Live data from Hacker News

Scientist-developed malware covertly jumps air gaps using inaudible sound

arstechnica.com

51–60 of 60 posts

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#51
post #35

Earlier quoted context omitted.

It's surprising how many people either forget about modems or never had internet in the days of modems. I've had numerous nerdy conversations and theory crafting scenarios where someone will bring up the crazy idea of using sound to transmit data. I'm just like "Yeah, we've done that already. Remember dialup?".

> It's surprising how many people either forget about modems or never had internet in the days of modems. Pardon the snark, but what is surprising about that? Every person with access to the internet born since about 1997* will have no memory of using dialup. The ratio of people who used dialup relative to the people on the internet is going to continue to dwindle rapidly from here on out. Even then, I probably spent…

Yeah situations I've described. I didn't really give much background information.

IE: I was having a conversation with some techie friends back when the SOPA scare was still at its peak. We were discussing purely hypothetical doomsday scenarios that would involve a "darknet" and the technical implications of creating an entirely subversive network. The idea was brought up that we could use our existing telephone infrastructure to send data, and only a way to transfer data via sound would need to be developed. This was shared amongst a few of the participants until I piped up and said "you know dialup has done this already, right? The information is already there."

This is a conversation amongst people who are involved with and passionate about technology and are around my age or older. These are the kinds of people that I'd expect, if not to think of specifics right away, but to at least be lead to something that was as pervasive as dialup. True, I don't expect an 18y/o of today to know or think about it, or even a 20y/o, but a 25+ hacker, developer, or general tech geek? I'm just surprised at how many in that former category just don't remember it.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#52
post #14

"Using nothing more than the built-in microphones and speakers of standard computers..." Are mics common on desktops? I would like to think I'm not that out of touch. I get that in laptops they are common. Still pretty cool. There could be an application for this that isn't malicious.

A little while back, somebody a cool demo of ultrasonic networking (using HTML5 Web Audio!) http://smus.com/ultrasonic-networking/

https://news.ycombinator.com/item?id=6181627 (3 months ago)

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#53
post #35

Earlier quoted context omitted.

20 bits = 2 and a half bytes, and you are right that is enough. What surprises me is how people regarding this as "novel" not too long ago quite a few people used a "modem". That was a mythical device that used phone networks to transmit information. Regular phones would pick up that as sound. Sure there are few technical hurdles - covert communication and stringent error correction are most visible, but concepts are…

It's surprising how many people either forget about modems or never had internet in the days of modems. I've had numerous nerdy conversations and theory crafting scenarios where someone will bring up the crazy idea of using sound to transmit data. I'm just like "Yeah, we've done that already. Remember dialup?".

Acoustic modems were obsolete by 1980.

Smartmodems of the 1980s didn't use sound to transmit data, they modulated an electrical signal directly on the line. They were silent (except during call set up, but that was just a "Monster Rancher" to confirm set up was proceeding in the normal way)

Telephone handsets used data to transmit sound.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#54
post #2

Note that using ultrasound as a communication mechanism, which is what's being described here, is very different from using it as an infection vector .

In other words, the "target" computer has to be actively listening?

Imagine a world in which Google Glass other speech activated devices are the norm. A virus like this could potentially spread from person to person as they passed each other in the street, without anyone knowing, if it exploited a bug in the speech recognition tech. It's not interesting if it relies on the other computer already being infected, but exploits in image/sound parsing are not uncommon and could be combined with this. Another cool hack would be a physical real-world shape/pattern which exploited the image recognition software in something like glass to take over the device.

It's an interesting idea I think, which will have more applications in the future than it does now as more computers start to be always on, listening and watching, but mostly because audio or video is not an infection vector we take seriously yet in the same way that we do network infection.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#55
post #53
post #35

Earlier quoted context omitted.

It's surprising how many people either forget about modems or never had internet in the days of modems. I've had numerous nerdy conversations and theory crafting scenarios where someone will bring up the crazy idea of using sound to transmit data. I'm just like "Yeah, we've done that already. Remember dialup?".

Acoustic modems were obsolete by 1980. Smartmodems of the 1980s didn't use sound to transmit data, they modulated an electrical signal directly on the line. They were silent (except during call set up, but that was just a "Monster Rancher" to confirm set up was proceeding in the normal way) Telephone handsets used data to transmit sound.

ATm3 would leave the speaker on for the duration of the call.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#56
post #35

Earlier quoted context omitted.

It's surprising how many people either forget about modems or never had internet in the days of modems. I've had numerous nerdy conversations and theory crafting scenarios where someone will bring up the crazy idea of using sound to transmit data. I'm just like "Yeah, we've done that already. Remember dialup?".

Also, modems didn't really seem very different from ethernet. My initial reaction as an early adolescent to first encountering ethernet was along the lines of, "oh, so it's just a wider port? what's all the fuss about?" Besides all the funny noises on connection (which, as an aside - why did the handshake have to actually be audible?), everything seemed to work the same, just more slowly. You don't have to forget abo…

Generally the handshake was audible so that you could tell if someone was already on the phone when you started connecting, or if someone answered the phone instead of a computer.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#57

Earlier quoted context omitted.

In other words, the "target" computer has to be actively listening?

Imagine a world in which Google Glass other speech activated devices are the norm. A virus like this could potentially spread from person to person as they passed each other in the street, without anyone knowing, if it exploited a bug in the speech recognition tech. It's not interesting if it relies on the other computer already being infected, but exploits in image/sound parsing are not uncommon and could be combine…

> if it exploited a bug in the speech recognition tech.

That would be one hell of an exploit.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#58
post #56

Earlier quoted context omitted.

Also, modems didn't really seem very different from ethernet. My initial reaction as an early adolescent to first encountering ethernet was along the lines of, "oh, so it's just a wider port? what's all the fuss about?" Besides all the funny noises on connection (which, as an aside - why did the handshake have to actually be audible?), everything seemed to work the same, just more slowly. You don't have to forget abo…

Generally the handshake was audible so that you could tell if someone was already on the phone when you started connecting, or if someone answered the phone instead of a computer.

Interesting! Thanks for that.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#59
post #7

What else would you exfiltrate/steal besides passphrases and private keys? Serial numbers/IPs/hostnames of any discovered devices on the air-gapped network? Send to the airgapped computer(s) software updates and new commands to run? 20 bytes per second is enough for that, or is it bits? A shellcode is about 40bytes or less. I guess if you want to guard against this the reasonable thing to do would be to physically ta…

You could also broadcast noise in those frequencies at a loud enough volume to block any signal.

True. I tried that last month, it works.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#60
post #53
post #35

Earlier quoted context omitted.

It's surprising how many people either forget about modems or never had internet in the days of modems. I've had numerous nerdy conversations and theory crafting scenarios where someone will bring up the crazy idea of using sound to transmit data. I'm just like "Yeah, we've done that already. Remember dialup?".

Acoustic modems were obsolete by 1980. Smartmodems of the 1980s didn't use sound to transmit data, they modulated an electrical signal directly on the line. They were silent (except during call set up, but that was just a "Monster Rancher" to confirm set up was proceeding in the normal way) Telephone handsets used data to transmit sound.

[deleted]
Post reply on HN