This made me think of The Thing, a fascinating listening device made by the Soviets that was completely passive until powered remotely. Very difficult to detect when unpowered.
The Eye of Sauron paper does acknowledge the limitations that would likely prevent it from working against such a device. Impressive nonetheless. True privacy/security is just very hard!
the rabbit hole goes so much deeper than this 'Thing'.
An interesting read is Spy Catchers written by first science officer from MI5 in cold war. he was tasked with reversing listening devices and making them.. it doesnt spill all the beans but givea a good insight into how far they were already then.
u can hardly imagine what tech exists now 40-60 years later as electronics and computers have shrunk drastically and infinitely more weird material properties are discovered....
> In 1985, Wim van Eck published the first unclassified technical analysis of the security risks of emanations from computer monitors.[2][3] This paper caused some consternation in the security community, which had previously believed that such monitoring was a highly sophisticated attack available only to governments; van Eck successfully eavesdropped on a real system, at a range of hundreds of metres, using just $15 worth of equipment plus a television set.
In this context "emanations" means a signal allowing the listener to reconstruct the image and read the words on the screen.
I'm not sure if it works with modern monitors (CRTs were pretty high voltage!), but they are also quite "loud" in EMF. A fun experiment is to walk around your house with a portable radio in AM mode. You can "hear" all the electronics!
It seems like it must be much more limited these days. Display transport is packetized, often encrypted (HDCP), and designed to be capable of exceedingly high bandwidths. Versus a CRT that comparatively blasted out a nice sequential analog signal for anyone to listen in on.
That said, if you're using a wireless keyboard it's pretty much a given that the keystrokes can be recovered by timing analysis regardless of the manner of wireless connection. At least unless you happen to hunt and peck painfully slowly.
It would be the scan of the column data lines and sequential row update of the LCD that would be detected. For low spatial frequencies where you're simply mapping changes in the image, it might still be doable, but the real challenge is that the resolution of monitors and refresh rate have increased so much that it's more difficult to resolve characters or images. OLED is even more difficult, because the top cathode layer really shields most emissions (much more than the patterned VCOM of most modern LCDs).
Embedded touch is a whole'nuther issue. One could certainly remotely measure the radiated emissions of a cell-phone to get finger proximity and position in at least one if not both XY dimensions.
Precisely. Pixel clocks in van Eck's day were perhaps a few MHz, and the image was displayed by firing a modulated electron beam at a sheet of glass (i.e. a lot of power being manipulated in a fairly unconfined manner). Modern displays can have pixel clocks above 1 GHz, the amount of power being switched is much less, and that power is used in a very small space (the thickness of the LCD). Even given that receiving technologies have improved as well, the odds are against the eavesdropper.
Big difference whether you have a few hundred volts on a deflection coil with appreciable inductance or a digital circuit inside an RFI shield operating with a couple of volts. I am not going to say it is 100% sure impossible but I do think it is an orders of magnitude harder problem to solve.
My cell phone makes really weird noises (as picked up by AM radio), especially when I turn the screen on. I don't know how far it travels, or if it can be decoded, though.
My father worked in defense. He shared lore about the genesis of tempest, the requirement to use faraday cages to protect secrets, gear, etc.
The story goes that some kind of red team set up shop down the road from some missile tests (or something) with some simple gear. Afterwards, they shared the launch codes used, shocking all the brass. Hence the need for shielded comms.
I was under the impression that in actual practice all the launch codes are set to 0000. Wouldn't want to delay a launch because someone forgot the code. (I'm only half joking)
It has been speculated many times that the US would not have been able to respond to a nuclear attack on purpose, but was likely to start one by accident.
I suppose you can activate such device by just sweeping a high power radio wave over a frequency range. At that point, you can see what signals it sends back. Excite, then listen. This is how a lot of detection methods work, including radar, so it is not a weird idea.
Also there are ways to detect diode junctions now.
