Author Topic: Acoustic cryptanalysis may make 4096-bit RSA keys vulnerable  (Read 1122 times)

0 Members and 1 Guest are viewing this topic.

Offline Ironchew

  • Official Edgelord
  • The Beast
  • *****
  • Posts: 1888
  • Gender: Male
  • The calm, intellectual Trotsky-like Trotskyist
Acoustic cryptanalysis may make 4096-bit RSA keys vulnerable
« on: December 19, 2013, 01:19:11 pm »
RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis

The attack has to be near the physical space of the decrypting-device to work, but apparently just about any device with a microphone is good enough.

Quote
The attack can extract full 4096-bit RSA decryption keys from laptop computers (of various models), within an hour, using the sound generated by the computer during the decryption of some chosen ciphertexts. We experimentally demonstrate that such attacks can be carried out, using either a plain mobile phone placed next to the computer, or a more sensitive microphone placed 4 meters away.

...

  • In almost all machines, it is possible to distinguish an idle CPU (x86 "HLT") from a busy CPU.
  • On many machines, it is moreover possible to distinguish different patterns of CPU operations and different programs.
  • Focusing on GnuPG as a study case, on some machines we can:
            distinguish between the acoustic signature of different RSA secret keys (signing or decryption), and
            fully extract decryption keys, by measuring the sound the machine makes during decryption of chosen ciphertexts.


The rule of extreme paranoia still seems to apply here: Don't let anyone you don't completely trust anywhere near your machine, and this attack won't work.
Consumption is not a politically combative act — refraining from consumption even less so.

Offline The Illusive Man

  • The Beast
  • *****
  • Posts: 869
  • Gender: Male
  • Saw the ME3 endings, got turned into a husk. :(-
Re: Acoustic cryptanalysis may make 4096-bit RSA keys vulnerable
« Reply #1 on: January 04, 2014, 03:24:46 pm »
Oh goody now people can get RAM burglared without connecting an external device.
Despite knowing about indoctrination I thought it was a good idea to put a human Reaper near my office. Now I am a sentient husk :(.

*RRRRRRRRRRAAAAAAAAAAAAAAAAAWWWWWWWWWWWWRRRRRRRRR* *SCREECH* *smokes*