편집증 아니면 준비된 것? 당신 책상 위의 스파이들

나는 보통 왜 내 노트북과 휴대폰에 주변광 센서에 스티커가 붙어 있냐는 질문을 받는다. 어떤 사람들은 내가 빛 센서와 카메라의 차이를 모른다고 생각하며 이건 카메라가 아니라고 설명하려 한다. What they don’t know is that ambient light sensors can be used with machine learning methods to extract data like they are weak cameras.
I generally hear from people: “But we have nothing to hide!” Well, you have more to hide than you think, and your data can be combined with other data collected from you elsewhere to produce intelligence at a level you can’t even imagine possible. And those who collect the data are not necessarily those with right intentions. Your data can be collected by different threat actors to be analyzed using AI and be used for different purposes and intentions.
In cybersecurity, we assume that if a type of attack is possible and there is an opportunity to perform an attack, then there might be motive to perform those attacks. We do not assume that those who can collect the data always have legitimate cause to collect that data. We also do not assume only a single party or entity exploit a vulnerability to collects that data.
Below is a list of other things that can be used to spy on you that you probably don’t know have such capabilities.
Your TV speaker can listen to you
I am one of those who usually choose a TV model without a microphone or camera before I need to physically remove those devices. I also have a home firewall and a secured internal network, but I have learned throughout the years not to only rely on logical controls. However, based on a WikiLeaks release in 2017 and documents from 2014, the CIA (in cooperation with MI5) turned speakers in certain TV models into microphones to collect data. They even developed a fake off mode to show that the TV is off when they collect those conversations. If you think your TV might listen to your conversation, it is better to unplug it when not in use. It also saves you some energy because plugged devices even while not in use may consume some electricity.
Your tablet or laptop light sensor can capture your hand or your image
I always adjust screen light manually, and I believe I have a good reason for that.
The ambient light sensor is used to measure the amount of light and to adjust the brightness of the screen. Ambient light sensors can be used to capture images or keystrokes to steal passwords and data. A group of MIT researchers 최근 안드로이드 태블릿의 손짓을 주변 광 센서에 포착해 터치 상호작용을 포착하는 개념 증명을 만들었으며.
당신의 마우스가 당신의 대화를 들을 수도 있다
이건 정말 말도 안 된다! 마우스는 마이크나 스피커가 없어서 마이크로 변환되어 무언가를 들을 수 있다. However, 사이드 채널 공격이 있다 “Mic-E-Mouse” 공격자가 마우스를 통해 대화를 들을 수 있게 해주는.
고성능 게이밍 마우스 (고DPI) 광학 센서에 의해 탈취 가능, 즉, 대화할 때, 음성 진동을 이 센서로 측정할 수 있다. 기계 학습 알고리즘과 마우스 센서 데이터를 활용해, 보안 연구자들이 진동과 음성 인식 가능한 음성을 식별할 수 있다.
Side channel attacks are a type of physical attack that measures changes in device output while a device performs an action. This type of attack is usually more sophisticated and targets certain assets like encryption keys. However, if an attack method is developed for certain types of devices, it won’t be very difficult to expand it to other similar devices and even automate it.
Motion sensors (gyroscope) can be used to record your voice
Now that we learned your mouse can be used to record your talking, it’s good to know that motion sensors can also be used for the same purpose. This is important as almost all modern smart devices like phones and tablets have a gyroscope or motion sensor. The sensor acts as a vibrating device, making it perfect for side-channel attacks and to capture voice, as sound waves can produce tiny vibrations.
Your hard disk drive (HDD) noise can be captured to steal sensitive data
Now that we’ve learned about side channel attacks, there is a type of attack called DiskFiltration developed by a group of Israeli researchers that can capture sensitive data from the sound of a hard disk drive working. This type of attack is sophisticated and aims at devices with an air gap. With air gapped devices, a device is not connected to any network like the internet and is usually kept at sensitive facilities. Air gapped devices are not necessarily immune to cyber attacks. A classical example of these attacks is Stuxnet which targeted Iranian nuclear systems that were all air gapped.
In this type of attack, an attacker infects the device with malware that changes how the device operates. The malware can be introduced to the system by an intruder or through other methods. The device is air gapped, so the malware can’t send anything outside. However, it makes the device operate in a certain way so that the drive arm moves in certain patterns. A nearby smartphone or device that is not air gapped can be used to capture the sound of the hard disk drive to decode it back to data while it is written or read on disk effectively removing the air gap.
Your computer fan can compromise your data
You have an SSD on your system and don’t use a cheap and noisy HDD. So if your device is air gapped, then sensitive data cannot be exfiltrated. Well! Another group of Israeli researchers invented a method for you. Although your SSD doesn’t have an arm to rotate to make noise like with an HDD, your computer fan can be used to capture sound to compromise sensitive data from your air gapped computer. In this type of attack, malware first infects the air gapped system (perhaps by an intruder to a secured facility), then the speed of the cooling fan will be changed in certain patterns. The sound can transmit the data to a nearby listening device.
WiFi signals can see through your walls
WiFi signals bounce off humans in a room. Researchers can see through walls to know how many people are in the room and identify individuals by movement and posture without needing any camera.
포스트 면책 조항
견해, 정보, 또는 표현된 의견은 전적으로 작성자의 개인 의견이며, 반드시 작성자의 고용주 또는 그가 속한 조직의 의견을 나타내는 것은 아닙니다..
이 게시물에 포함된 정보는 일반적인 정보 제공 목적으로만 사용됩니다.. The information is provided by Farhad Mofidi and while he strives to keep the information current and accurate, he does not make any representations or warranties of any kind, express or implied, regarding the completeness, accuracy, reliability, suitability or availability of the website. Farhad makes no representations or warranties. or any information, 어떤 목적을 위한 게시물에 포함된 제품 또는 관련 그래픽.
또한, AI는 제안을 제공하고 일부 내용이나 문장을 개선하는 도구로 사용될 수 있다. 아이디어, 생각, 의견, 최종 제품은 원본이며 저자가 만든 인간 제작물입니다.