Disruption for one, since it would mean that every office would have to be turned over on a regular basis to find these things. Increasing American paranoia and insecurity were part of Soviet long term goals.
I skipped through the video real fast, so maybe im mistaken, but there was a diagram concerning external memory access of the SoC and RF signals emitted when that happens.
Stated another way, it is because its recording that its detectable.
Shielding would certainly reduce the strength of emitted frequencies, by some amount, but 100% shielding and 0% emissions would likely not allow for the opening for the camera optics, so they are going to leak something.
These assumptions are for commodity devices as well, not necessarily CIA in house produced unobtainium.
Dan Gelbart's lecture on sensors[0] explains another fascinating method in detail using RF as well as the optical scanning method mentioned in the original video. The full lecture is worth a watch, but the timestamp is where the RF method explanation starts.
That Dan Gelbart lecture where he also explains how retroreflection[0] is used to detect remote viewing, was it anything with a lens or even human eye is really good.
Reminds me of how every random electronic item would seemingly pick up audible interference from nearby GSM phones. Nonlinear components would involuntarily modulate the RF signal.
When close enough, and especially when GSM antennas are mis-tuned it's perfectly possible to turn on the ESD protection diodes on low voltage inputs. For 1.8v IOs with weak current driven pull-ups you can trip the TTL threshold hysteresis.
I saw this once in a pre-production cell phone where tact-switch IO inputs were being spuriously activated. Figuring out that part of the UI required pushing physical buttons, suddenly made sense of "why do your batteries only last an hour".
"an NLJD is correspondingly capable of detecting almost any unshielded electronic device containing semiconductors, whether the electronics are actively powered or not."
Is properly shielding something really that difficult or expensive that people are not shielding their gear? Or is more of nobody gives a damn to be bothered?
Interesting - but 800-900MHz (the mentioned harmonic frequencies) are blasted with LTE and 5G in Europe.
But maybe with a sharp filter (there's a gap between up- and downlink) it can be used with a RTLSDR. But the RTLSDR hates close strong signals as its 8-Bit ADC doesn't have much dynamic range.
This is a genius approach. I was wondering how to approach this problem myself the other day, and other things like audio poisoning for ambient listening devices. This gives me hope for being able to actually fight in the cat and mouse game of privacy that's coming up.
TSCM services commonly employ non linear junction detectors, if you have a legit need and money to spend and worry that your offices have been bugged (or are at risk of being bugged), you absolutely can hire them. This isn't really a new thing. More advanced highly portable RF equipment, portable spectrum analyzers and things built with relatively low-cost SDR that talk to Linux SBCs make the equipment to do this a lot less costly than it used to be.
If the intention is to RF "illuminate" an array of DRAM, portable GaN based amps in different bands capable of directing RF at an area (let's say, with a set of horn antennas on a plastic rolling cart being taken around an office) are also a lot smaller and less power hungry than they used to be.
Edit: Looking at the Zhang PDF, the box next to the laptop in figure 15 is a USRP 210 SDR, and a basic log periodic antenna on a PCB.
So really this boils down to "we're using a COTS SDR repurposed as a spectrum analyzer and we've written custom software to sniff what it looks like when DRAM is actively being used in a small embedded device". Some serious TSCM firms have been doing this for 35 years, just the equipment is a hell of a lot smaller and cheaper now.
You could just as easily stimulate a camera set to record only when motion is detected by bringing a few 2'x2' orange spray painted piece of cardboard and waving them around in a room. Or just by walking around in a room as a single person, since any usable hidden camera setup would need to be sensitive enough to capture the physical action of the person hauling a laptop with SDR and directional antenna around in the area seen by its lens.
I think this is less about a motion detecting camera and more the sudden jump in bitrate needed to encode all the new information when the scene changes quickly. This also lets them stimulate the camera at a known frequency, which I think could get them a better snr vs random emissions. unsure on how h264 or etc is actually encoded in terms of memory access patterns though
If the goal is to stimulate a H264 encoder or similar waving a theoretical big orange square around in a room will equally accomplish the same task. Though admittedly you can get some pretty damn powerful flashlights with multi-pattern strobe features for $35 (running on one 18650 or 21700 cell), so strobing a room isn't technically difficult or complicated either.
