Recovering secret keys from devices using video footage of their power LED
nassiben.com
nassiben.com
> A: Cryptanalysis requires a high sampling rate.
> By filling the frame with the LED, attackers exploit the rolling shutter to increase the number of measurements of the color/intensity of the LED by three orders of magnitude from the FPS rate (60 measurements per second) to the rolling shutter's speed (60K measurements per second in iPhone 13 Pro Max). A sampling rate of 60k can provide the needed sampling rate to attack functional IoT devices (smartphones, smartcards, TV streamers, etc.).
Using a single frame captured with rolling shutter as a 1-bit high-framerate video. Very cool technique!
EDIT - Answered here: https://news.ycombinator.com/item?id=36332352
I guess what could be more interesting or practical: Low-res very high FPS, or very high resolution, and regular/high FPS (having more pixels would give you more sampling opportunities...).
I do assume that you were talking in jest, but overestimations of technological progress are to much a pet peeve of mine that I had to bite. What will technology look like 40 years in the future? No idea. 40 years in the past we built a pretty cool maglev train (TR 06, best looking version of them all)
> The Emsland test facility was the only Transrapid track in Germany.[citation needed] It has been deactivated, and is scheduled to be disassembled.
As far as I can tell, they're comparable in features and specs. The Galaxy has better screen resolution, the Pixel has better networking... The only thing I could identify as a feature missing in the Galaxy is "dual LED flash" which was obviously technically possible in 2018.
So yeah, I was being a bit facetious. Considering the lifetime of phones, it probably takes 10 years rather than 5 for a farmer in Kenya to have a more powerful phone than a Bay Area programmer does today.
[0] https://m.gsmarena.com/compare.php3?idPhone1=8967&idPhone2=1...
[1] https://www.androidpolice.com/best-budget-android-phones/
https://www.gsmarena.com/motorola_moto_e7-10511.php
https://www.gsmarena.com/oppo_a57s-11835.php
At present that means ~2/4GB RAM, 4G, slow CPU, 50mpix, very laggy camera processing (because pixels are a metric buyers don't understand), slow storage I/O, no fancy comms like SOS beacons, UWB, limited security (no separate security enclave chip), and of course, old android and slow patching that stops quickly.
But you can at least get a headphone jack on the E7.
And that's OK for regular photos, but I guess is not that good if you want to do image or signal processing and your data has already gone through some other processing and a "IA".
Obviously processing is getting more powerful, but I think you're discounting the improvements in the space. There's a few notable exceptions (e.g., Pixel phones used the same kinda crappy sensor for many generations), but largely people keep using the newer, better sensor on flagship devices.
> As observed in the papers presenting the Minerva [8] and TPM-FAIL [9] attacks, many common cryptographic libraries optimize the computation time of ECDSA signing by truncating any leading zeros. This optimization results in a variable number of loop iterations that is associated with a variable execution time for the entire main loop, which is determined by the number of leading zeros in the randomly generated nonce.
> Thus, by measuring the signing time, attackers can detect the number of loop iterations and determine the number of leading zeros in the nonce k, which can be used to extract the target’s private key using lattice techniques, in which the signatures whose nonces have many leading zeros are used to construct a hidden number problem, which is reduced to a shortest vector problem and solved using lattice reduction (see [8] for details).
Edit: the intuitive reasoning for why it has to be secret and uniformly random is that half of the resulting signature is essentially an linear function of private key, k and the other half of the signature. So if attacker knows k he can trivially recover the whole private key. (EC)DSA uses slightly different representation of the signature, but it is only about shuffling stuff around (presumably to sidestep Schnorr's patent on the scheme) and the same attack still works.
Why aren't cryptographic security algorithms that defend against sidechannel timing attacks by guaranteeing fixed execution time more common?
