All your keyboards are belong to us!
Federico Lucifredi (Manager)
DEF CON 33 · Day 1 · Main Stage
Overview
In this comprehensive DEF CON talk, Federico Lucifredi, an experienced embedded engineer and co-founder of an R&D shop, delves into the often-overlooked and repeatedly rediscovered world of keyboard side-channel attacks. The presentation, titled "All your keyboards are belong to us!", meticulously explores how these ubiquitous input devices, which handle plaintext data before it's encrypted or hashed, can be exploited for both data exfiltration and command injection. Lucifredi highlights the critical vulnerability of keyboards across various attack vectors, from historical electromagnetic emanations to modern acoustic analysis leveraging artificial intelligence and even the subtle flickering of LEDs.

Key moments
- 0:00 Introduction to keyboard exploits and classified adjacent material
- 2:00 Historical SIGINT: IBM Selectric and Charles Gandhi's inspiration
- 4:00 Wim Van Eck's $15 CRT signal emission exploit
- 5:48 BBC demonstration of reading CRT data from a van
- 8:00 TEMPEST explained: classified standard and mitigation strategies
All your keyboards are belong to us!
Speakers: Federico Lucifredi, Manager
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=KeNBWILSlC4
Overview
In this comprehensive DEF CON talk, Federico Lucifredi, an experienced embedded engineer and co-founder of an R&D shop, delves into the often-overlooked and repeatedly rediscovered world of keyboard side-channel attacks. The presentation, titled "All your keyboards are belong to us!", meticulously explores how these ubiquitous input devices, which handle plaintext data before it's encrypted or hashed, can be exploited for both data exfiltration and command injection. Lucifredi highlights the critical vulnerability of keyboards across various attack vectors, from historical electromagnetic emanations to modern acoustic analysis leveraging artificial intelligence and even the subtle flickering of LEDs.
The talk serves as a stark reminder that physical and electromagnetic security, often considered archaic in the age of sophisticated network attacks, remains a potent concern, particularly for high-value targets. Lucifredi draws a clear lineage from classified government research dating back to the 1940s to contemporary academic breakthroughs, demonstrating how fundamental principles of signal leakage continue to manifest in new and unexpected ways with modern technology. By showcasing a diverse array of attacks—including those against air-gapped systems and wireless peripherals—he underscores why keyboards are prime targets for adversaries ranging from nation-state actors to determined pentesters.
Lucifredi's presentation is a call to re-evaluate the security posture surrounding input devices, emphasizing that while remote network exploits often take precedence, local side-channel attacks offer a powerful alternative for sophisticated attackers. He skillfully navigates through decades of research, illustrating how seemingly minor physical phenomena can be weaponized to compromise sensitive information, often with surprising ease and range. The talk not only educates on the technical intricacies of these exploits but also stresses the cyclical nature of their discovery and the enduring challenge they pose to information security.
Background
▶ Watch: Introduction to keyboard exploits and classified adjacent material (0:00)
The concept of extracting sensitive information from unintended signal emissions, often colloquially referred to as TEMPEST, forms the bedrock of many keyboard-related side-channel attacks. This phenomenon, known to signal intelligence (SIGINT) professionals since the 1940s, remained classified for decades. Its public unveiling came in 1985 through a paper by Dutch researcher Wim Van Eck, who demonstrated how unshielded CRT monitor emanations could be reconstructed into a visible display from hundreds of meters away using inexpensive equipment (around $15). This "Van Eck Phreaking" exploits frequency components in the UHF band, recreating missing synchronization pulses to display the monitor's content on a standard television. Historical records indicate that Bell Labs discovered similar principles in 1943, and the CIA rediscovered them in 1951, showcasing a recurring pattern of discovery and forgetting within the security community.
Early mitigation strategies for TEMPEST, as outlined in declassified NSA documents, included shielding (e.g., Faraday cages), filtering specific frequencies, and masking by introducing noise. For instance, in the 1950s, the military advised maintaining a 200-foot exclusion zone around teletypes transmitting classified information and even operating multiple teletypes simultaneously to confuse signal collection—a masking technique now understood to be largely ineffective. The declassified TEMPEST code word, made public in 2008, also hinted at signal emanations in other domains, specifically seismic (vibrations) and acoustic (sound).