Well it kind of works. The palantir was (were? are there more than one?) used for remote viewing and Sauron corrupted it for his own purposes.
Here, palantir is meant for surveillance and this corrupts that by allowing the user to use the presence of the camera to curtail surveillance rather than submit to surveillance.
Nope, still doesn’t work. The palantir — and yes, there were more than one, there had to be, they were each nodes in a kind of closed-circuit communication network; the current user of one stone could see what the current user of any another stone could see, but if one of the two current users was sufficiently powerful of mind they could deceive the other current user — weren’t surveillance devices until they’d been employed by a bad actor to that end, and that bad actor was turn the presence of the palantir untrustworthy. The analogy doesn’t work because it was trivially easy to know a palantir was present (at least one was several feet in diameter) and just as easy to know if one was actively being used (if you could see anything through one then someone was present on the other end)… the problem was you didn’t know if it was being used for good or evil once one was in the hands of Sauron precisely because the being on the other end could always be the Lidless Eye.
All you had to do to curtail the use of a palantir was throw a sheet over it… the problem was the temptation to use one was too great.
Right, but adding a big memory chip may be difficult in a video camera that must be as small as possible, except when using some expensive packaging method, with chip stacking.
Ensuring almost perfect shielding is cheaper and simpler. The camera should be completely enclosed in a metallic case, with only 2 small holes, for the camera lens and for the antenna output. Also its schematic should include adequate filtering components superposed to the integrated circuit packages, to minimize the length of the metal traces with variable potential, which radiate electromagnetic waves.
Improved shielding and filtering should reduce a lot the detection distance from the 20 meter range obtained with ordinary cameras, perhaps to a range under 1 meter.
If the camera is designed to not watch continuously, but to halt its activity for random intervals, it may have great chances to not be detected even by close sweeps with the camera detector.
Hmmm, another approach might be to constantly emit signals, so the interesting ones are lost in the noise. This is similar to another commenter about making the algorithms produce the same amount of noise regardless of input as in cryptography (time-constant, energy-constant, etc.)
The speaker in the video was extremely difficult for me to understand but the idea seems quite clever.
What I'm most surprised about is just how well it actually works... I did not think such EM fluctuations would be usably detectable from several meters away... but I suppose this may be moreso due to improper/lack of shielding in the first place, which I would think should be easily fixable in most products to mitigate this type of detection.
Youtube subtitles can help in situations like this. Although they're not able to understand perfectly either. Example (1m0s) speaker means to say 'they can be disguised' but subtitles are:
> they can be disgusted
I think the speaker genuinely gets that word wrong; a malapropism (as opposed to the auto-generated English subtitles getting it wrong).
> The speaker in the video was extremely difficult for me to understand but the idea seems quite clever.
With a bit of practice it's actually quite easy to understand the accent of Chinese speakers as they have some typical patterns and speak slowly.
I must say, I loved listening to him because this was genuine human work. Human made slides (with lots of ugliness coming with PowerPoint), human typos, human grammar mistakes, all of it. It may be flawed in some ways but this fully removed any doubts that a slop machine came even near it. So refreshing in this day and age!
Shielding is addressed in the paper. They did some testing covering it with aluminum sheet (from coke can not aluminum foil) which decreased detection range from 30 to 2m. That's still not a bad range compared to other similar projects attempting to detect hidden cameras using EM. But with a properly designed shield the detection is probably even worse. Within limitations section they mention, they had problems detecting some smartphone cameras due them using low power memory and in general being better shielded.
this adds to the field sometimes known as 'sousveillance'. i even saw one in AR that would show you the field covered by the cameras. thanks for the effort!
