Skip to content

Comment on RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis

Comments

The single coolest thing in the paper (other than Shamir's name): "On many laptops (e.g., most Lenovo ThinkPad models), the chassis potential can be easily reached by a human hand, through metal connectors and conductive coating on metal surfaces. Thus, an attacker can measure the chassis potential by merely touching the laptop chassis with his hand. Surreptitiously, the attacker can simultaneously measure his own body potential relative to the room’s ground potential, e.g., by having a concealed differential probe touching both his body and some nearby conductive grounded surface in the room. Perhaps surprisingly, even this circuitous measurement offers sufficient signal-to-noise ratio for the key extraction attack."

I wonder whether this is specific to laptops (running from battery or otherwise not grounded) or if it also works with properly grounded desktop computers.

My HP notebook from ~2000 had measurable (although very high impedance) 110V AC between exposed metal parts and PE in wall outlet when connected to charger. Modern thinkpads (and probably all non-Apple laptops sold in Europe) does not seem to have this problem as ground is connected through in charger, not only AC coupled to both hot and neutral.

Macbooks can be grounded, too. The round metal thing that's holding the plug in place also serves as a connection for ground. It is moot if you're using the small plug which doesn't have ground but if you connect the cable instead of the plug, or use a UK plug, the computer is properly grounded.

I have been finally able to download and read their full paper and it seems to answer this question: they observe that grounding thru AC charger does increase SNR of measured signal.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.