DiggThis

Power sockets can be used to eavesdrop on what people type on a computer.

Security researchers found that poor shielding on some keyboard cables means useful data can be leaked about each character typed.

By analysing the information leaking onto power circuits, the researchers could see what a target was typing.

The attack has been demonstrated to work at a distance of up to 15m, but refinement may mean it could work over much longer distances.

"Our goal is to show that information leaks in the most unexpected ways and can be retrieved," wrote Andrea Barisani and Daniele Bianco, of security firm Inverse Path, in a paper describing their work.

The research focussed on the cables used to connect PS/2 keyboards to desktop PCs.

Usefully, said the pair, the six wires inside a PS/2 cable are typically "close to each other and poorly shielded". This means that information travelling along the data wire, when a key is pressed, leaks onto the earth (ground in the US) wire in the same cable.

The earth wire, via the PC’s power unit, ultimately connects to the plug in the power socket, and from there information leaks out onto the circuit supplying electricity to a room.

Even better, said the researchers, data travels along PS/2 cables one bit at a time and uses a clock speed far lower than any other PC component. Both these qualities make it easy to pick out voltage changes caused by key presses.

A digital oscilloscope was used to gather data about voltage changes on a power line and filters were used to remove those caused by anything other than the keyboard.

"The PS/2 signal square wave is preserved with good quality… and can be decoded back to the original keystroke information," wrote the pair in a paper describing their work.

They demonstrated it working over distances of 1, 5, 10 and 15m from a target, far enough to suggest it could work in a hotel or office.

"The test performed in the laboratory represent a worst case scenario for this type of measurement, which along with acceptable results emphasizes the feasibility of the attack on normal conditions," they added.

The pair said their research was "work in progress" and expect the equipment to get more sensitive as it is refined.

The attack is due to be demonstrated at the Black Hat conference that takes place in Las Vegas from 25-30 July.

Article from: BBC
 

Related posts:

  1. Smart clothes could take photos
  2. Hi-tech criminals target Twitter
  3. Oyster card hack to be published
  4. Boot your PSU without a Motherboard
  5. Cooler Master M850 Power Supply

Search

Latest Articles

How to replace cracked iPhone 3GS screen

How to replace cracked iPhone 3GS screen

So you’ve just been to a party and woken up with a throbbing hangover to find your iPhone screen is cracked. Familiar story? It’s happened to me, too many times! Fret not though, it’s really easy to replace a cracked iPhone screen and can be done for a just a fiver!

Read Article »

Related Content

Jan 17

Protest causes UK website blackouts

As some of you might have heard recently, the US have some planned anti-piracy laws that they hope to implement, and, because of this, many websites will be going offline in protest.

Read the Story »
Nov 28

Best Buy UK has cut-price sale before fleeing back to US

After only 18 months here in the UK, retailer Best Buy is almost finished packing its bags and ready to go back to the US, not before having one hell of a massive sale though.

Read the Story »
Nov 24

Steve Jobs movie – updates and information

Planning and preparations are now in place for the movie about the late Apple founder Steve Jobs. The movie, once completed, will probably be one of the highest grossing movies of all time.

Read the Story »
Nov 23

New Google Doodle celebrates Stanislaw Lem

The latest and possible the greatest Google Doodle is now viewable on the Google homepage. It celebrates 60-years since Stanislaw Lem’s first book was published and has been hailed as Google’s most complex Doodle ever.

Read the Story »