Hacker News new | ask | show | jobs
by wlesieutre 2856 days ago
I'm talking about their "Deducing victim's music and video tastes" section.

The data exfiltratiom part is after that, titled "Data exfiltration from personal devices", which yes, is a new means of transmitting data. Under the assumptions that there's no authentication to control the lights and that they have malware running on your computer already.

But my point is that the whole first section is absurd. Leaking what's on the TV via a light that shows the average color of what's on the TV? It's already on the TV. Stop looking at the light from the lightbulb and look at the TV. If you can't see the TV directly, look at the light from the TV, which is already the same color as what the lightbulb would tell you.

The music part doesn't seem any better. You know what's a good way to figure out what music someone's listening to? A microphone. Granted a light might be visible from farther away, but if someone is running party lights the music is probably not quiet.

2 comments

Honestly, you're just being argumentative. The researchers haven't proposed that they've backdoored your computer, but historically every impressive hacking feat is built on a stack of "obvious in hind-sight" novel abuses.

Instead of writing it off as Rube Goldberg over-engineering, it would be a lot more useful (and fun) to consider what these sort of attacks could do in less obvious conditions.

The people who put the 2600hz tone whistles in the breakfast cereal didn't anticipate Apple computers.

>Instead of writing it off as Rube Goldberg over-engineering, it would be a lot more useful (and fun) to consider what these sort of attacks could do in less obvious conditions.

Having slept on it, I still can't come up with a situation where the "average screen color" mode reveals anything that wasn't already public with higher fidelity.

Maybe you can help me out?

For remote surveillance, you can use a laser microphone up to 4-500 meters away from the target house. No hardware or software in the house required.
With a $20 dongle you can perform TEMPEST attacks on the display itself.

https://www.rtl-sdr.com/tempestsdr-a-sdr-tool-for-eavesdropp...