Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows

samy kamkar

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

This talk, "Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows," delivered by Samy Kamkar at DEF CON 32, promises to delve into a fascinating and concerning area of physical side-channel attacks. The title itself suggests a sophisticated technique where an attacker could remotely eavesdrop on keystrokes by analyzing the minute vibrations caused by typing, captured by a laser directed at a window or other reflective surface. This method falls under the broader category of acoustic cryptanalysis or optical eavesdropping, leveraging the physical environment to extract sensitive information.

Watch on YouTube

Visual summary for Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows by samy kamkar
Visual summary for Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows by samy kamkar

Key moments

  1. 0:00 Childhood WinNuke 95 incident ignites hacking curiosity
  2. 2:10 Discovering system internals via 'Smashing the Stack for Fun'
  3. 3:15 Core insight: Everything ultimately boils down to energy
  4. 3:30 Clarifying definitions of energy, power, and horsepower
  5. 4:05 USB 2.0 power lines transmit encryption information

Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows

Speakers: samy kamkar

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=R5nMqju6crY

Overview

This talk, "Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows," delivered by Samy Kamkar at DEF CON 32, promises to delve into a fascinating and concerning area of physical side-channel attacks. The title itself suggests a sophisticated technique where an attacker could remotely eavesdrop on keystrokes by analyzing the minute vibrations caused by typing, captured by a laser directed at a window or other reflective surface. This method falls under the broader category of acoustic cryptanalysis or optical eavesdropping, leveraging the physical environment to extract sensitive information.

However, the provided transcript for this talk primarily focuses on the speaker's personal journey into cybersecurity and his foundational philosophy rather than the detailed technical mechanics of optical espionage. It serves as an extended introduction, tracing Kamkar's early experiences with computer vulnerabilities and his evolving understanding of how systems truly operate. While the transcript does not provide the anticipated deep dive into laser technology, signal processing, or keystroke reconstruction, it lays the conceptual groundwork for why such attacks are possible, emphasizing the fundamental principle that "everything boils down to energy." This article will therefore focus on the rich philosophical and foundational context provided in the transcript, linking it to the implied technical subject matter where possible, while acknowledging the absence of specific details regarding the optical espionage technique itself.

The significance of such research, even without the full technical exposition in this segment of the talk, is profound. It highlights the persistent vulnerability of information to physical emanations, challenging traditional security perimeters that focus solely on network or software layers. Understanding these subtle side channels is crucial for both attackers seeking novel exfiltration vectors and defenders striving to build truly resilient systems in an increasingly interconnected and transparent world.

Background

▶ Watch: Childhood WinNuke 95 incident ignites hacking curiosity (0:00)

Samy Kamkar's journey into understanding system vulnerabilities began at a remarkably young age, driven by a personal experience in 1995. At just 10 years old, after his mother had invested significantly in a new computer, Kamkar encountered the then-prevalent Win Nuke 95 vulnerability. While engaging in an Internet Relay Chat (IRC) channel, his computer was abruptly crashed by an unknown individual using a single, malformed, out-of-band network packet. This incident, occurring in an era predating modern endpoint detection and response (EDR) solutions like CrowdStrike, left a lasting impression. The ability of an attacker to compromise his system without any prior knowledge of its configuration or operating environment sparked a deep curiosity: "How do I do that?"

This initial fascination led Kamkar to explore the mechanics behind such exploits. He quickly discovered that WinNuke 95 exploited a flaw in the Windows 95 TCP/IP stack, specifically its handling of out-of-band data (often associated with the Urgent Pointer in TCP segments), leading to a denial-of-service (DoS) condition. When Microsoft subsequently released Windows Service Pack 2, which patched this vulnerability, Kamkar's "magical tool" ceased to function, prompting him to seek a deeper understanding of vulnerability creation rather than just exploitation.

His quest for knowledge led him to Frack, a long-running underground hacking magazine that began in 1985. It was there he encountered the seminal article "Smashing The Stack For Fun And Profit," which profoundly shifted his perspective. This article introduced him to the concept of buffer overflows, a fundamental memory corruption vulnerability. Kamkar explains the simplicity and power of this attack: a basic C program might allocate a fixed amount of memory, say 100 bytes, for user input (e.g., a name). If the program fails to check the length of the input, a user can type more than 100 bytes, causing data to spill over into adjacent memory regions. Crucially, this overflow can overwrite the stack pointer or return address on the program's call stack. By carefully crafting the overflowing input, an attacker can redirect program execution to arbitrary code, often referred to as shellcode, which is embedded within the malicious input itself. This allows for complete compromise of the system with an "extremely simple program."

