5 ms·
I'd say it's a solid "no", and the author says as much in the paper. > We transmitted the data with a bit rate of 1 bit/sec, which is shown to be the minimal t
by jagger27 4y ago
I'd say it's a solid "no", and the author says as much in the paper.
> We transmitted the data with a bit rate of 1 bit/sec, which
is shown to be the minimal time to generate a signal which is
strong enough for modulation. The BER for PC-1 is presented
in Table VI. As can be seen, the BER of 1% - 5% is maintained
between 0 - 90 cm. With a greater distance of 120 cm, the
BER is significantly higher and reaches 15%. With PC-2 and
PC-3, the bit error rates (BER) are less than 5% only in short
proximity up to 30 cm, and hence the attack is relevant only
for short ranges in these computers.
This particular attack is a weak 6 GHz signal that can exfil about 1 bit/s from a metre away. It's neat, but impractical.
- leeter 4y agoPretty sure a ferrite beads can shut this down anyway. But this seems like a more practical question of "If they can get that close do they really need this?" They've already had USB or software access in some form already.
- cogman10 4y agoYup, that's the part that makes this attack completely impractical. You are trying to leak information but first you have to install a virus on the computer? Neat concept, wildly impractical.
- PeterisP 4y agoI mean, Stuxnet is an illustrative example that has been seen in the wild (and the rare exception of one that became public - in general, if you'd be the target of something like this and found out, the results of that analysis would be classified and unpublishable), and there have been almost 20 years to do improvements since Stuxnet was first developed, so there definitely are real attacks aiming to do stuff and/or exfiltrate data from air-gapped computers after "installing a virus on the computer" - and it's quite clear that Stuxnet did achieve a significant practical effect.
- lallysingh 4y agoEnough for cryptographic key material, but not much else. Still, publishing which methods are a risk, and which ones aren't, is quite useful.