Live data from Hacker News

Scientist-developed malware covertly jumps air gaps using inaudible sound

arstechnica.com

21–30 of 60 posts

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#22
post #19

So how would this tolerate an environment with lots of white-noise generators?

Given the amazing array of ways to slice and dice audio signals, that would be a very dangerous security measure to depend on. Better to just clip wires on the microphones and speakers.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#23
post #16
post #10

Keep your headphones plugged in. BAM! Solved!

This just shows my ignorance with regard to this topic, but is the speaker cutoff from plugging in headphones always a hardware switch? I.e., can software override it and direct sound to the speakers even if one has headphones plugged in? Of course, if one were playing music or something, it would be obvious that the switch had been circumvented.

On one computer I owned, it was entirely in the audio driver -- so when I switched to Linux, I was surprised to see that the headphones and speaker had independently controls for volume levels. (The latter was labelled "Mono Out", and the behaviour where plugging in headphones cut off speakers didn't happen on that Linux install.)

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#24
post #16
post #10

Keep your headphones plugged in. BAM! Solved!

This just shows my ignorance with regard to this topic, but is the speaker cutoff from plugging in headphones always a hardware switch? I.e., can software override it and direct sound to the speakers even if one has headphones plugged in? Of course, if one were playing music or something, it would be obvious that the switch had been circumvented.

No, on my current mac there is a delay of one or two seconds between when the plug is fully inserted and the speakers/headphones start working. Thus, i presume it is some silicon or software.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#25
post #18

Earlier quoted context omitted.

That's how it seems to me. But a well-hidden bit of malware won't have a problem turning on the mic for a few seconds on the hour every hour to listen for a handshake chirp or the like. It's a limitation, but far from an insurmountable one.

yea but then the malware has to already be present on both machines, eh?...

It's still a pretty neat trick, if you want malware designed to penetrate an airgapped network to phone home.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#26
post #16
post #10

Keep your headphones plugged in. BAM! Solved!

This just shows my ignorance with regard to this topic, but is the speaker cutoff from plugging in headphones always a hardware switch? I.e., can software override it and direct sound to the speakers even if one has headphones plugged in? Of course, if one were playing music or something, it would be obvious that the switch had been circumvented.

No, it's not always hardware, things are shifting over to software switching over the past few years. One way to bypass this completely is to short your microphone input, or make a feedback loop between mic/headphone jack (this hurts just thinking about it, but should work.)

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#27
post #20
post #16

Earlier quoted context omitted.

This just shows my ignorance with regard to this topic, but is the speaker cutoff from plugging in headphones always a hardware switch? I.e., can software override it and direct sound to the speakers even if one has headphones plugged in? Of course, if one were playing music or something, it would be obvious that the switch had been circumvented.

I honestly have no idea. My response was meant to be tongue-in-cheek, but whoever downvoted me seems to have missed my subtle sense of humor.

They may have gotten it, but thought it was not funny.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#28
post #16
post #10

Keep your headphones plugged in. BAM! Solved!

This just shows my ignorance with regard to this topic, but is the speaker cutoff from plugging in headphones always a hardware switch? I.e., can software override it and direct sound to the speakers even if one has headphones plugged in? Of course, if one were playing music or something, it would be obvious that the switch had been circumvented.

I have seen this behavior both controlled by an extra mechanical pin in the audio jack and also by a feature on the audio chip which was ultimately controlled in software. So it's hard to tell whether that would work.

Also consider that if you played the sound at maximum volume it might actually be audible some distance away from the headphones.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#30
post #8

Earlier quoted context omitted.

In other words, the "target" computer has to be actively listening?

Yes. To call this result "unsurprising" would dignify it unduly.

Well, "can get useful info through unheard sound on typical hardware at a range of 65 ft" is interesting. Not shocking, and horrifically oversold, but interesting.
Post reply on HN