This discovery cemented Kamkar's understanding that "the way a system works is not how we think it works." He realized that true security and exploitation stemmed from understanding the "ground truth" – the intricate details of CPU architecture, memory management, and the compilation and linking processes that transform high-level C code into executable machine instructions. This low-level understanding became his guiding principle, leading him to a broader philosophical conclusion: "ultimately everything boils down to energy."

Kamkar elaborates on this concept, clarifying that while information is energy, he specifically refers to power in this context. Energy is the capacity to do work, while power is the rate at which that work is done (ee.g., horsepower, defined as lifting 550 pounds one foot in one second, or 542 pounds for metric horsepower). His core assertion is that "if you want to actually move any information around, we must use energy." He posits that "power is data and data is power."

He illustrates this with a practical example involving a USB 2.0 connection. A USB cable has four pins: ground, power, and two differential data lines. While the ground and power lines carry energy, they also carry information. Kamkar explains that if a computer is performing an operation like encryption, the power draw on the 5-volt power rail will fluctuate ever so slightly. These minute variations in voltage, riding on the power rail, are not just incidental byproducts but are information that can be measured and potentially analyzed. This principle—that information leaves a physical energy signature—forms the bedrock of side-channel attacks, including, theoretically, optical espionage.

Key Findings

▶ Watch: Discovering system internals via 'Smashing the Stack for Fun' (2:10)

The provided transcript, while rich in the speaker's personal journey and philosophical underpinnings, does not detail the specific technical findings or results related to "Optical Espionage" itself. It serves as an extended prologue, establishing the speaker's core thesis rather than presenting the attack's methodology or outcomes.

Therefore, the primary "key finding" presented within this segment of the talk is a profound philosophical and practical principle: Information is energy, and energy is information. Samy Kamkar asserts that any movement or processing of information within a system inherently requires and generates energy, and the subtle fluctuations or patterns in this energy can reveal the underlying information. This principle forms the theoretical basis for all physical side-channel attacks.

Kamkar illustrates this finding with the example of a USB 2.0 connection. He highlights that when a computer performs a computationally intensive task like encryption, the demand for power fluctuates. These fluctuations are not confined to the data lines but manifest as measurable variations in the 5-volt power rail itself. He states that the power rail "will actually go up and down just a little bit," and these changes "can be measured." This demonstrates that even seemingly secure operations leave a physical, energetic fingerprint that can be observed and potentially exploited by an adversary. This concept directly underpins the feasibility of attacks like optical espionage, where physical vibrations (a form of kinetic energy) caused by keystrokes are hypothesized to carry information that can be extracted via optical means.

Technical Deep Dive

▶ Watch: Core insight: Everything ultimately boils down to energy (3:15)

As noted, the provided transcript does not offer a technical deep dive into the specifics of "Optical Espionage," such as the type of lasers used, the optical setup, signal processing algorithms, or the methods for reconstructing keystrokes from vibrations. The technical content focuses instead on the foundational vulnerabilities and principles that shaped the speaker's understanding of system insecurity.

The most detailed technical explanation provided is the buffer overflow vulnerability. This class of vulnerability arises from a program attempting to write more data into a fixed-size buffer than it can hold, overwriting adjacent memory locations. Kamkar describes a simple C program that allocates 100 bytes for a user's name. If the program lacks bounds checking, an input exceeding 100 bytes will spill over.

To understand the impact, one must grasp the concept of the program stack. The stack is a region of memory used for local variables, function parameters, and, critically, return addresses. When a function is called, the address of the instruction to return to after the function completes is pushed onto the stack. If a buffer overflow occurs within a function, and the overflowing data overwrites this stored return address, an attacker can supply a new address. This new address can point to a malicious payload, known as shellcode, which the attacker has also injected into memory (often as part of the overflowing buffer itself, or in another accessible memory region). When the vulnerable function attempts to return, it will pop the overwritten return address from the stack and jump to the attacker's shellcode, thereby executing arbitrary code on the system with the privileges of the vulnerable program. This detailed explanation of memory layout, stack frames, and the mechanics of redirecting control flow through a overwritten return address is the primary technical deep dive offered in the transcript.

