Hackers Read Your Screen in Your Eyeglasses, Teapots, and Other Reflective Objects   - 1,236 Views,

Summary: An intriguing and novel eavesdropping technique has been disclosed by a group of German scientists, who describe and demonstrate in their paper "Compromising Reflections, or How to Read LCD Monitors Around the Corner" how your monitor screen can be read from a distance, by pointing a telescope at its content reflected in nearby objects. Teapots, spoons, plastic bottles, glasses and even the surface of the user's eye offer sufficient quality for text on the screen to be intelligible, even at long distance.

Previous Article « MrChimp2007 Ordered to Stop Posting Videos of His Crimes on YouTube
Read Next Article » Google Earth Now Available Through Your Browser - No Download Necessary!

  Follow Anne on Twitter

An intriguing and novel eavesdropping technique has been disclosed by a group of German scientists, who describe and demonstrate in their paper “Compromising Reflections, or How to Read LCD Monitors Around the Corner” (warning: PDF download) how your monitor screen can be read from a distance, by pointing a telescope at its content reflected in nearby objects. Teapots, spoons, plastic bottles, glasses and even the surface of the user’s eye offer sufficient quality for text on the screen to be intelligible, even at long distance.

Many passive techniques have been employed in the past to non-intrusively grab data from computers, all with a very low risk of detection. 30 years ago, cathode-ray tube emissions were being sniffed, and the screen content reconstituted, by those engaged in military and industrial espionage. Shielding the tube and cables helped put a stop to this exploit. Keyloggers, hardware or software, run the risk of being detected, but techniques to analyze the sound of individual key clicks and recover typed content are well-known; an interesting paper is that by Asonov and Agrawal. Indeed, extracting information using acoustic cryptanalysis has even fuelled a TV writer’s fevered imagination.

Michael Backes, Markus Dürmuth, and Dominique Unruh from Saarland University in Saarbrücken, Germany, used an inexpensive camera and telescope, costing together less than $1500 and available off-the-shelf, to view reflected 12-point Word documents from a distance of 10 metres (33 feet). Smaller font text could be viewed from closer distances, with a longer exposure time, or if reflected from a less curved surface, such as a user’s pair of glasses. The 10 metre distance can be extended to over 30 metres (about 100 feet) with a $27,500 telescope.

But never fear, The Internet Patrol has great news for the paranoid. Firstly, you’re likely to notice someone maneuvering a cumbersome 3-feet long telescope and camera combination 15 feet from your coffee shop seat, and so you’re unlikely to be compromised in such a situation. Secondly, if the bad guy is extraordinarily persistent and positions their telescope twice as far from your coffee shop seat, the telescope has to have a diameter twice as large, and this typically means twice as long and likely more than twice as expensive. So for now you’re likely to be safe, indoors and outdoors. At least, you’ll be safe until these three complete their current experiments, in which they’re looking at diffuse reflections from walls or clothes, and reconstituting the image from these. If these experiments are successful, we’ll have to all work indoors with the curtains closed.

Hackers Read Your Screen in Your Eyeglasses, Teapots, and Other Reflective Objects

 Follow Anne on Twitter

 Twitter Explained in Plain English

Previous Article « MrChimp2007 Ordered to Stop Posting Videos of His Crimes on YouTube
Read Next Article » Google Earth Now Available Through Your Browser - No Download Necessary!

Read more:

»  Hackers Co-Opt Comedy Central and Other Websites to Steal User Passwords

»  Netscape Critical Flaws Fixed with This Week’s Netscape 8.0.3.1 Release

»  Hackers, Government Unite to Take Down Terrorist Websites

»  X-Ray Vision System Sees Objects Hidden Under Clothing - The New ThruVision T5000 T-Ray Security Imaging System

For additional similar stories check out our archives on Security

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 6/6/2008
The Internet Patrol
Patrolling the Internet for You!