News: 1661277605

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Smartphone gyroscopes threaten air-gapped systems, researcher finds

(2022/08/23)


An Israeli security researcher known for foiling air gap security measures has published a reminder of just how vulnerable the approaches are to both visual and ultrasonic threats.

A pair of preprint papers from Mordechai Guri, head of R&D at Ben-Gurion University's Cyber Security Research Labs, detail new methods for [1]transmitting data ultrasonically to smartphone gyroscopes and [2]sending Morse code signals via LEDs on network interface cards (NICs).

Dubbed Gairoscope and EtherLED respectively, the two exploits are the latest in a [3]long line of research from Guri, who has previously developed air gap exfiltration methods, including stealing data by reading the [4]radio frequency of networking cables , using [5]RAM buses to transmit data electromagnetically , and doing the same [6]with power supplies .

From secure system to smartphone gyroscope

The Gairoscope attack involves using the speakers on an air-gapped computer to generate "covert acoustic sound waves" detectable by the microelectromechanical system (MEMS) gyroscopes that are standard in many smartphones.

Microphones, which Guri used in a previous [7]exploit , are considered high-security sensors that may give snooping malware difficulty with permissions. It's worth following the linked backreading if you're still scratching your head about what phone gyroscopes have to do with sound detection.

[8]

The problem with phone gyroscopes is that, unlike microphones that are generally visibly activated, Gyroscopes can be "used by many types of applications to ease the graphical interfaces, and users may approve their access without suspicion," Guri wrote in the paper.

[9]

[10]

Additionally, Guri cites a lack of visual indicator in iOS and Android that the gyroscope is being used and the fact that smartphone gyroscopes can be accessed from a browser using JavaScript, meaning – in theory – that no actual malware need be installed on the device to execute the attack.

Using his method, Guri was able to achieve speeds of up to eight bits per second at a max distance of eight meters, which the paper claims is faster than other established covert acoustic methods. Guri demonstrated the attack in a video showing an Android app detecting and decoding a message typed on a computer monitor within a few seconds of it being typed.

[11]

[12]Youtube Video

NICing data from LEDs

The second attack Guri reported on was EtherLED, which uses the familiar green-and-amber lights on network interface cards to transmit data in Morse code. As opposed to similar attacks that rely on exploiting lights on keyboards, hard drives and the brightness of monitors, Guri said Ethernet LEDs are "a threat that has not been studied before, theoretically or technically."

[13]LockBit gang hit by DDoS attack after threatening to leak Entrust ransomware data

[14]Ex-HP finance manager jailed after going on $5m spending spree using company plastic

[15]Ransomware attack on UK water company clouded by confusion

[16]1,900 Signal users exposed: Twilio attacker 'explicitly' looked for certain numbers

In this case, the lights being used is the novel element. As with other optical exfiltration techniques, EtherLED requires a visual line of sight, and as such is limited by the placement of existing hackable cameras that can spot the infected NIC and whether the lights face an outside window where someone could place a drone or other camera capable of picking up the blinks and decoding them.

Additionally, mitigations like covering NIC lights with black tape still apply.

That doesn't mean NIC exfiltration wouldn't work. In the paper, Guri reported being able to steal a 100-bit password in less than a minute with two LED colors, an RSA key in 30-60 minutes, and was able to decode a keystroke in two seconds.

When able to access the NIC driver or firmware as part of the exploit, those times drop drastically, with a password exfiltrated in one second, an RSA key transmittable in 42 seconds, and a 1KB text file able to be transmitted in less than two minutes.

What's the big deal?

It's easy to dismiss attacks against air-gapped systems as rare instances targeted against specific types of targets. While uncommon, attacks against such systems can be devastating.

Air gapping is used widely in military and defense systems, and Guri describes it as a common security practice in critical infrastructure, government agencies, finance, and industrial systems. Because of their extreme security posture, it's safe to assume information stored on air-gapped systems would be very valuable to the right people.

[17]

Guri cites [18]Stuxnet , a joint operation between the US and Israel to destroy Iranian nuclear enrichment systems, as a successful air gap infiltration. In addition, "several attacks on air-gapped facilities such as the power utilities and nuclear power plants have been publicized in recent years," Guri wrote.

In other words, these attacks might seem like fodder for spy novels, but someone needs to test the most improbable of attacks to see if they work before someone less scrupulous figures them out. ®

Get our [19]Tech Resources



[1] https://arxiv.org/abs/2208.09764

[2] https://arxiv.org/abs/2208.09975

[3] https://search.theregister.com/?q=mordechai+guri

[4] https://www.theregister.com/2021/10/14/lantenna_ethernet_cable_rf_emissions/

[5] https://www.theregister.com/2020/12/16/wifi_memory_hacking/

[6] https://www.theregister.com/2020/05/04/power_supply_attack/

[7] https://www.theregister.com/2018/03/12/turning_speakers_into_covert_listening_devices/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YwVN931didhn56Vudx0VTgAAANU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwVN931didhn56Vudx0VTgAAANU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwVN931didhn56Vudx0VTgAAANU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwVN931didhn56Vudx0VTgAAANU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://www.youtube.com/watch?v=5sUQ0jG01dw

