An Unusual Data-Exfiltration Method: Recovering Data from Hard-Drive Sounds
Modern computer systems are exposed to many data-exfiltration techniques. At the time this note was written, an unusual method had recently been added to them.
For a long time, sensitive information could be obtained with software such as sniffers, spyware, backdoors, trojans and keyloggers. Security software and encryption can mitigate these methods. From what I observed, defense companies also removed network cards from computers to avoid putting confidential data at risk. Network access was prohibited on computers used to develop sensitive projects, removable storage could not be taken into protected areas, and computer cases containing critical data could be physically locked.
There are also unconventional methods that extract information from electronic emissions or even noise. I observed that countermeasures such as Faraday cages were used against some of these channels.
Mordechai Guri, an engineer at a university in Israel, introduced a more unusual data-exfiltration method. According to the demonstration, a mobile application could recover data from the sounds produced by a computer’s hard drive. Exfiltrating data through the sound of partly mechanical hardware was a particularly interesting example.
The note concluded that environments in which confidentiality is critical should consider acoustic isolation or solid-state drives. In a country where national projects had been stolen, this type of channel also deserved attention.




Share on Facebook
Share on LinkedIn
Share on X
C Programming — The if Statement
What Is Mechatronics?
Introduction to Data Structures
The Sound of Sorting Algorithms