[LINK] Interesting security risk
Chirgwin, Richard
Richard.Chirgwin@informa.com.au
Thu, 7 Mar 2002 11:07:50 +1000
http://applied-math.org/optical_tempest.pdf
To save Linkers the big PDF: some researchers have demonstrated the ability
to extract "live" data from status LEDs on various types of equipment,
including modems, LAN switches, and Cisco 4000 and 7000 routers.
The LEDs flash far faster than the eye's persistence of vision, so nobody
has given thought to whether the flash could be extracted by an optical
detector. Many designs wire the status LEDs in series with the data path for
simplicity. The theoretical "reach" of the authors' work is up to 10M bps.
In cases such as network equipment (the routers), the risk applies to the
serial interfaces, but those are often used (for eg) to connect a router to
telecomms CPE.
Interesting, anyhow!
Richard Chirgwin