Yes but only for detecting 5ghz WiFi cameras (actively streaming). If it’s 2.4ghz WiFi, or Ethernet wired, or it’s just recording to an sd card, it can’t be detected using the quadRF.
They already use fiber-optic borescopes with no electronics on the lens side to create distance from electronics when their targets do sweeps.
You can also have opto-mechanical listening devices where the electronics are 100 m away. There is a vibrating membrane at one end, and a laser through the fiber reads the vibrations.
Really interesting concept! I would not have thought of EMR variation as a usable side channel for this.
IIUC, the EMR increases following scene changes (like a light being turned on or off) are a result of the fact that video codecs try hard to compress similar images. So, I speculate that an "extremely bad codec" that simply dumps raw pixels to storage would not produce such variation, and therefore remain undetectable?
Makes sense. It might be possible to develop a codec that, in addition to being constant-time, has the property that every prefix of the bits encoding a unit (e.g., a frame or block within a frame) encodes an approximate version of that unit, where the longer the prefix the more faithful the approximation is. Then each unit could be output in full to storage, and the "output file pointer" could then be wound back to a point dependent on how many bits are actually required to represent it accurately -- so keeping the full amount for a full scene change, or just a few bits for the "same as last time" common case.
Oh, that is fascinating - I think a scheme like that could very well give you constant-space as well as constant-time, while calculating and preserving the desired compression information for use in transmission (which itself could separately be made constant for detectable channels).
That's clever. I think you could improve localisation by instead of just turning the light on and off, have a spinning light like a lighthouse, and then match the timing of it with the timing of the EMR changes.
The former owner of my house has cameras littered around the outside of the house and 2 inside (these aren't discrete they're specifically security cameras). I'm like 95% sure I took over the appropriate accounts. My neighbors said that he was a former Airforce guy and was obsessed with gadgets and "spy conventions," though.
I feel bad for Tolkien. The names in his beautiful works are being semantically hijacked by tech bros and authoritarian types with surveillance wet dreams.
This made me think of The Thing, a fascinating listening device made by the Soviets that was completely passive until powered remotely. Very difficult to detect when unpowered.
https://en.wikipedia.org/wiki/The_Thing_(listening_device)
And then I thought, something similar might be possible for video. Turns out, yep.
https://ieeexplore.ieee.org/document/8719264
The Eye of Sauron paper does acknowledge the limitations that would likely prevent it from working against such a device. Impressive nonetheless. True privacy/security is just very hard!
The Thing is full of surprises to this day.
> The Thing was designed by Soviet Russian inventor Leon Theremin, best known for his invention of the theremin, an electronic musical instrument.
the rabbit hole goes so much deeper than this 'Thing'.
An interesting read is Spy Catchers written by first science officer from MI5 in cold war. he was tasked with reversing listening devices and making them.. it doesnt spill all the beans but givea a good insight into how far they were already then.
u can hardly imagine what tech exists now 40-60 years later as electronics and computers have shrunk drastically and infinitely more weird material properties are discovered....
There's also the Moog synthesizer: https://www.google.com/search?q=moog+synthesizer
And the Moog company, specializing in high tech products, started by a cousin of the synthesizer guy: https://en.wikipedia.org/wiki/Moog_Inc.
Learned about this from a huge intro in an episode of this amazing podcast. https://500songs.com/podcast/episode-146-good-vibrations-by-...
Seems like the devices they found in the IBM Selectrics during Project GUNMAN (though, same ‘conflict’).
https://media.defense.gov/2021/Jul/13/2002761779/-1/-1/0/LEA...
Haseltine’s The Spy in Moscow Station is also a fascinating account of events.
Turns out we're all livestreamers:
> In 1985, Wim van Eck published the first unclassified technical analysis of the security risks of emanations from computer monitors.[2][3] This paper caused some consternation in the security community, which had previously believed that such monitoring was a highly sophisticated attack available only to governments; van Eck successfully eavesdropped on a real system, at a range of hundreds of metres, using just $15 worth of equipment plus a television set.
https://en.wikipedia.org/wiki/Van_Eck_phreaking
In this context "emanations" means a signal allowing the listener to reconstruct the image and read the words on the screen.