Some fun slides with examples of timing attacks: https://cr.yp.to/talks/2014.10.18/slides-djb-20141018-a4.pdf. Old standards like RFC 5246 often say shit like "it is not believed to be large enough to be exploitable, due to the large block size of existing MACs and the small size of the timing signal" and then get exploited 5 years later.
> This is caused by the fact that the power LED is connected directly to the power line of the electrical circuit which lacks effective means (e.g., filters, voltage stabilizers) of decoupling the correlation with the power consumption.
The solution is simple: don't have crap power trees.
slightly improving the argument, while keeping the device non-compromised, is that whatever info is coming out of the LED is probably coming out in RF, also. so getting the LED further away from the CPU's power rail(s) probably isn't going to help. they're already emitting the data.
if you can stick a camera this close to the LED, you can probably surround the device with antennae, as well.
Let your LED will take extra 500-700 ms of fading when the power goes off. It would prevent such side-channel attacks extremely cheaply though.
> A: Use the most updated cryptographic libraries available.
Or what about covering the LED(s) with something so that the camera filming the top secret computer non-stop doesn't have a chance to exploit the side channel?
(excuse the sarcasm; but they were such low-hanging fruits I couldn't resist. The awareness is indeed important, as there are countless other side channels such as USB-cabled mice and keyboards with LEDs...
Also: I'm writing this from a hotel room with a TV illuminating the darkness with its bright standby blue melatonin killer LED - about to hang a towel over it)
[0]: https://news.ycombinator.com/item?id=36310594 [1]: https://news.ycombinator.com/item?id=36315148 [2]: https://news.ycombinator.com/item?id=36322522
They also have white versions
I've taken to just cutting the leads or traces to those power LEDs. Problem solved.
It was so bright that even two layers of gaff tape didn't resolve the situation.
It's crazy. I often wonder about the reasoning behind choosing to use these LEDs is. Does nobody actually use these device in the real world during development?
So that basically leads to them purchasing leds that are powerful enough for all uses and using them for everything, ie, they're way too bright.
Usage is entirely secondary
I like LightDims a lot. I realize I could just use tape, but I can always find the right size and shape that way on smaller devices, plus a little light comes through. It just doesn't shine.
LEDs on the electric toothbrush shining brigher than a thousand suns? Put stickers on them.
LEDs on the dog water fountain illuminating the whole living room at night? Put stickers on them.
The funny thing is that the LEDs are so bright that they still shine through the stickers. Except that now it's at the brightness level they should have had in the first place.
the point is so that you can find the light in the dark. it may be poorly made or unecessary but I can at least in theory understand the logic.
Here’s another technique to pick up information remotely with a video camera: a laser microphone.
The next step I was going to take it was to use to microphones on different windowpanes and be able to triangulate multiple keyboards in a room - never quite got there because my DSP skills were garbage, but it's in the back of the mind someday to pick back up if I ever take a sabbatical.
In terms of cameras, I suspect my Pixel 4a's rolling shutter isn't truly continuous, but has blocks of 4 or so "scanlines" (haha) which start and stop recording light simultaneously.
> We describe a new acoustic cryptanalysis attack which can extract full 4096-bit RSA keys from the popular GnuPG software, within an hour, using the sound generated by the computer during the decryption of some chosen ciphertexts. We experimentally demonstrate such attacks, using a plain mobile phone placed next to the computer, or a more sensitive microphone placed 10 meters away
[0] https://www.iacr.org/archive/crypto2014/86160149/86160149.pd...
Example: <https://github.com/shoyo/acoustic-keylogger>
I would link something, but there isnt even anything useful about it on the internet, that google can find anyway.
Ironically, you can always keep open a few pages infested with multiple video ads or other doodads that switch unpredictably, sap power, and thus add noise to your power consumption. Or run a CPU miner for some coin.
Unironically, you can just put a bit of adhesive tape over your power LED if you're really concerned that someone cares enough to stage an attack like that against you.
I guess online ads do have a benefit for the user
Oh yeah someone else mentioned caps hmm