Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

[ Create a new account ]

Compromising Wired Keyboards

Posted by CmdrTaco on Monday October 20, @09:30AM
from the not-a-lot-of-substance-here dept.
Flavien writes "A team from the Security and Cryptography Laboratory (LASEC) in Lausanne, Switzerland, found 4 different ways to fully or partially recover keystrokes from wired keyboards at a distance up to 20 meters, even through walls. They tested 11 different wired keyboard models bought between 2001 and 2008 (PS/2, USB and laptop). They are all vulnerable to at least one of the 4 attacks. While more information on these attacks will be published soon, a short description with 2 videos is available."
security inputdev tempest hardware usethemouse
hardware inputdev
story

Related Stories

The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More | Login | Reply
Loading... please wait.
  • by Anonymous Coward on Monday October 20, @09:33AM (#25439925)

    I won't type what I think about that...

  • TEMPEST (Score:5, Informative)

    by michaelhood (667393) on Monday October 20, @09:33AM (#25439929)

    This appears to be related to why TEMPEST [wikipedia.org] attacks work on monitors.

    • Re:TEMPEST (Score:5, Insightful)

      by CRCulver (715279) <crculver@christopherculver.com> on Monday October 20, @09:43AM (#25440013) Homepage
      Indeed. Already a decade ago I was hearing people claim that the best way to enter passphrases and the like would be an on-screen keyboard whose keyboard map changes after each letter is input, all ideally displayed with a TEMPEST-resistant font. Even back then people knew anything wired was snoopable.
    • Re:TEMPEST (Score:5, Interesting)

      by Harley_Ghostrider (1226170) on Monday October 20, @10:01AM (#25440223)
      I agree. I don't see the big "News Flash" on this. This was well known back in the mid 80's when I fixed computers for the military. They had to be Tempest certified before and after the fixes. It was common knowledge that EMF emissions would be able to be picked up and recorded some distance away from the host computer.
      • Re:TEMPEST (Score:5, Insightful)

        by IceCreamGuy (904648) on Monday October 20, @10:58AM (#25440963) Homepage

        I don't see the big "News Flash" on this.

        I think the big news flash on this is that they actually performed four different, real attacks on real, physical keyboards. Theory is one thing, someone actually saying "hey, we can really do this on the cheap now to 11 different keyboards sold at your local Best Buy; here's how..." is another. I don't think it's unreasonable to consider that "news for nerds."

        • Re:TEMPEST (Score:5, Funny)

          by Jay L (74152) * <`mf.yaj' `ta' `hsals+yaj'> on Monday October 20, @02:27PM (#25444199) Homepage

          I think the big news flash on this is that they actually performed four different, real attacks on real, physical keyboards.

          When the first mass-transit-quality teleporter is installed in a major city, there will be a commenter on Slashdot, sneering at it: "This isn't news. They've been doing that at the quantum level for years."

  • by Drakkenmensch (1255800) on Monday October 20, @09:34AM (#25439935)
    Is this going to be another one of those hollow claims backed up by a viral video, like unlocking car doors with a tennis ball?
  • ...why should I worry? I work for BoingBoing.

  • by apathy maybe (922212) on Monday October 20, @09:38AM (#25439967) Homepage Journal

    To determine if wired keyboards generate compromising emanations, we measured the electromagnetic radiations emitted when keys are pressed. To analyze compromising radiations, we generally use a receiver tuned on a specific frequency. However, this method may not be optimal: the signal does not contain the maximal entropy since a significant amount of information is lost.

    Our approach was to acquire the signal directly from the antenna and to work on the whole captured electromagnetic spectrum.

    Looks like a room or building size Faraday Cage [wikipedia.org] (a foil hat the size of your house!) might be the only defence...

    Especially considering that you can also detect what is shown on monitors (again, by detecting the electromagnetic radiation), and so on screen "keyboards" operated with a mouse become not so useful.

    It's not clear from the article whether they have have the keyboard before hand to be able to record which key-press outputs what radiation, or if they can use this (and by that I mean one of the four) technique on any old keyboard, including ones they haven't seen before.

    Anyway, this shouldn't be too surprising to anyone, electronics emit electromagnetic radiation, which can be captured.

