Coming to a Desktop near you: Tempest Capabilities
AftanGustur writes "New Scientist has an interesting article about a new toy we will all want. It's a card that plugs in one of your PCI slots and allows you to scan the EMF spectrum and read your neighbours terminal. In about 5 years you might be able to get one for just under £1000. (Modern Tempest Hardware costs about £30000) " Excellent. Now I won't have to read over Rob's shoulder all the time.
"Microsoft announced this morning that it did not design it's keyboards to emit to the EMF spectrum, allowing the NSA a backdoor into your computer. They place the blame on physics."
For that matter, light is EMF radiation, so unless you have your LCD in a coal-mine, it's reflecting EMF all the time it's switched on.
Then, there's the fact that screen monitoring isn't the only monitoring you can do. I used to use a radio, tuned into the bus for the PET, as a sound card. Worked surprisingly well, for all that very clunky metal shielding. What's to stop a much higher-quality receiver from seeing the data, in an unshielded box, being sent TO the LCD, or to any other device on the machine?
It's a mistake to assume that Tempest technology is single-function and that that single-function only works in a single situation.
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
Pattern of keystrokes? I'd bet it's possible to really confuse the individual spying on you via the typing patterns monitor method... :P
Use a Dvorak
Already, a few people have posted expressing their misconceptions about what TEMPEST is. In a nutshell, it's the process by which radiation given off by electronic devices can be captured and analyzed in order to gather information about what that device is doing.
A good example of how it can be used was given during the October 1996 episode of Discovery Channel's "Cyberlife" show.
A couple other decent sites with more information about TEMPEST are:
The Complete, Unofficial TEMPEST Information Page
TEMPEST monitoring in the real world
In about 5 years you might be able to get one for just under £1000.
In about 5 years, I expect to have a flat-screen (19"). These don't work on LCD, do they?
Also due in about 5 years...
**A robot that cooks and cleans and has a cute, cartoon personality.**
**Cars that fly**
**One supreme Linux Distro**
**A final end to the DOJ MS trial**
I'm concerned with the following paragraph from the article:
And keyboards are also troublesome. They rely on a scanning signal, which radiates the pattern of keys being pressed. So the patent suggests using a random number generator to continually distort the scanning signal.
That's one of the the most vague things I've ever read in my life. That's like saying "I didn't want anyone to see me when I robbed the bank, so I used a random number generator to distort the police radio signal." It's apparent that they have some particular application of a random number generator in mind and that it is probably effective, but how on earth it's applied is neither implied nor apparent.
Does any have a clue what they're referring to?
This is old news.
I have an Atari Jaguar with Tempest capabilities...
--
Did you know that you can do tricks with antialiasing in your fonts to change the text on your screen as it appears to a tempest scanner?
tempest isn't there to read text off your screen. it's there to show that your screen is on in the first place and that it's doing something, and that something matches patterns kind of like typing. so if you say "i was in bora bora the day that system was cracked" they can ask you, "then who was typing on your computer?"
I've finally had it: until slashdot gets article moderation, I am not coming back.
Also, he demonstrated displaying one thing on your screen, and another thing on the attackers screen, which has the potential to be used two ways: either to foil an attacker, or the possibility of a Tempest virus, which secretly transmits your cryptographic key to the white van waiting outside, while displaying something else altogether on your screen!
Ross Anderson's homepage has links to his papers on this topic.
You're right, of course, a laptop won't be detectable at the same range as a CRT, but the actual range isn't fixed, as the radiation doesn't just stop.
(eg: If you rigged up Jodrel Bank to a Tempest device, you'd probably be able to capture an LCD on the moon, with only minimal distortion. Jodrel Bank's resolving power would be the key factor there, rather than signal strength.)
Using a primitive, unfocused arial, a low-power amplifier, and minimal screening, you're probably right on the estimates - 1000 yards for a CRT and 10 yards for an LCD sound about right. Rig up a squarial or a satellite TV dish, beef up the amplifier, and improve the screening and you can probably add at least one, maybe two, orders of magnitude.
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
Shielding one's computer is very cumbersome. Is it not easier, knowing the exact frequencies where your electronic components leak data, to just add a small white-noise transmitter that will jam the needed frequencies? If you want to get sophisticated, it can analyze your emissions in real-time and generate the correct noise to cover/distort them...
But in any case, local jamming should be much simpler/cheaper than shielding. Anybody knows if this is a viable option and if not, why?
Kaa
Kaa
Kaa's Law: In any sufficiently large group of people most are idiots.
Of course it's possible! It'll mean a reworking of X font handling mechanisms, and it'll certainly be a lot of work, but it definitely *is* possible.
"The invisible and the non-existent look very much alike." -- Delos B. McKown
All this thing is is a tuner card on a pci board.
BFD. Ham radio people have been making stuff like this for years. Maybe not so nice a version, but hey...
Of course, it is a difference when it's a mass-market item, and more people have the ability to hack away at the software.
Anyway, basically the card is a variable tuner to go through the spectrum and see what's out there. Pipe any signals you may find into the system and decode to your hearts content...
It's pretty entertaining what's out there on the airwaves.. Fun with HAM radios.
---
- Give a man a fire and he's warm for a day, but set him on fire and he's warm for the rest of his life.