Furthermore, the philosophical "energy is information" concept, while not a technical deep dive into optical espionage, is a crucial technical principle for understanding side-channel attacks. Kamkar distinguishes between energy (the capacity to do work) and power (the rate at which work is done). He emphasizes that any computation or information transfer requires power, and this power consumption is not constant but fluctuates based on the operations being performed. The USB 2.0 example illustrates this:

  • Four pins: Ground, Power (+5V), Data+ (D+), Data- (D-).
  • Energy transfer: Ground and Power lines carry electrical energy.
  • Information leakage: Even if data is encrypted and transmitted over D+/D-, the act of encryption itself causes the CPU and other components to draw varying amounts of power. These variations cause minute fluctuations (up and down) in the nominal 5-volt power rail.
  • Measurability: These subtle voltage changes are measurable. An attacker with access to the power lines (or even electromagnetic emanations from them) could potentially analyze these fluctuations to infer information about the ongoing cryptographic operations, possibly leading to key recovery. This concept extends to physical vibrations, electromagnetic radiation, acoustic emissions, and thermal changes – all forms of energy that can carry information about a system's internal state.

While the specific technical implementation of leveraging these principles for "Optical Espionage" is not described, the groundwork is firmly laid. The implication is that typing on a keyboard creates subtle acoustic vibrations in the keyboard itself, which then travel through the desk, the air, and ultimately cause a window pane to vibrate minutely. If these vibrations are measurable via a laser reflected off the window, and if these vibrations are distinct enough for different keys, then the information (keystrokes) could theoretically be extracted.

Demo / Proof of Concept

▶ Watch: Clarifying definitions of energy, power, and horsepower (3:30)

The provided transcript does not describe a live demonstration or proof of concept specifically for the "Optical Espionage" technique. The speaker's narrative focuses on the foundational experiences and principles that led to his research philosophy, rather than showcasing the specific attack described in the talk's title.

However, the talk does implicitly refer to two historical "proofs of concept" that shaped the speaker's understanding of system vulnerabilities:

  1. Win Nuke 95: Kamkar's initial encounter with hacking involved a remote denial-of-service attack against his Windows 95 computer. This served as a personal, impactful demonstration of how a single, malformed, out-of-band network packet could crash an entire operating system. While not a demonstration performed by Kamkar, it was the "demo" that inspired his journey.
  2. Buffer Overflow: The explanation of a simple C program demonstrating a buffer overflow serves as a conceptual proof of concept. Kamkar details how overwriting 100 bytes of allocated memory can lead to the manipulation of the stack pointer and the execution of arbitrary shellcode. Although this was described theoretically rather than practically demonstrated in the transcript, it highlights a classic and potent method for achieving arbitrary code execution, which was a fundamental lesson for the speaker.

The absence of a specific optical espionage demo in the transcript means this section cannot detail the setup, tools, or success rates of such an attack.

Defensive Implications

▶ Watch: USB 2.0 power lines transmit encryption information (4:05)

Given that the transcript primarily covers the speaker's foundational journey and philosophy rather than the specifics of optical espionage, the defensive implications directly related to laser-based keystroke interception are not detailed. However, the overarching principles discussed by Samy Kamkar offer broad and vital insights for defenders.

Firstly, the core principle that "everything boils down to energy" and that "power is data and data is power" underscores the critical importance of considering side-channel attacks. Defenders often focus on network perimeter security, software vulnerabilities, and cryptographic strength. However, Kamkar's philosophy highlights that information leaks can occur through any physical manifestation of computation or human interaction. This means organizations must broaden their threat models to include:

  • Acoustic Eavesdropping: Any sound generated by computing devices or human interaction (e.g., keystrokes, printer noises, CPU whine) can potentially be analyzed to infer data.
  • Electromagnetic (EM) Eavesdropping: Devices emit EM radiation, which can be intercepted and analyzed to reconstruct screen content, keystrokes, or cryptographic operations (a field known as TEMPEST).
  • Power Analysis Attacks: As illustrated by the USB 2.0 example, minute fluctuations in power consumption can reveal sensitive information, particularly during cryptographic operations. Defenses include designing hardware with constant power consumption profiles, using noise injection, or employing specific cryptographic algorithms resistant to power analysis.
  • Optical Side Channels: The very title of the talk, "Optical Espionage," points to the vulnerability of physical vibrations (e.g., from typing) being detected and analyzed remotely via lasers. This implies a need for physical security measures beyond visual obstructions.