I'm not sure if it works with modern monitors (CRTs were pretty high voltage!), but they are also quite "loud" in EMF. A fun experiment is to walk around your house with a portable radio in AM mode. You can "hear" all the electronics!
It seems like it must be much more limited these days. Display transport is packetized, often encrypted (HDCP), and designed to be capable of exceedingly high bandwidths. Versus a CRT that comparatively blasted out a nice sequential analog signal for anyone to listen in on.
That said, if you're using a wireless keyboard it's pretty much a given that the keystrokes can be recovered by timing analysis regardless of the manner of wireless connection. At least unless you happen to hunt and peck painfully slowly.
It would be the scan of the column data lines and sequential row update of the LCD that would be detected. For low spatial frequencies where you're simply mapping changes in the image, it might still be doable, but the real challenge is that the resolution of monitors and refresh rate have increased so much that it's more difficult to resolve characters or images. OLED is even more difficult, because the top cathode layer really shields most emissions (much more than the patterned VCOM of most modern LCDs).
Embedded touch is a whole'nuther issue. One could certainly remotely measure the radiated emissions of a cell-phone to get finger proximity and position in at least one if not both XY dimensions.
Precisely. Pixel clocks in van Eck's day were perhaps a few MHz, and the image was displayed by firing a modulated electron beam at a sheet of glass (i.e. a lot of power being manipulated in a fairly unconfined manner). Modern displays can have pixel clocks above 1 GHz, the amount of power being switched is much less, and that power is used in a very small space (the thickness of the LCD). Even given that receiving technologies have improved as well, the odds are against the eavesdropper.
Big difference whether you have a few hundred volts on a deflection coil with appreciable inductance or a digital circuit inside an RFI shield operating with a couple of volts. I am not going to say it is 100% sure impossible but I do think it is an orders of magnitude harder problem to solve.
My cell phone makes really weird noises (as picked up by AM radio), especially when I turn the screen on. I don't know how far it travels, or if it can be decoded, though.
As a Neal Stephenson fan, Van Eck phreaking is where my mind went after reading the abstract. Glad to see the technique is alive and well today :)
Do you have a hankering for antique furniture?
Yup.
My father worked in defense. He shared lore about the genesis of tempest, the requirement to use faraday cages to protect secrets, gear, etc.
The story goes that some kind of red team set up shop down the road from some missile tests (or something) with some simple gear. Afterwards, they shared the launch codes used, shocking all the brass. Hence the need for shielded comms.
I was under the impression that in actual practice all the launch codes are set to 0000. Wouldn't want to delay a launch because someone forgot the code. (I'm only half joking)
It has been speculated many times that the US would not have been able to respond to a nuclear attack on purpose, but was likely to start one by accident.
Zenith used to sell a TEMPEST sealed PC clone for military use, that was then installed inside a TEMPEST constructed room/facility.
This was decades ago, so, not spilling any secrets here.
Not sure what current procedures are.
I suppose you can activate such device by just sweeping a high power radio wave over a frequency range. At that point, you can see what signals it sends back. Excite, then listen. This is how a lot of detection methods work, including radar, so it is not a weird idea.
Also there are ways to detect diode junctions now.
What if the Thing was supposed to be found? People think it was for surveillance. Maybe it was to make the Americans more paranoid.
What would that achieve for their goals, compared to listening in to what they're saying?
Disruption for one, since it would mean that every office would have to be turned over on a regular basis to find these things. Increasing American paranoia and insecurity were part of Soviet long term goals.
It’s really clever.
The idea is that cameras read/write to a disk. That cause electromagnetic radiation that is detectable.
Then this drone does [something/move/stimulus] to trigger more read/write/EM radiation.