Beyond electromagnetic leakage, the talk highlights another critical historical vulnerability: acoustic emanations. Electric typewriters and teletypes, which produce significant noise, were found to leak plaintext information. The TEMPEST memo itself suggested that typing sounds could be deciphered from 100 feet away using a shotgun parabolic microphone. Intriguingly, subsequent research over 40 years confirmed that soundproofing a room, contrary to intuition, could aid attackers by dampening background noise more effectively than the main signal, thereby improving the signal-to-noise ratio and extending interception range. This acoustic leakage, quaintly termed "phenomenon number five" by the NSA, underscores the diverse physical channels through which data can escape.
Another foundational concept is red/black separation, a security directive from the NSA. This arose from a 1960s MI5 wiretap operation on the French embassy, where technicians discovered a much weaker plaintext signal alongside the expected encrypted transmission. The issue wasn't a flaw in the French encryption but rather cross-talk—plaintext data leaking from a machine in one room to an adjacent room containing the encrypted data. This incident solidified the need to strictly separate machines handling plaintext ("red") from those handling ciphertext ("black") according to specific wiring and distance rules, many of which remain classified. The Russian equivalent of TEMPEST is ПЭМИН (PEMIN), an acronym for "unwanted electromagnetic radiation and interference," with some declassified Russian documents briefly surfacing around the turn of the millennium before being reclassified. These historical precedents establish a clear context for understanding the sophisticated side-channel attacks possible on modern keyboards.
Key Findings
▶ Watch: Historical SIGINT: IBM Selectric and Charles Gandhi's inspiration (2:00)
The talk uncovers several key findings about the enduring vulnerabilities of keyboards and the ingenious methods adversaries employ to exploit them:
- Keyboards are a Persistent Side-Channel Risk: Despite decades of security advancements, keyboards remain a critical point of leakage for plaintext data due before encryption or hashing. This vulnerability is repeatedly rediscovered across generations and technologies.
- Diverse Attack Vectors: Attacks are not limited to a single modality. Electromagnetic, acoustic, optical, and even physical injection techniques can all be leveraged against keyboards, often in combination.
- Modern AI/ML Enhances Efficacy: Contemporary artificial intelligence and machine learning models significantly improve the accuracy, range, and adaptability of acoustic keyboard attacks, enabling high-fidelity plaintext recovery even from distant or noisy environments.
- Air-Gapped Systems Are Not Immune: Optical side channels, such as blinking LEDs on network devices or even speaker lights, demonstrate that data can be exfiltrated from air-gapped networks, challenging the conventional understanding of air-gap security.
- Non-Privileged Sensors are Exploitable: The use of accelerometers in modern smartphones to detect keyboard vibrations illustrates a novel attack vector that bypasses traditional microphone permissions, making it easier for Trojan horse applications to compromise data without explicit user consent.
- Wireless Peripherals Introduce New Flaws: Wireless keyboards and mice, particularly those with unencrypted communication channels, are susceptible to injection attacks like MouseJack, allowing adversaries to remotely control systems and inject keystrokes in plaintext.
- Fingerprinting Capabilities: Advanced EM analysis, even with off-the-shelf equipment like GNU radio, can not only extract keyboard signals but also fingerprint individual keyboards within a shared environment, defeating basic masking attempts.
- Sophistication Varies: While some attacks require nation-state level resources and expertise, others, like basic acoustic analysis or USB injection tools, are accessible to semi-sophisticated adversaries or even hobbyists, underscoring a broad threat landscape.
- The "Don't Skype and Type" Rule: Acoustic attacks can now be conducted over video conferencing platforms like Zoom, meaning that keystrokes typed during a call can be decoded by other participants, even without direct access to the victim's environment.
Technical Deep Dive
▶ Watch: Wim Van Eck's $15 CRT signal emission exploit (4:00)
The talk provides a detailed exploration of various technical methodologies used to compromise keyboards, spanning decades of research and technological advancements.
