• mo_ztt ✅@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 year ago

    In one, they say they were able to hijack an Internet-connected security cam and capture footage of the power LED of a smart card reader 16 meters away. After processing and analyzing the footage, the team was able to recover the 256-bit key.

    Wow! That’s incredibly impressive.

    In another study, they were able to take iPhone footage of the power LED of Logitech speakers that were hooked up to an USB hub that was also charging a Samsung Galaxy S8 smart phone. From looking at the speakers’ power LED and analyzing its colors and brightness, the team says they were able to uncover the 378-bit key for the Samsung Galaxy — a remarkable scenario because the key was solved indirectly by looking at another connected device.

    Holy shit! That’s unbelievable! By which I mean: I don’t believe you.

      • mo_ztt ✅@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        1 year ago

        With the help of this video I found their paper. So: In order to compromise the smart card reader, they hooked up their own hardware to it and caused it to perform 10,500 signature operations while they carefully measured the brightness of the LED. For the Samsung private key attack, they’re applying in a novel way an already-known timing attack caused by an interaction between the crypto library and the power-saving features of the processor. They threw large numbers of carefully crafted cryptographic operations at the CPU to cause it to change its voltage and power characteristics in ways it’s not supposed to, which they then detected at a distance by observing the speaker’s LED, which led them to be able to deduce the private key.

        It’s still extremely impressive and 100% valid research. But, I feel that “if we have access to the hardware / ability to attack the software at length, and in addition we can watch the LEDs, the LEDs can help with the attack operation we conduct” is a little different than what the article made it sound like.

  • Amilo1591@lemmynsfw.com
    link
    fedilink
    English
    arrow-up
    3
    ·
    11 months ago

    The part about hacking Galaxy S8 keys by looking at a speaker connected to same usb… I think it’s very far fetched.

    S8 has a battery that is constantly charged by usb cable. When you unlock the phone, power draw doesn’t change except maybe for a brief second when key is entered.

  • Thorry84
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    I’ve read the paper, it’s really very cool. However there is nothing to worry about in real life. They captured thousands of uses of a smartcard and then used statistical analysis to gleen data used to attack a protocol with known vulnerabilities. In another setup they had a phone right up against the power led, using the roller shutter effect to collect a single point of data at really high speed. The whole thing also depends on a shitty power supply with a led in the main path. Most power supplies these days don’t have such a led and if they do it’s not always the case they leak data like this.

    The circumstances that allow this to work aren’t likely to occur in real life. Even if everything is just right, it still requires a way to collect thousands of samples to do the statistical analysis. And then also requires a scheme with known specific vulnerabilities to work.

    Very cool research, but don’t worry about taping off al your power leds for security reasons.