Extracting information from a computer protected via an "air gap" is the goal of many specialized laboratories around the world. A system without an internet connection and with external devices absent should significantly reduce the risk of leaks, but at Ben-Gurion University they have developed BitWhisper, a technique that uses heat emitted by a PC to inject malicious commands into another nearby system through its temperature sensors.
The Air Gap and Its Weaknesses
Completely isolating a computer from the internet is not limited to intelligence agencies or uranium enrichment platforms. Anyone who decides to take extreme security measures can remove the connection and minimize the use of accessories. However, the overall effectiveness of the air gap is directly linked to that person's behavior. A simple USB drive loaded with the right malware is all it takes to compromise a computer under those conditions, and we must also remember the initiatives of certain groups seeking to 'affect from the factory' the security of a PC. To this we must add unorthodox attacks, such as sound-based attacks and AirHopper created by Ben-Gurion University.
BitWhisper: A Thermal Channel
Today, it is that same university that brings us together again, and the reason is the development of BitWhisper, a communication system based on heat. It is a proof of concept with multiple requirements, but that does not make it any less striking. In essence, BitWhisper transmits data by generating controlled heat spikes in a compromised computer. With just one degree of difference within a pre-established time frame, the second system interprets that extra degree as "1", and when the temperature returns to its normal level in another time frame, it is read as "0". The developers have taken into account critical factors, including the natural temperature fluctuations that any PC goes through, and most importantly, BitWhisper has bidirectional capability, so a compromised system can leak private data and/or receive malicious orders.
For BitWhisper to work correctly, several conditions must be met. First, both systems must be infected with custom malware; the distance between them cannot exceed 40 centimeters (something the university highlights as very common), and the permanence must be long enough, since BitWhisper records about eight bits per hour as transfer speed. The video proves that those eight bits are enough to trigger a toy missile launcher... but it was accelerated 16 times. The university hopes that BitWhisper will stimulate additional research aimed at exploring this thermal channel, with optimizations in speed and distance.