An Unusual Data-Exfiltration Method: Recovering Data from Hard-Drive Sounds

An Unusual Data-Exfiltration Method: Recovering Data from Hard-Drive Sounds

A short historical note on acoustic data exfiltration from air-gapped computers through sounds produced by mechanical hard drives.

A mechanical hard drive does more than store logical blocks: head movement, platter rotation, and access order create physical traces that vary with workload. Those traces do not broadcast file contents directly, but under controlled conditions they can become acoustic or vibrational side channels from which activity classes or repeated access phases may be inferred.

Modern computer systems are exposed to many data-exfiltration techniques. At the time this note was written, an unusual method had recently been added to them.

For a long time, sensitive information could be obtained with software such as sniffers, spyware, backdoors, trojans and keyloggers. Security software and encryption can mitigate these methods. From what I observed, defense companies also removed network cards from computers to avoid putting confidential data at risk. Network access was prohibited on computers used to develop sensitive projects, removable storage could not be taken into protected areas, and computer cases containing critical data could be physically locked.

There are also unconventional methods that extract information from electronic emissions or even noise. I observed that countermeasures such as Faraday cages were used against some of these channels.

Mordechai Guri, an engineer at a university in Israel, introduced a more unusual data-exfiltration method. According to the demonstration, a mobile application could recover data from the sounds produced by a computer’s hard drive. Exfiltrating data through the sound of partly mechanical hardware was a particularly interesting example.

The note concluded that environments in which confidentiality is critical should consider acoustic isolation or solid-state drives. In a country where national projects had been stolen, this type of channel also deserved attention.

The original note below also records the security context in which I encountered air-gapped systems, restricted removable media, physically protected cases, and electromagnetic countermeasures. I am retaining that context because it explains why an apparently unusual acoustic channel matters: once ordinary network paths are removed, the threat model shifts toward physical leakage. The engineering claim still has to remain bounded by device model, microphone position, signal-to-noise ratio, repeated observations, and cross-session validation.

References

  • **[1]** Daniel Genkin; Adi Shamir; Eran Tromer. (2014). RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis. Advances in Cryptology - CRYPTO 2014, Springer. doi:10.1007/978-3-662-44371-2_25
QR code for this page