Login Register


Computer coughs up passwords, encryption keys through its cooling fans filter_list
Author
Message
Computer coughs up passwords, encryption keys through its cooling fans #1
Quote:
[Image: ysqtro.jpg]
Here’s a security update to haunt your dreams, and to make the FBI’s quest for un-exploitable cryptographic backdoors look all the more absurd: a team of Israeli researchers has now shown that the sounds made by a computer’s fan can be analyzed to extract everything from usernames and passwords to full encryption keys. It’s not really a huge programming feat, as we’ll discuss below, but from a conceptual standpoint is shows how wily modern cyber attackers can be — and why the weakest link in any security system still involves the human element.

In hacking, there’s a term called “phreaking” that used to refer to phone hacking via automated touch-tone systems, but which today colloquially refers any kind of system investigation or manipulation that uses sound as its main mechanism of action. Phone phreakers used to make free long distance phone calls by playing the correct series of tones into a phone receiver — but phreaks can listen to sounds just as easily as they can produce them, often with even greater effect.

Hackers (the movie) -- scarily prescient tagline?!That’s because sound has the potential to get around one of the most powerful and widely used methods in high-level computer security: air-gapping, or the separation of a system from any externally connected network an attack might be able to use for entry. (The term pre-dates wireless internet, and a Wi-Fi-connected computer is not air-gapped, despite the literal gap of air around it.)

So how do you hack your way into an air-gapped computer? Use something that moves easily through the air, and which all computers are creating to one extent or another: Sound.
Article
As long as they weren't targeting someone writing a lot of emails or documents, I suppose this could actually be effective. Still it would be difficult work, you have to get someone onto the computer to install the malware and then install a microphone and then have a receiver in close enough proximity to record the data from the microphone and then have the means to retrieve the data on the recorder. A Cleaner or IT staff I suppose would be a good cover for such an attack.
[Image: master645.png]

Life before death, strength before weakness, journey before destination.” ― The Way of Kings by Brandon Sanderson

[+] 1 user Likes Master's post
Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #2
This is actually really disturbing, but at the same time its also kinda funny that someone had this idea. I would like to see the FBI or someone use this.
You can find me on Keybase
"Reach the state of ubiquity, and you will be in control"
Student, Technician, Designer, and more.
[Image: YUpAMpx.png]

Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #3
It's fucking amazing but impractical... I love to see articles like these though, seeing the things researchers built. It's like Christmas.

[+] 1 user Likes Wildfire's post
Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #4
I don't buy this. From what I know of fans they run on simple 12 volt DC current, and are independent of the system (mostly) the pc simply controls the fan speed via voltage. I smell a hoax.
[Image: qcYJ3l.png]

[+] 1 user Likes Skullmeat's post
Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #5
I thought phone phreaking was all but forgotten nowadays. It's good to see It's still remembered.

On topic, I'd love to see the accuracy of It all and the percentage rate of a successful outcome. I haven't read the full article so unless a demonstration Is available whereby It can be substantiated, It means nothing to me. Still, this Is very Informative Indeed.
[Image: AD83g1A.png]

Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #6
(07-06-2016, 04:38 AM)mothered Wrote: I thought phone phreaking was all but forgotten nowadays. It's good to see It's still remembered.

On topic, I'd love to see the accuracy of It all and the percentage rate of a successful outcome. I haven't read the full article so unless a demonstration Is available whereby It can be substantiated, It means nothing to me. Still, this Is very Informative Indeed.

I looked at the article and the only sources I found on it link back the their own site. That doesn't convince me.
[Image: qcYJ3l.png]

[+] 1 user Likes Skullmeat's post
Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #7
(07-06-2016, 04:42 AM)Skullmeat Wrote: I looked at the article and the only sources I found on it link back the their own site. That doesn't convince me.

Thanks for that, I don't have the time at the moment to read the entire article.

Agree, linking back to their own resource doesn't provide anything to back their claim.
[Image: AD83g1A.png]

Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #8
(07-06-2016, 04:34 AM)Skullmeat Wrote: I don't buy this. From what I know of fans they run on simple 12 volt DC current, and are independent of the system (mostly) the pc simply controls the fan speed via voltage. I smell a hoax.

I say the same. It seems very unlikely. Hilariously so.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #9
It was legit, and allowed for a very slow transmission of data over a couple of metres, but if you're going to use it maliciously then you'll need malware and physical access. If you have those then there's much easier and more effective ways than this.

This article is overhyping and misinterpreting what would otherwise be a pretty interesting piece of research.

Reply

RE: Computer coughs up passwords, encryption keys through its cooling fans #10
(07-06-2016, 10:05 AM)Eclipse Wrote: It was legit, and allowed for a very slow transmission of data over a couple of metres, but if you're going to use it maliciously then you'll need malware and physical access. If you have those then there's much easier and more effective ways than this.

This article is overhyping and misinterpreting what would otherwise be a pretty interesting piece of research.

So it's legit? Whats your sources? Because if its real I'd like to see some hard research and more reputable articles about it. Might be an interesting read.
[Image: qcYJ3l.png]

Reply







Users browsing this thread: 1 Guest(s)