[13] https://www.theregister.com/2022/08/22/entrust_lockbit_ddos_ransomware/

[14] https://www.theregister.com/2022/08/19/hp_manager_fraud/

[15] https://www.theregister.com/2022/08/18/clop_ransomware_uk_water/

[16] https://www.theregister.com/2022/08/16/twilio_breach_fallout_signal_user/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwVN931didhn56Vudx0VTgAAANU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://www.theregister.com/2012/06/01/stuxnet_joint_us_israeli_op/

[19] https://whitepapers.theregister.com/



Accessing gyroscope from a browser

DS999

Chrome is the only browser that supports something that stupid. Safari and Firefox have correctly refused to support that spec, and other stupidities like giving the browser direct access to connected USB devices, because they actually care about security a little bit.

anthonyhegedus

Maybe that's how my phone can hear me talk about something and then give me adverts about it.

druck

No, that will be the microphone, its far easier.

Review your app permissions!

elsergiovolador

Permissions are for the apps...

Let me see....

Anonymous Coward

.....an Android gyro detects some typing less than eight metres away.....

.....and this is described as "an attack".......

Please!!! The attackee sees some unknown someone with a smartphone less than twenty five feet away....when the attackee is typing something VERY SENSITIVE...

Air-gapped....Yes!

Eight bits per second (or in other language, one byte per second).....so a megabyte in say 2000 hours!!!

Plausible....I'll let you decide....

Re: Let me see....

druck

Many attachers infiltrate a system and remain undetected for months, during which significant amount of data can be exfiltrated by slow methods.

Re: Let me see....

Anonymous Coward

Bulk data exfiltration isn't much of a threat with this one, but it is one of many ways to extend a trigger or C&C to a compromised but isolated system.

Say you used a supply chain attack to install a modified Gas Chromatograph or Mass Spec in your targets lab. It's coded to flag certain traces (something something Hexaflouride perhaps?) and try to exfiltrate it's alert. That is where ultra low bitrate channels come into play. Perhaps that alert then trips another isolated system, say to remove speed limiting safeties, or hard dump power to gear that has a poor reaction to mid-process outages...

You can do plenty with a few bits even when you can't shift copies of war and peace around.

Re: Let me see....

elsergiovolador

Sometimes all you need to know is a safe word.

Anonymous Coward

> someone needs to test the most improbable of attacks to see if they work before someone less scrupulous figures them out

From the examples given in the article both parties work for the same side though.

Air gaps are all about physical security

Anonymous Coward

Most of this research(which I love for the lateral thinking involved) is exploiting the idea that the air gapped system isn't well isolated. This is why actual high security air gapped systems end to be behind security checkpoints, in access controled rooms, etc. The Gov had setup guides and rulebooks for physical security for several human generations, and handle much stealthier and higher tech attacks than these. If you didn't perform the physical hardening and isolation, you have an air-gap in name only.

While these attacks are an entertaining novelty, they aren't getting out of a properly configured SCIF. They do help highlight the multitude of ways generic PC and phone hardware make that process a nightmare. But using the pc speaker is old hat, and people have already done stuff over similar ranges using the ultrasonic whine of the transistors on the logic boards. People did TEMPEST attacks in the pre-cell phone era. They figured out a long time ago that if you wanted to keep a computer secure you should probably start by parking it in a sealed and windowless room, with access controls, behind a security checkpoint.

Re: Air gaps are all about physical security

elsergiovolador

If the most secure system is accessed by a human, then all you really need is to know by whom and a £5 wrench.

Re: Air gaps are all about physical security

Zarno

Other options you could go with:

~2m of 16mm heater hose

A wet beach towel

A sack of oranges

Old C-SPAN footage of a filibuster, played at 2X and looped

A particularly cheesed off cat

Jason Bloomberg

Gyroscopes can be "used by many types of applications ... and users may approve their access without suspicion"

So, the scenario is; you need to not only trick the attacked into installing something which covertly emits sound but you also need to trick someone into becoming the attacker to covertly pick up those sounds, and then have them both in the same room.

I'm not sure how long they can keep flogging this one-trick pony until it is completely dead.

Think it through.

NoneSuch

"So, the scenario is; you need to not only trick the attacked into installing something which covertly emits sound but you also need to trick someone into becoming the attacker to covertly pick up those sounds, and then have them both in the same room."

Amazon shopping App on phone

Amazon Alexa in your living room

Done.

Re: Think it through.

Paul Crawford

If you have Amazon products in or near any secure system you are completely fscked...

Anonymous Coward

A while back, an engineer friend was designing some data communications gear for the military. He was showing me the schematics and asking for my opinion on his design. My "day" job is in cybersecurity, but he farms out the occasional side project to me when he gets really busy.

I looked at the part of the circuit where he had a few LEDs. I asked about them, and he said that the client wanted some LEDs to show data activity. He just connected the LEDs through a buffer, directly to the transmit and receive data signals. I told him "wow, all someone needs to eavesdrop on the communications is a simple phototransistor". I went on "with a telephoto lens, it could even be done from a distance". That's when the oh, sh** moment hit him. I told him to at least put a one-shot device on the LED signal with long on-time. Engineers don't often think like an attacker.

Neutrinos have bad breadth.