Electromagnetic Emanations (TEMPEST & Van Eck Phreaking)
The foundational concept of TEMPEST involves collecting unintended electromagnetic signals. Van Eck Phreaking, a public demonstration of TEMPEST, targeted CRT monitors. These monitors emit radio frequency interference in the UHF band due to their electron beam sweeping across the screen. Van Eck's 1985 attack involved recreating the synchronization pulses of the monitor, which are often missing from the emanations, using a simple $15 circuit. This allowed him to reconstruct the displayed image from up to 1 kilometer away. Historically, NSA mitigation strategies included Faraday cages for shielding, filtering specific frequencies, and masking by introducing noise or maintaining physical distance (e.g., 200 feet). The speaker notes that the Russian equivalent, ПЭМИН (PEMIN), also focuses on unwanted electromagnetic radiation.
Modern EM attacks are not limited to CRTs. A 2008 Swiss team demonstrated the extraction of entire signals from both PS/2 and USB keyboards from distances of 5 to 20 meters using GNU radio (an open-source software toolkit for software-defined radio). A significant finding from this research was the ability to fingerprint different keyboards in the same room, effectively nullifying masking strategies that rely on multiple devices generating noise. This highlights that even low-voltage digital signals from modern peripherals produce exploitable EM leakage.
Optical Side Channels
Optical side channels leverage light emissions for data exfiltration or sensing:
- LED Blinking for Air-Gapped Systems: Research has shown that data can be exfiltrated from air-gapped systems by blinking indicator lights (e.g., Caps Lock LEDs, network activity lights). One study achieved speeds of up to 56 kilobits per second. This concept was even fictionalized in Neal Stephenson's novel Cryptonomicon.
- Optical TEMPEST (Modem LEDs): A 2002 study demonstrated that the flickering of a modem's TX LED (transmit light) could be observed from across a room, and potentially across the street, to decode the data being transmitted. While modems are largely obsolete, this technique proved the viability of optical eavesdropping on data transmission hardware.
- Speaker LED Sensing: More recently, in 2021, a team at Ben-Gurion University of the Negev showed that they could reconstruct sound in a room by analyzing the subtle flickering of speaker lights or even the USB hub lights powering speakers. Using a 10-inch telescope, they achieved this from 25 meters away, demonstrating highly sensitive optical sound reconstruction.
Keystroke Injection and Exfiltration via USB
The Rubber Ducky, a popular pentesting tool, is a USB device disguised as a flash drive but recognized by the operating system as a keyboard. It can inject commands at superhuman speeds. While effective for injection, traditional Rubber Duckies struggled with data exfiltration to their internal storage. This changed with the discovery of keystroke reflection. Historically, IBM delegated the management of Caps Lock, Num Lock, and Scroll Lock states to the host PC to reduce keyboard manufacturing costs. This created a side channel: a Rubber Ducky can now use these three indicator lights to establish a data transfer path, effectively exfiltrating data to its internal storage without needing network connectivity. This technique, highlighted by Lagrian's paper, represents a significant enhancement to USB-based attack tools.
Acoustic Keyboard Attacks
Acoustic attacks exploit the unique sound profile generated by each key press:
- IBM/Argo (2004) - Supervised Learning: This seminal work involved placing a microphone near a keyboard (0.5 to 15 meters) and sampling sound with a standard sound card (44.1 kHz). A neural network (with a few hundred nodes, comparable to early voice recognition systems) was trained to classify key presses.
- Accuracy: Achieved 100% success for distinguishing two keys and 95% for longer samples. For 30 keys, the correct key was guessed 79% of the time, and was among the top three choices 88% of the time.
- Distance and Position: Recognition quality did not decrease up to 15 meters and worked even with the microphone placed behind the typist.
- Keyboard Specificity: A model trained on one keyboard model performed poorly on another, indicating keyboard-specific sound profiles. However, this was still sufficient to compromise password entropy.
- Typist Variability: A model trained on variable key press force could decode both fixed and variable force inputs with similar accuracy. When subjected to multiple typists, classification quality was only slightly affected, demonstrating the applicability of an attacker-trained model to a victim.
- Mechanism: Research indicated that the location of the key switch on the keyboard plate was the most relevant factor, akin to how different parts of a drum or cymbal produce distinct sounds.
