Hackers can steal cryptographic keys by video-recording power LEDs 60 feet away
arstechnica.com
arstechnica.com
> The video must be captured for 65 minutes, during which the reader must constantly perform the operation.
So not only must you be using a compromised brand of smart card (which number in the low single digits), you have to use a cheap Chinese reader and the camera must be focused on card activity for 65 minutes (which would never happen). You have to compromise the camera first.
It would be more effective to use what I term the "Walter Sobchak method" which is during that 65 minute window you "grab the smart card and beat the PIN out of him".
there's a massive difference between giving away your keys and being compromised without your knowledge.
not to mention that are ways to secure data in a way that different keys yield different valid results with plausible deniability.
Also, the standard for cryptographic security tends to be "better than brute force". 65 minutes to extract a key is orders of magnitude better.
That's why certain agencies prioritizing collection over real-time cracking. Collect first, worry about the content later. An adversary just need 65 minutes of footage taken at some point - and we live in an age where there are plenty of devices that can passively capture w/ their cameras.
65 minutes is pretty bad. That's several orders of magnitude less than it takes to crack password hashes.
> Activating a rolling shutter can upsample the sampling rate to collect roughly 60,000 measurements per second. By completely filling a frame with the power LED that’s present on or connected to a device while it performs cryptographic operations, the researchers exploited the rolling shutter, making it possible for an attacker to collect enough detail to deduce the secret key stored on a smart card, phone, or other device.
I don’t recall how they fixed that, but it was a big deal at the time. Capacitor? Optical diode?
I believe I recall people using white-out or paint on the LEDs they couldn’t afford to replace.
Edit: if you think about it, wire protocols have error correction built in. Most of them don’t negotiate the amount to use, it’s baked into the spec. When you’re eavesdropping you lose signal to noise ratio. When the input signal is very clean, there’s plenty of SnR to spare. It’s easier to listen to a loud argument than a quiet conspiracy.
Faraday Cage is not just a mesh of wires but a solid wall/floor/ceiling cladding of copper.
Takes care of LEDs too.
https://www.nsa.gov/portals/75/documents/news-features/decla...
Some Blue LEDs contain sapphire, which is apparently macrostate entangleable.
I’ve studied quantum cryptography rather extensively, and I have no idea what you’re trying to say.
You could have a power LED that contains an actual magical quantum computer running attacker controlled software and with unlimited entanglement with the attacker, and it would not have a qualitatively greater ability to exfiltrate information to the attacker than a plain old LED would have. At best you would get a bandwidth increase by a small constant factor, improved tolerance to noise, and the ability to prevent anyone else from decoding the transmission.
From "Experiment demonstrates continuously operating optical fiber made of thin air" (2023) https://news.ycombinator.com/item?id=35812168 :
> Electrons turn piece of wire into laser-like light source" (2022) https://news.ycombinator.com/item?id=33490730
> What is also remarkable: Plane electromagnetic waves like a light beam normally cannot cause permanent velocity changes of electrons in vacuum, because the total energy and the total momentum of the massive electron and a zero rest mass light particle (photon) cannot be conserved. However, having two photons simultaneously in a wave traveling slower than the speed of light solves this problem (Kapitza-Dirac effect).
> For Peter Baum, physics professor and head of the Light and Matter Group at the University of Konstanz, these results are still clearly basic research, but he emphasizes the great potential for future research: "If a material is hit by two of our short pulses at a variable time interval, the first pulse can trigger a change and the second pulse can be used for observation—similar to the flash of a camera."
Chirped Pulse Amplification: https://en.wikipedia.org/wiki/Chirped_pulse_amplification
What Hz rate is necessary to do CPA Chirped Pulse Amplification with laser, or with a [blue] LED? FWIU lasers have a repetition rate between 0.1Hz and 1Mhz, and a pulse width between 1 picosecond and 1 millisecond?
Looks like there are already commercial LED CPA systems.
Aren't there also weird signal effects with e.g. PWM and a blue led connected to a Pi with a sufficient clock rate? What are the maximum binary data transmission distances for [blue] LEDs?
How to fade an LED in and out when you can only vary 5volts on and off? PWM: Pulse Width Modulation; you vary the duty cycle:
PWM: https://en.wikipedia.org/wiki/Pulse-width_modulation
"Learn PWM signal using Wokwi Logic Analyzer" https://blog.wokwi.com/explore-pwm-with-logic-analyzer/
Wokwi > New (Pi Pico w/ Micropython) LED project: https://wokwi.com/projects/300504213470839309
It's also imperative to minimize all sort of other EMF from a Van Eck perspective.
But in practice it doesn't matter that much for most of us.
A roll of electrical tape also seems like a reasonable mitigation in the field for the truly paranoid.
https://eprint.iacr.org/2017/985.pdf is an example of power analysis relying on ed25519's deterministic behavior.
Of course, there could still be some LED attack not connected to actually doing crypto operations, but this should mitigate the known attack.