- More porn sneaks onto the iPhone
- 'Swatting' case shows need to ban caller-ID spoofing
- Why the iPhone can't be "killed"
- Nortel enterprise chief wants to bring back Bay
- US sets final emergency responder wireless pilot
Researchers say that small devices called "JitterBugs" could piggyback onto network connections to discreetly send passwords and other sensitive data over the Internet.
Like the current keylogger hardware used by the FBI and criminals alike to record passwords and other data, JitterBugs are small devices that attach to a keyboard and record what users type. Unlike current keyloggers, which store the data to internal memory, JitterBugs do not have to be retrieved before captured data can be read.
What do you think? Join our JitterBug discussion.
Although no such device has been found "in the wild" yet, researchers have developed a working prototype, and they postulate that similar ideas may have already been used in unnoticed attacks.
In a paper titled "Keyboards and Covert Channels," University of Pennsylvania grad students explain that the device could encode data in keystrokes by introducing an extra delay between when a key is pressed and when the keyboard tells the computer that the key has been pressed.
In applications such as telnet and remote desktop, a packet is sent every time a user presses a key. By causing calculated "jitters" in keyboard input while such a program is running, a JitterBug could slightly delay data sent over the network. Certain amounts of delay could represent a one or a zero in each packet that is linked to keyboard use, allowing an attacker to send secret information in otherwise innocuous data without modifying software or initiating any new connections.
Although one bit per packet is not a great deal of space, an application like telnet could send enough packets to transmit a password or another small, important piece of data.
To intercept this data, a spy would need to use a packet sniffer to intercept a connection from the target computer. This would require that the attacker have access to a network somewhere between the victim and the victim's destination - not a trivial goal, but probably easier than attaching the JitterBug in the first place.
Even if the connection is encrypted, data encoded in the delays would likely be visible to an attacker. Although additional delays could ruin the careful pattern introduced by the JitterBug, the device has some level of tolerance for this issue.
Comment