I was going to add a line like "Who has a mic and speakers on their airgapped machine?!" but obviously every laptop does.
When a program wanted to produce a tone, the program took the input frequency of the clock divider divided by the desired frequency and programmed it into the clock divider. To control the duration of the tone, a DOS or BIOS call was available delay the program or the program could hook the timer interrupt vector. The program would then turn the speaker off or start the next tone.
Programs could also turn the output bit on and off manually. Some programs could turn the bit on and off rapidly to play arbitrary sounds. There was even a Windows driver to play sound through the PC speaker, but it disabled interrupts, causing the clock, keyboard, mouse, and network to stop while the sound was playing.
Ruiu said he arrived at the theory about badBIOS's high-frequency networking capability after observing encrypted data packets being sent to and from an infected laptop that had no obvious network connection with—but was in close proximity to—another badBIOS-infected computer. The packets were transmitted even when the laptop had its Wi-Fi and Bluetooth cards removed. Ruiu also disconnected the machine's power cord so it ran only on battery to rule out the possibility it was receiving signals over the electrical connection. Even then, forensic tools showed the packets continued to flow over the airgapped machine. Then, when Ruiu removed the internal speaker and microphone connected to the airgapped machine, the packets suddenly stopped.
The conclusion that for communications across the air-gap to work, the receiver must already be infected is the only alternative to "No, it isn't happening."
Now I'm not in a position to say, that it is happening. But I'm not in a position to say that the supply chain for electronic devices is hardened against an attack by a state sponsored agency seeking to inject spores into devices at the time of manufacture. If an agency is interested in maximizing backdoor accesses, having infected devices roll off the assembly line and straight to end users certainly seems like an ideal outcome. It's map reduce.
Don't get me wrong, I know I'm furiously folding Reynolds Wrap. But I also know that there is a cognitive gap between the furniture of everyday experience and large scale phenomena - e.g. collecting meta data on all phone calls simultaneously and then storing and searching it doesn't fit with the MOS 6510 mental model of computing I habitually use.
And we already have proof that manufacturers in China have been doing this:
http://www.theguardian.com/technology/2012/sep/14/malware-in...
"Microsoft researchers in China investigating the sale of counterfeit software found malware pre-installed on four of 20 brand new desktop and laptop PCs they bought for testing. They found forged versions of Windows on all the machines."
This would be the easiest way to do this, and since it's already been demonstrated, I would hasten to say your tinfoil folding is certainly is not being done in vein.
A typical laptop has a +- 3db audio frequency response of 200hz - 8khz if you are lucky, even if you wanted -10 or 20db I doubt you would get much above 12khz which is detectable by most people without significant hearing damage. I'm very skeptical about this article...
https://plus.google.com/u/0/103470457057356043365/posts/3reW...
It's perfectly capable of sending and picking up a 20kHz signal by itself. The frequency response starts dropping off drastically at around 14kHz. Around 21kHz seems to be the practical limit.
However, there seems to be a bit of distortion going on. I'm not sure it's possible to send a clean inaudible signal without introducing lower frequency components.
So, you may be able to hear higher than 20kHz. Even if you increase your sound card sample rate, best test would be to try something analog to eliminate other bottlenecks in the audio processing. But you can easily tweak your audio settings and generate sine waves with this program:
I don't understand why he hasn't posted 'infected' USB sticks to a bunch of high profile security folk with "POTENTIAL BIOS MODIFYING TROJAN ONBOARD" written on it? It would be a matter of a day or two before someone monitored all communications with it passively and proved or disproved his theory.
@dragosr - @PaxNoxNomPox no evidence of "spreading" via audio. Just comms between infected machines.
I'm guessing of course, there's not much real details to go on, and that would mean this infection is more then just a malicious BIOS.
EDIT: Or he's full of shit. Honestly I said that several times reading it, the story was clearly written for sensationalism and made many seemingly impossible claims. I'm no where near an expert but it still set off the bullshit meter too many times.
Hm. I suppose this is theoretically possible, but I don't see why it would be done in a practical sense. If the malware needs to "phone home", it doesn't need to send packets via localhost; it just sends them out on whatever interface is connected to the Internet. (But how would you distinguish those packets from any others being sent out to the Internet?) If the malware is divided up into multiple processes that need to communicate with each other, why would they betray themselves by connecting via localhost? If they are on OS X or Linux, they can use Unix sockets, which don't need to go through any network interface. If they are on Windows, they can use any of several Windows IPC mechanisms that don't require a network interface.