Movies and television have thought us absolutely ridiculous computer operations and information theft over the years, but that doesn't mean there aren't people working on unconventional vulnerabilities... so to speak. That said, all arrows point to Ben-Gurion University, an institution known for its unusual attacks against air-gap protected systems. Today it is the turn of "Brightness", a technique that exploits small variations in screen brightness that are invisible to the user but easy for a camera to detect, allowing data exfiltration.
In the past we've seen things like data transfers using computer heat, hard drive sounds, a mobile phone's radio, and even changes in fan speed on a PC.
Brightness: Screen Brightness, a Vulnerability?
As expected, the goal of "Brightness" focuses on air-gap protected systems, without remote connections. The first step is to infect the system in question through a physical medium (say, a USB drive) with malware capable of collecting and processing information. Then, that same malware modifies the monitor brightness (the red component of each pixel, to be more precise) by only 3 percent, thus modulating the data stream. Finally, a security camera, a nearby webcam, or a mobile phone camera records the screen, enabling subsequent content decoding.
https://old.neoteo.com/privacidad-los-auriculares-conectados-tan-peligrosos-las-camaras-sin-tapar/The brightness change is so subtle that the user cannot detect it, but it's a true Christmas tree for modern sensors. Now, "Brightness" may be enough to extract passwords and other vital "tidbits", but no one should expect massive transfers with this. The maximum speed ranges from five to ten bits per second, so a simple ten-kilobyte document would take more than two hours in the best case. Additionally, the researchers offer a simple and effective protection: install a polarized filter on the screen.
Access the study (PDF): Click here
Source: PCMag