Live data from Hacker News

Novel Attack Technique Uses Smart Light Bulbs to Steal Data

bleepingcomputer.com

21–30 of 41 posts

Re: Novel Attack Technique Uses Smart Light Bulbs to Steal Data

#25
post #10
post #7

> Light bulbs need to support infrared lighting and should not require authorization for controlling them over the local network. Moreover, the adversary needs to plant malware that encodes private data from the target device and sends it to the smart light bulbs. If you've already exploited the target device, why not just send private data to the attacker's servers instead? This has to be one of the most convoluted…

To exfiltrate data from a network not connected to the internet. Drop USB drive in parking lot to get malware inside the network. Use a signaling mechanism like this one to get data out.

Heck, drop a smart bulb in the parking lot...

Re: Novel Attack Technique Uses Smart Light Bulbs to Steal Data

#26

Earlier quoted context omitted.

I'm talking about their "Deducing victim's music and video tastes" section. The data exfiltratiom part is after that, titled "Data exfiltration from personal devices", which yes, is a new means of transmitting data. Under the assumptions that there's no authentication to control the lights and that they have malware running on your computer already. But my point is that the whole first section is absurd. Leaking what…

Honestly, you're just being argumentative. The researchers haven't proposed that they've backdoored your computer, but historically every impressive hacking feat is built on a stack of "obvious in hind-sight" novel abuses. Instead of writing it off as Rube Goldberg over-engineering, it would be a lot more useful (and fun) to consider what these sort of attacks could do in less obvious conditions. The people who put t…

>Instead of writing it off as Rube Goldberg over-engineering, it would be a lot more useful (and fun) to consider what these sort of attacks could do in less obvious conditions.

Having slept on it, I still can't come up with a situation where the "average screen color" mode reveals anything that wasn't already public with higher fidelity.

Maybe you can help me out?

Re: Novel Attack Technique Uses Smart Light Bulbs to Steal Data

#27
post #10

Earlier quoted context omitted.

To exfiltrate data from a network not connected to the internet. Drop USB drive in parking lot to get malware inside the network. Use a signaling mechanism like this one to get data out.

Heck, drop a smart bulb in the parking lot...

This might sound too obvious to work but I know a non-zero number of people who picked up lightbulbs and plugged them in at home.

Re: Novel Attack Technique Uses Smart Light Bulbs to Steal Data

#28

Earlier quoted context omitted.

I'm talking about their "Deducing victim's music and video tastes" section. The data exfiltratiom part is after that, titled "Data exfiltration from personal devices", which yes, is a new means of transmitting data. Under the assumptions that there's no authentication to control the lights and that they have malware running on your computer already. But my point is that the whole first section is absurd. Leaking what…

For remote surveillance, you can use a laser microphone up to 4-500 meters away from the target house. No hardware or software in the house required.

With a $20 dongle you can perform TEMPEST attacks on the display itself.

https://www.rtl-sdr.com/tempestsdr-a-sdr-tool-for-eavesdropp...

Post reply on HN