    • by bhima (46039) * <Bhima...Pandava@@@gmail...com> on Monday October 20, @09:48AM (#25440069)

      Being the only house on your block not radiating all sorts of data sounds like an excellent reason for the DHS to perform a no-knock raid with a legions of SWAT teams and an armored troop carrier or two.

    • by d3ac0n (715594) on Monday October 20, @11:05AM (#25441071)

      Looks like a room or building size Faraday Cage (a foil hat the size of your house!) might be the only defence...

      This is actually easier to do than you might imagine. My old house was essentially a Faraday Cage. You could NOT get a wireless signal more then 1 foot outside it. Why? Aluminum Siding. Add in aluminum powder tinted windows (triple layer UV and thermal glass) and the only leakage was straight up through the roof.

      So you could get an OK cell-phone signal on the second floor (2 bars), but almost nothing on the first floor. Walk out the front door, 4 bars. Same with WiFi. Full strength "g" signal anywhere inside, walk outside and the connection drops.

      My current home has asbestos siding (bleah!) that does nothing to attenuate the Wifi signal, so I actually had to encrypt my wireless for the first time ever when I moved. I can pick up my wireless signal about 2 doors away now, and it's the same wireless device I used in my old house, located in a roughly similar spot (close to the center of the house, in the basement, on a shelf near the basement rafters)

      If I could I'd re-side in Aluminum again, but the costs to re-side an asbestos tile sided house are astronomical, and many places simply won't do it.

      Regardless, if you really want to attenuate any wireless signals going into or out of your home, slap on some aluminum siding. You'll kill those pesky wireless signals, AND make your house look really nice at the same time.

  • Oh no, we will have to learn to type code by tapping on a single key and read the results in the flickering of the hard drive light.

    When they can manage the same trick in a noisy office environment with dozens of keyboards and monitors in use, then I'll worry.

      • Most modems back in the '80s just ran either RD, TD, or (RD|TD) through the LED. It was cheap and easy and gave you a good activity signal. Nobody cared about people sniffing the data through the LED, and really hardly anyone is ever going to be in a situation where they're even potentially exposed. And for virtually all the rest, this is hardly the low hanging fruit... if you can get close enough to read the LED, you're close enough to see what the target is doing any number of easier ways.

  • Nothing new (Score:5, Interesting)

    by thered2001 (1257950) on Monday October 20, @10:04AM (#25440259)
    I saw this demonstrated about 10 years ago while working for a military contractor during a demonstration to increase awareness of security risks. They were able to capture video and keyboard data through a wall adjacent to the PC being monitored. (I can't elaborate on who 'they' were...but I'm sure astute readers can guess correctly.)
  • by sirwired (27582) on Monday October 20, @10:15AM (#25440395)

    As everyone should know, the IBM Model M is the One True Keyboard. Surely all of the steel plating inside that thing must be good for something! If all else fails, the relentless clicking while they listen to your bugged cube or house should drive them completely insane.

    Even if it doesn't prevent snooping, you could still use the thing as a self-defense weapon when Mysterious Men From the Shadows come to capture you.

    SirWired

  • Shenanigans? (Score:5, Interesting)

    by tdc_vga (787793) on Monday October 20, @10:30AM (#25440579)
    If you watch the video he sets the keyboard.eavesdropper into a listening/polling state waiting for keypress information. From there it's filtered and decoded --fine. Now the part that seemed odd to me is it exits as soon as it finds the 'e' in 'trust no one', why?

    If the eavesdropper is in a polling state it should continue looking for more keypresses, unless something there are some smoke and mirrors going on. Also, if you listen there's no termination sent --no keypresses heard on camera.
    • Re:laptops only? (Score:5, Informative)

      by tsvk (624784) on Monday October 20, @10:08AM (#25440307)

      I understood that the disconnecting of the charger was because of that the "victim" laptop computer and the "attacker" desktop computer were connected to the same electrical mains network of the building.

      By disconnecting the laptop charger it was proven that the keyboard signal was truly intercepted from over-the-air electromagnetic radiation, as the laptop was "independent" and not connected to anything. There was not any chance that the signal could have leaked or transmitted any other way.