Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 17 submissions in the queue.
posted by janrinok on Tuesday July 28 2015, @08:05PM   Printer-friendly
from the make-that-rule-"NO-phones" dept.

The most sensitive work environments, like nuclear power plants, demand the strictest security. Usually this is achieved by air-gapping computers from the Internet and preventing workers from inserting USB sticks into computers. When the work is classified or involves sensitive trade secrets, companies often also institute strict rules against bringing smartphones into the workspace, as these could easily be turned into unwitting listening devices.

But researchers in Israel have devised a new method for stealing data that bypasses all of these protections—using the GSM network, electromagnetic waves and a basic low-end mobile phone. The researchers are calling the finding a "breakthrough" in extracting data from air-gapped systems and say it serves as a warning to defense companies and others that they need to immediately "change their security guidelines and prohibit employees and visitors from bringing devices capable of intercepting RF signals," says Yuval Elovici, director of the Cyber Security Research Center at Ben-Gurion University of the Negev, where the research was done.

The attack requires both the targeted computer and the mobile phone to have malware installed on them, but once this is done the attack exploits the natural capabilities of each device to exfiltrate data. Computers, for example, naturally emit electromagnetic radiation during their normal operation, and cell phones by their nature are "agile receivers" of such signals. These two factors combined create an "invitation for attackers seeking to exfiltrate data over a covert channel," the researchers write in a paper about their findings.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 1) by mechanicjay on Tuesday July 28 2015, @09:12PM

    On second thought, perhaps the skepticism as the real-world application of security cracking coming out of Israel isn't the point.

    Conspiracy Theorist Mode: on

    Perhaps the point is that they're really going for it....these are the artifacts of research that are getting published -- what's just getting funneled right to the Intelligence Agencies? Is Israel a stealth player in the Gloabal Cyberwar? Is this their method of public dick waggling, telling the world, "All your base are belong to us?"

    CTM: off

    Regardless of how much fun the above is, there's some interesting security stuff going on there which we should probably all be keeping tabs on.

    --
    My VMS box beat up your Windows box.