- UC Berkeley/Lee Juang (2005) - Self-Supervised Learning: This team advanced acoustic attacks by implementing self-supervised training. Their model could discover patterns without prior training data. While not perfect for full plaintext recovery, it successfully compromised passwords: five-character random passwords were broken in fewer than 20 attempts, and 80% of 10-character passwords were broken in fewer than 75 attempts.
- Modern Acoustic Attacks (2023) - Unconstrained Accuracy: Recent British research achieved 95% accuracy without using language model constraints (i.e., pure sound matching). This was demonstrated by placing a phone microphone near the keyboard. Critically, they achieved 93% accuracy when performing this attack over a Zoom video conference connection, leading to the "Don't Skype and Type" warning. This confirms earlier postulations by researchers like Marcus (2003) and IBM (2004) that telephone frequencies could carry the necessary acoustic data.
- Spy Phone Attack (Georgia Tech) - Accelerometer-Based: This innovative attack uses a smartphone's accelerometer to detect keyboard vibrations transmitted through the table, rather than using the microphone. The key advantage is that accelerometer access is typically not privileged, meaning a Trojan horse app can exploit this without requiring explicit user permission, making it an easier vector to compromise.
Wireless Keyboard Vulnerabilities (MouseJack)
The MouseJack exploit targets wireless keyboard and mouse combinations that use a single USB dongle. While keyboard connections are often encrypted, mouse connections, for speed or legacy reasons, may not be. Researchers discovered that they could connect a fake mouse to the system. Once connected, this fake mouse could then call the keyboard API in plaintext, allowing it to inject arbitrary keystrokes and commands, bypassing any encryption on the legitimate keyboard's channel. This vulnerability affected not only Logitech devices (which were heavily publicized) but also other vendors using similar chips, demonstrating a significant flaw in the design of many wireless peripheral systems.
Demo / Proof of Concept
▶ Watch: BBC demonstration of reading CRT data from a van (5:48)
The speaker intended to provide a live demonstration of acoustic keyboard analysis using a hobby project by Gennady Gurgenov. While the live demo was ultimately skipped due to time constraints and the challenging noise environment of the conference, the speaker detailed its functionality and visual output.
Gurgenov's project is a lightweight web assembly implementation that performs acoustic pattern matching, distinguishing it from the more complex neural network models used in academic research. The process involves a short training phase where the user types a few sentences—specifically, 100 to 300 characters of valid English without typos or backspaces. This trains a simple pattern-matching model.
Once trained, the system makes predictions based on subsequent keystrokes. The cool aspect of this code, as highlighted by the speaker, is its visualization. It displays the top three guesses for each detected key press. Using an example from an "Andy Pro keyboard" (a notably "clacky" mechanical keyboard), the speaker showed a screenshot where, after pressing the letter "U" repeatedly, the system frequently guessed "H" in the top three choices, sometimes even as the first guess. Despite being a hobbyist project, this demonstration effectively illustrates the core principle of acoustic key identification and the potential for plaintext recovery, even if not perfectly accurate in this simplified implementation. The speaker emphasized that with a good microphone, the results would be even clearer.
Defensive Implications
▶ Watch: TEMPEST explained: classified standard and mitigation strategies (8:00)
Understanding these sophisticated keyboard attacks is crucial for developing robust defensive strategies. Defenders should consider a multi-layered approach:
- Physical Security and Exclusion Zones: Revisit the historical 200-foot rule (or equivalent) for highly sensitive environments. Control physical access to areas around computers handling classified or critical plaintext data to prevent microphone, optical, or EM signal collection from proximity.
- Red/Black Separation: Strictly enforce red/black separation principles. Physically separate systems processing plaintext ("red") from those handling encrypted or sensitive data ("black") according to established security guidelines, paying attention to shared power lines, cabling, and even adjacent rooms to prevent cross-talk.
- Electromagnetic Shielding: For extreme security, consider Faraday cages or EM-shielded enclosures for devices handling sensitive information. Ensure cables are shielded and properly filtered to minimize unintended EM emanations.
