your facility will be printer-free.
Vanity attacks with branded names like this "Lasershark" sound sexy and appealing, because they invoke James Bond-style gadgetry and accompanying delusions of grandeur, but real life is decidedly more prosaic: someone is going to discover infinitely more intelligence while expanding exponentially less time and energy by just good old fashioned dumpster diving than by designing and successfully implementing a novel airgap exfiltration methodology.
Air gapped networks and hardware are interesting to powerful organizations. Don’t underestimate the base for “impossibly expensive”
But I don’t know how much of a realistic threat it poses, because in order to control GPIO LEDs the computer already needs to be pwned. Magic Lantern dumped firmware via LED because there wasn’t a known serial link or display driver or anything like that to make it easier.
But it’s a camera, and it’s not designed to be airtight air-gapped. Running arbitrary code is certainly discouraged, but to my knowledge Canon has never fought against consensual hacking of their cameras. (I say “consensual,” because there have been, say, Wi-Fi exploits found and patched, but that’s probably not the way a camera owner would try to get in.)
Anyway, this boils down to the definition of an air gap, because any input/output device is bridging it. A printer was mentioned, of course printing sensitive information is a bridge across the gap. And if the machine has GPIO LEDs then that’s a bridge, too. But what about a hidden camera pointing at the monitor? Frankly the monitor itself is a serious exfiltration risk across the air gap, no?
So as always in security, at some point we have to say “good enough,” and consider it as safe as can be.
Edward Snowdon was recently spied on by cameras installed by a fire extinguisher technician...