• Thorry84@feddit.nl
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    I’ve read the paper, it’s really very cool. However there is nothing to worry about in real life. They captured thousands of uses of a smartcard and then used statistical analysis to gleen data used to attack a protocol with known vulnerabilities. In another setup they had a phone right up against the power led, using the roller shutter effect to collect a single point of data at really high speed. The whole thing also depends on a shitty power supply with a led in the main path. Most power supplies these days don’t have such a led and if they do it’s not always the case they leak data like this.

    The circumstances that allow this to work aren’t likely to occur in real life. Even if everything is just right, it still requires a way to collect thousands of samples to do the statistical analysis. And then also requires a scheme with known specific vulnerabilities to work.

    Very cool research, but don’t worry about taping off al your power leds for security reasons.