- Acoustic Mitigation:
- Quiet Keyboards: Deploy quiet membrane or silent mechanical keyboards, or even on-screen keyboards, in sensitive areas.
- White Noise/Masking: While problematic if not carefully implemented, introducing controlled white noise or acoustic masking can reduce the signal-to-noise ratio for attackers. However, be aware that soundproofing can aid attackers by dampening background noise more than the key press sounds.
- Microphone Discipline: Enforce strict policies regarding microphones during sensitive operations or video conferences. Users should mute microphones when not speaking and avoid typing while unmuted, especially during video calls.
- Accelerometer Awareness: Be mindful of apps requiring accelerometer permissions on mobile devices, particularly if those devices are regularly placed on surfaces used for typing.
- Optical Mitigation:
- Block Line of Sight: Ensure sensitive device indicator lights (modem TX LEDs, speaker LEDs) are not visible from outside the secure area or through windows. Consider using opaque covers or tape over non-essential LEDs.
- Air-Gap Isolation: For air-gapped systems, implement stringent physical separation and ensure no light-emitting components can be observed from outside the secure perimeter.
- USB Device Security:
- Strict USB Policies: Implement strict policies regarding the use of unknown or unauthorized USB devices. Disable unused USB ports or configure them for read-only access where appropriate.
- Endpoint Detection and Response (EDR): Utilize EDR solutions that can detect and alert on unauthorized HID (Human Interface Device) activity, such as a Rubber Ducky injecting commands at superhuman speed.
- Wireless Peripheral Security:
- Encrypted Wireless: Only deploy wireless keyboards and mice that use robust, authenticated, and encrypted communication protocols.
- Regular Firmware Updates: Keep firmware for all wireless peripherals and their dongles up-to-date to patch known vulnerabilities like MouseJack.
- Wired Alternatives: For highly sensitive environments, revert to wired keyboards and mice to eliminate wireless interception and injection risks.
- Employee Training and Awareness: Educate employees about the various side-channel risks, emphasizing the importance of physical security, microphone discipline, and cautious use of peripherals.
Key Takeaways
- Keyboards are a fundamental attack surface, providing access to plaintext data through various side channels before encryption or hashing.
- The vulnerabilities related to electromagnetic, acoustic, and optical emanations are continuously rediscovered and refined, often leveraging modern AI/ML techniques for enhanced accuracy and range.
- Even seemingly secure "air-gapped" systems are susceptible to data exfiltration via optical channels, such as blinking LEDs.
- Acoustic attacks, particularly when amplified by AI and deployed over common platforms like Zoom, pose a significant threat, making "don't Skype and type" a critical security rule.
- Non-privileged sensors like accelerometers can bypass traditional permission models, enabling covert data collection from devices placed near keyboards.
- Wireless peripherals introduce new and significant vulnerabilities, allowing for remote keystroke injection and command execution through flaws like MouseJack.
- Defenders must adopt a holistic security approach that addresses not only network and software vulnerabilities but also physical, electromagnetic, and acoustic side channels to protect sensitive information.
About the Speaker(s)
Federico Lucifredi is a seasoned professional with a career dedicated to free and open-source software. Currently serving as a manager, he engages in research and talks on topics like hardware hacking as a means to maintain his technical edge and passion for embedded engineering. Lucifredi is also the co-founder of a small R&D shop in Boston, specializing in sound and computer-related technologies, which naturally led him to explore the intricate topic of keyboard vulnerabilities. His background as an embedded engineer provides him with a deep understanding of the hardware and low-level interactions that underpin these sophisticated side-channel attacks.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent survey of keyboard side-channel attacks spanning TEMPEST, acoustic analysis, optical channels, MouseJack, and USB injection — well-organized and historically grounded, but fundamentally a literature review rather than original research. No new CVEs, no novel attack chains, no original tooling beyond referencing a hobbyist web-assembly demo that didn't even run live.
Heather Calloway (CISO) — WEAK
A technically competent survey of keyboard side-channel attacks with real historical depth, but it never crosses the line from interesting to actionable for the people who need it most. The defensive guidance is present but generic, and the institutional question — why organizations keep ignoring this class of risk — goes unasked and unanswered.