Van Eck Phreaking and the Tempest Origins
Wim Van Eck’s 1985 paper published what SIGINT professionals had known since the 1940s: CRT monitors radiate UHF signals that can be reconstructed with $15 of circuitry from up to 1 kilometer away. The BBC demonstrated reading a monitor eight floors up from a van. Bell Labs discovered the effect in 1943, the CIA rediscovered it in 1951. The NSA’s Tempest program mandated shielding, filtering, or 200-foot exclusion zones around teletypes handling classified data. Red-black separation keeps cipher and plaintext machines physically apart.
Acoustic Keylogging: From Neural Nets to Zoom
In 2004, IBM researchers Asonov and Agrawal placed a microphone half a meter to 15 meters from a keyboard. A neural network with a few hundred nodes distinguished two letters with 100% accuracy over 20 tries. With 30 keys and 300 tests, the correct key was the top guess 79% of the time. Distance did not degrade performance. By 2023, British researchers achieved 95% accuracy using only the sound of each key, no language model, and 93% accuracy over a Zoom connection.
EM Emanations from Keyboards
Van Eck’s method applies to keyboards. In 2008, a Swiss team extracted the full signal of PS/2 and USB keyboards using GNU radio on cheap hardware. They demonstrated capture at 5 meters and up to 20 meters. The attack could fingerprint different keyboards in the same room, isolating each signal independently. The voltages are not too low; PS/2 is serial and carries enough energy to radiate. No classified equipment needed.
The Mouse-Jack Vulnerability
Logitech’s unifying receiver uses one dongle for mouse and keyboard. Keyboard traffic is encrypted; mouse traffic is not. Researchers discovered that a fake mouse can connect to the dongle and then call the keyboard API in plain text, injecting keystrokes. The chip is not exclusive to Logitech; non-Logitech mice are also affected. The attack bypasses encryption entirely because the mouse link was left plaintext for speed ten years ago.
Practical Threat and a Hobbyist Demo
Gennady Gurgenov built a lightweight web assembly tool that trains on 100-300 characters of typed text without a neural net. It uses pattern matching and language constraints. After training on a clacky keyboard, the top three guesses contained the correct key over 50% of the time. The speaker concludes that a sophisticated adversary with resources can recover keystrokes within 30-40 feet. Tools are not public, so the threat is government-level, but a dedicated hobbyist could finish them.
Notable Quotes
it’s realistically possible for an sophisticated, semi-sophisticated adversary with some resources to read whatever is going on on your keyboard if they can get within, let’s say, 30 to 40 ft. Federico Lucifredi · ▶ 36:01
they demonstrated that they could fingerprint different keyboards in the same room. Federico Lucifredi · ▶ 30:46
the model guessed the correct key 79% of the time Federico Lucifredi · ▶ 24:13
they figured out a way to read the sound in a room by looking at the flickering on the speaker lights. Federico Lucifredi · ▶ 20:01
Key Takeaways
- Van Eck phreaking from 1985 works on CRT monitors; keyboards radiate similar EM signals.
- Acoustic keylogging via phone microphone achieves over 90% accuracy, even over Zoom.
- Unencrypted mouse connections allow keystroke injection through the keyboard API.