Researchers at the Georgia Institute of Technology are now investigating where these information "leaks" originate so they can help hardware and software designers develop strategies to plug them.
By studying emissions from multiple computers, the researchers have developed a metric for measuring the strength of the leaks - known technically as "side-channel signal" - to help prioritise security efforts.
Also Read
"Even if you have the Internet connection disabled, you are still emanating information that somebody could use to attack your computer or smartphone," said Zajic.
Side-channel emissions can be measured several feet away from an operating computer using a variety of spying methods. Electromagnetic emissions can be received using antennas hidden in a briefcase, for instance.
Acoustic emissions - sounds produced by electronic components such as capacitors - can be picked up by microphones hidden beneath tables, researchers said.
Information on power fluctuations, which can help hackers determine what the computer is doing, can be measured by fake battery chargers plugged into power outlets adjacent to a laptop's power converter.
Some signals can be picked up by a simple AM/FM radio, while others require more sophisticated spectrum analysers.
And computer components such as voltage regulators produce emissions that can carry signals produced elsewhere in the laptop.
As a demonstration, Zajic typed a simulated password on one laptop that was not connected to the Internet.
On the other side of a wall, a colleague using another disconnected laptop read the password as it was being typed by intercepting side-channel signals produced by the first laptop's keyboard software, which had been modified to make the characters easier to identify.
"There is nothing added in the code to raise suspicion," said Milos Prvulovic, an associate professor in the Georgia Tech School of Computer Science.
"It looks like a correct, but not terribly efficient version of normal keyboard driver software. And in several applications, such as normal spell-checking, grammar-checking and display-updating, the existing software is sufficient for a successful attack," said Prvulovic.
Currently, there is no mention in the open literature of hackers using side-channel attacks, but the researchers believe it is only a matter of time before that happens.
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)