Power sockets can be used to eavesdrop on what people type on a computer.

Security researchers found that poor shielding on some keyboard cables means useful data can be leaked about each character typed.

By analysing the information leaking onto power circuits, the researchers could see what a target was typing.

The attack has been demonstrated to work at a distance of up to 15m, but refinement may mean it could work over much longer distances.

"Our goal is to show that information leaks in the most unexpected ways and can be retrieved," wrote Andrea Barisani and Daniele Bianco, of security firm Inverse Path, in a paper describing their work.

The research focussed on the cables used to connect PS/2 keyboards to desktop PCs.

Usefully, said the pair, the six wires inside a PS/2 cable are typically "close to each other and poorly shielded". This means that information travelling along the data wire, when a key is pressed, leaks onto the earth (ground in the US) wire in the same cable.

The earth wire, via the PC’s power unit, ultimately connects to the plug in the power socket, and from there information leaks out onto the circuit supplying electricity to a room.

Even better, said the researchers, data travels along PS/2 cables one bit at a time and uses a clock speed far lower than any other PC component. Both these qualities make it easy to pick out voltage changes caused by key presses.

A digital oscilloscope was used to gather data about voltage changes on a power line and filters were used to remove those caused by anything other than the keyboard.

"The PS/2 signal square wave is preserved with good quality… and can be decoded back to the original keystroke information," wrote the pair in a paper describing their work.

They demonstrated it working over distances of 1, 5, 10 and 15m from a target, far enough to suggest it could work in a hotel or office.

"The test performed in the laboratory represent a worst case scenario for this type of measurement, which along with acceptable results emphasizes the feasibility of the attack on normal conditions," they added.

The pair said their research was "work in progress" and expect the equipment to get more sensitive as it is refined.

The attack is due to be demonstrated at the Black Hat conference that takes place in Las Vegas from 25-30 July.

Article from: BBC
 

Like us on Facebook!

Latest Articles

Latest Competitions

Latest Reviews

Follow us on Twitter!

Latest Articles

Which Apple iPad should you choose?

Which Apple iPad should you choose?

If you’re looking to purchase an Apple iPad, there are a few things you need to consider. Are you going to really notice the Retina Display, use the upgraded 5-megapixel camera or use the new 4G connectivity? If you answered no to any of those, then you might want to take a look at this guide on choosing the right iPad.

Read Article » How to replace cracked iPhone 3GS screen

How to replace cracked iPhone 3GS screen

So you’ve just been to a party and woken up with a throbbing hangover to find your iPhone screen is cracked. Familiar story? It’s happened to me, too many times! Fret not though, it’s really easy to replace a cracked iPhone screen and can be done for a just a fiver!

Read Article »

Related Content

Apr 26

Springtime fun with the arrival of Shaun the Sheep in 3D!

Spring has truly sprung with an all-new series of video adventures featuring a much-loved farmyard favourite from the multi-award winning Aardman Animations. And, the great news is, they are free and exclusive to those with a Nintendo 3DS handheld gaming system.

Read the Story »
Mar 27

GAME has entered administration – many jobs will be lost

It’s official, GAME has entered administration and we’ll shortly be seeing high street store closures as well as a rise in unemployment rates. However if they find a buyer who wants to take on £180m debt, they might be alright.

Read the Story »
Mar 26

Sky HD subscribers can now access Sky Anytime+ for free

Sky have just announced that they’re taking the shackles off their Anytime+ service so that all of their HD customers, no matter who their broadband provider is, can benefit from the catch-up service.

Read the Story »
Mar 23

Student Finance Leaks over 8,000 Students’ Details

Thousands of student details have accidentally been released as part of a mass email distribution. The email addresses of the students were sent out as an attachment to an email which prompted students to complete their grant application forms.

Read the Story »