272
3 Hardware Trojans in Electronic Devices
The main offender was a small chip additionally installed in the devices. The user
only needs to plug appliances with such hardware in, and they will be able to freely
connect to any unprotected computers within 200 m radius via Wi-Fi.
According to Innokenty Fedorov, CEO of the importing company, he did not
expect such a surprise from his Chinese colleagues: “This is a trusted location,
and the fact that this story happened was very strange. It happened only recently;
something started going on, and we tried to find the reason.”
A brokerage office helped the entrepreneurs discover the spyware-infected counterfeit. Even before shipment of equipment from China, the Russian specialists were
alarmed by the weight of packages that was just a few grams different from the value
stated in documentation. The batch was stopped at the border, and the experts started
studying the electronics. As a result, it appeared that built-in Trojans were designed
for mailing of spam and computer viruses.
The user will not even notice that the iron is sending something. No system
administrator can notice such attack, since it comes not from the outside via the
Internet, but from the inside.
About 30 irons, kettles, phones, and even drive cams from the test batch still ended
up in network stores of Saint Petersburg; no one can say exactly how many electronic
devices with spy chips were among those appliances. This multi-purpose equipment
could be delivered to other regions of Russia. Here, we leave out the logical question:
who and why would inject such Trojans into household appliances? [26–28] One of
the answers is perhaps the fact that if all “irons” are switched off by synchronous
command of the intruder, mobile communication within a radius of several kilometers
will be impaired?
In general, it should be noted that all so-called household appliances today are
capable of performing functions that are completely unexpected for their owners.
Let us take, for example, highly popular smartwatches and fitness bands.
So, a group of American researchers [29] has developed an algorithm that uses
readings from sensors of a smartwatch or a fitness tracker to accurately determine a
password or a PIN code entered with the help of keyboard.
Within the framework of the experiment conducted by the researchers, 20 volunteers wore smartwatches LG W150, Moto 360, and a separate motion tracking device
MPU-9150. The volunteers entered PIN codes using ATM keyboards, while the
researchers recorded the readings of device sensors indicating movement of hands
pressing the buttons.
The most difficult task was to measure the distance of hand movement between
keys, which was determined using the acceleration gauge. However, during the study,
the authors managed to achieve 80% precision of determining the input password
based solely on the readings from the device sensors.
Specialists believe that manufacturers of such gadgets can add special noise to
sensor readings in order to combat data leakage. Users of smartwatches and fitness
bands are advised to make extra movements when entering the PIN code in order
to prevent intruders from using the algorithm. These smart recommendations will
clearly be ignored by most users.
In conclusion, we shall mention the vulnerability of smart houses to cyberattacks.
Précédent

- 292/839

Suivant