For the buffer overflow vulnerability, which Kamkar details as a pivotal learning experience, defensive measures have evolved significantly since the WinNuke 95 era:

  • Memory Safe Languages: Using languages like Rust, Go, or modern C++ practices (e.g., smart pointers, bounds-checked containers) that prevent direct memory manipulation can eliminate many buffer overflow vulnerabilities.
  • Compiler-Based Protections: Compilers now offer features like stack canaries (a sentinel value placed on the stack to detect overflows before they overwrite the return address), Data Execution Prevention (DEP) or No-Execute (NX) bit (marking memory regions as non-executable to prevent shellcode execution from data segments), and Address Space Layout Randomization (ASLR) (randomizing memory addresses to make it harder for attackers to predict the location of shellcode or return addresses).
  • Secure Coding Practices: Developers must be educated on secure coding principles, including rigorous input validation, bounds checking for all user-supplied data, and careful memory management.
  • Exploit Mitigations: Operating systems and runtime environments implement various exploit mitigations that make buffer overflow exploitation more challenging, though not impossible.

In the context of optical espionage, specific defensive implications, though not in the transcript, would logically include:

  • Physical Security: Obscuring windows with curtains, blinds, or specialized glass that scatters light effectively.
  • Noise Generation: Introducing random, low-frequency vibrations or acoustic noise to mask typing sounds.
  • Keyboard Design: Exploring keyboard designs that minimize physical vibrations or produce uniform vibrations across all keys.
  • Situational Awareness: Educating personnel about the potential for remote optical eavesdropping and encouraging secure typing practices (e.g., typing away from windows).

Ultimately, Kamkar's initial narrative serves as a powerful reminder that attackers will always seek the "ground truth" of how systems work, exploiting any available channel—whether network packets, memory corruption, or subtle energy emanations—to achieve their objectives. Defenders must adopt a similarly holistic and low-level understanding to anticipate and mitigate these diverse threats.

Key Takeaways

  • Early Hacking as a Catalyst: Samy Kamkar's journey into cybersecurity was sparked by a childhood encounter with the Win Nuke 95 vulnerability, demonstrating how a single network packet could crash a system, igniting his curiosity about fundamental system mechanics.
  • The Power of Low-Level Understanding: Learning about buffer overflows from Frack magazine's "Smashing the Stack for Fun and Profit" taught Kamkar that understanding CPU architecture, memory management, and compilation processes is essential to truly comprehending and exploiting system vulnerabilities.
  • Energy as the Ultimate Information Carrier: A core philosophical and technical principle is that "everything boils down to energy," and specifically, "power is data and data is power." Any information processing or transfer necessitates and creates measurable energy fluctuations.
  • Side Channels Exploit Physical Manifestations: The USB 2.0 power rail example illustrates that even encrypted operations leave subtle energy signatures (e.g., 5-volt fluctuations during encryption) that can be measured and exploited, forming the basis of physical side-channel attacks.
  • Beyond Surface-Level Security: The talk implicitly argues that security must extend beyond traditional network and software layers to account for physical emanations. Understanding how systems actually work, rather than how we think they work, is crucial for both offense and defense.
  • Continuous Learning and Experimentation: Kamkar's narrative highlights a career built on self-directed learning, reading seminal papers, watching videos, and "just testing things" to uncover the "ground truth" of technology.

About the Speaker(s)

Samy Kamkar is a renowned security researcher and hacker known for his innovative and often audacious projects that expose vulnerabilities in everyday technology. His talk, "Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows," is a testament to his focus on unconventional attack vectors. As revealed in the transcript, Kamkar's passion for understanding how systems truly work was ignited at the age of 10 when his brand-new Windows 95 computer was crashed by a Win Nuke 95 attack. This experience, coupled with his self-taught journey through resources like Frack magazine and its explanation of buffer overflows, instilled in him a foundational philosophy: that all information ultimately manifests as energy, and by understanding these energy fluctuations, one can uncover hidden data. His work consistently challenges conventional security paradigms by demonstrating how seemingly innocuous physical properties can be exploited for significant information leakage.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

This transcript, presented as a talk on "Optical Espionage," is an extended and unnecessary introduction detailing the speaker's personal journey and foundational principles like buffer overflows and the concept of energy as information. While the speaker's credibility is undeniable and the underlying principles are vital, the talk fails to deliver any substantive technical detail on the promised laser-based keystroke interception, making it a significant bait-and-switch for a DEF CON audience expecting novel research.

Heather Calloway (CISO) — STRONG ACCEPT

While the talk, titled "Optical Espionage," primarily served as an extended philosophical introduction rather than a detailed technical deep dive into laser-based keystroke interception, it delivered a profoundly important message for security leaders: "power is data and data is power." Samy Kamkar's narrative, rooted in fundamental vulnerabilities like buffer overflows, effectively reinforced the critical insight that all information processing leaves an energy signature. This foundational principle is essential for expanding our understanding of side-channel attacks and developing robust, holistic risk models, even if the specific operational guidance for the promised attack vector was…

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage