It's not Wi-Fi. The article title is misleading clickbait. They are just using a simple script to exercise the RAM in a way that produces more or less radio noise, and then using a debug feature in an off the shelf Wi-Fi chipset to measure the channel noise and transfer data that way (at an extremely low rate of a few bits per second). At no point are Wi-Fi signals involved. Both sides need to collude to make this work. It only takes a few hours to put together this kind of demo.
He did the same thing with GSM a few years ago - the exact same concept with 800MHz RAM - but he's so bad at it that even though he was using an open source fully documented GSM stack as a base for his receiver (osmocombb), he couldn't get more than a few bits per second out of it, even though you could obviously get a lot more data through with access to the DSP hardware at the receiver like he did.
This guy basically runs a paper mill where every few months he comes up with a new side channel, builds the minimum viable PoC, and produces no research of value. He makes no attempt to measure theoretical maximum channel bandwidths, he doesn't optimize the data coding, nothing. He just picks a new random idea, like using screen brightness or network activity LEDs to encode information, and cranks out a paper. And he's really good at clickbaiting his way through news cycles, which I'm sure keeps the funding going.
You can implement a PoC at the same level of some of his papers in a one line shell script that blinks the camera LED on a machine to transfer a file bit by bit:
Comments
Not this one again...
It's not Wi-Fi. The article title is misleading clickbait. They are just using a simple script to exercise the RAM in a way that produces more or less radio noise, and then using a debug feature in an off the shelf Wi-Fi chipset to measure the channel noise and transfer data that way (at an extremely low rate of a few bits per second). At no point are Wi-Fi signals involved. Both sides need to collude to make this work. It only takes a few hours to put together this kind of demo.
He did the same thing with GSM a few years ago - the exact same concept with 800MHz RAM - but he's so bad at it that even though he was using an open source fully documented GSM stack as a base for his receiver (osmocombb), he couldn't get more than a few bits per second out of it, even though you could obviously get a lot more data through with access to the DSP hardware at the receiver like he did.
This guy basically runs a paper mill where every few months he comes up with a new side channel, builds the minimum viable PoC, and produces no research of value. He makes no attempt to measure theoretical maximum channel bandwidths, he doesn't optimize the data coding, nothing. He just picks a new random idea, like using screen brightness or network activity LEDs to encode information, and cranks out a paper. And he's really good at clickbaiting his way through news cycles, which I'm sure keeps the funding going.
You can implement a PoC at the same level of some of his papers in a one line shell script that blinks the camera LED on a machine to transfer a file bit by bit:
https://twitter.com/marcan42/status/1339156243517095936?s=19