But part of me can’t believe this is the cutting edge in 2026? Feels like 60s engineers would’ve thought about this
Intelligence services are very likely far ahead and for obvious reasons the public is not privy to it.
Not to disk, writing to RAM is the important part. DDR3 runs at high fixed frequencies, so you can use a pretty sharp filter to find it.
Oh wow that’s crazy
So basically we can detect locally driven AI devices too, anything physical AI is going to be carrying a fuckton of memory.
This will be useful for the Butlerian Jihad.
I think the cutting edge part, is that a couple of college students can do this for $100 in parts with a laptop and open source software.
Not necessarily that it wasn't done decades ago for millions by well funded government agencies, who then didn't talk about it.
New tech standing on the shoulders of old tech, as it does.
Presumably it doesn't work on a battery powered device that is recording and not transmitting any data at all? Especially a shielded one.
I skipped through the video real fast, so maybe im mistaken, but there was a diagram concerning external memory access of the SoC and RF signals emitted when that happens.
Stated another way, it is because its recording that its detectable.
Shielding would certainly reduce the strength of emitted frequencies, by some amount, but 100% shielding and 0% emissions would likely not allow for the opening for the camera optics, so they are going to leak something.
These assumptions are for commodity devices as well, not necessarily CIA in house produced unobtainium.
Dan Gelbart's lecture on sensors[0] explains another fascinating method in detail using RF as well as the optical scanning method mentioned in the original video. The full lecture is worth a watch, but the timestamp is where the RF method explanation starts.
[0] https://youtu.be/0MtRxX0crjU?t=1815
That Dan Gelbart lecture where he also explains how retroreflection[0] is used to detect remote viewing, was it anything with a lens or even human eye is really good.
[0] straight link to where he explains retroflection https://youtu.be/0MtRxX0crjU?t=3019
Also many other videos where he explains how to solve hard problems are really good too.
e: There seems to be commercial product using retroreflection advertised Youtube
https://www.youtube.com/watch?v=NaXSRpTeMbU
The final boss of detection doesn't need the camera to be powered at all.
https://en.wikipedia.org/wiki/Nonlinear_junction_detector
Reminds me of how every random electronic item would seemingly pick up audible interference from nearby GSM phones. Nonlinear components would involuntarily modulate the RF signal.
When close enough, and especially when GSM antennas are mis-tuned it's perfectly possible to turn on the ESD protection diodes on low voltage inputs. For 1.8v IOs with weak current driven pull-ups you can trip the TTL threshold hysteresis.
I saw this once in a pre-production cell phone where tact-switch IO inputs were being spuriously activated. Figuring out that part of the UI required pushing physical buttons, suddenly made sense of "why do your batteries only last an hour".
"an NLJD is correspondingly capable of detecting almost any unshielded electronic device containing semiconductors, whether the electronics are actively powered or not."
Is properly shielding something really that difficult or expensive that people are not shielding their gear? Or is more of nobody gives a damn to be bothered?
Interesting - but 800-900MHz (the mentioned harmonic frequencies) are blasted with LTE and 5G in Europe.
But maybe with a sharp filter (there's a gap between up- and downlink) it can be used with a RTLSDR. But the RTLSDR hates close strong signals as its 8-Bit ADC doesn't have much dynamic range.
This is a genius approach. I was wondering how to approach this problem myself the other day, and other things like audio poisoning for ambient listening devices. This gives me hope for being able to actually fight in the cat and mouse game of privacy that's coming up.
I'd have asked the speaker if he scanned his actual hotel room at the conference.
I'm actually quite certain that he did. Imagine the scoop, opening your conference presentation with what you found upstairs the evening before!
When I stay at an Airbnb I open up my camera app and look around the room with the lights off. Anything emitting IR light shows up very obviously.
Did you find any occurrences of hidden cameras ?
I had wondered time to time, as a guest, but also as a host (if guest left devices after).
TSCM services commonly employ non linear junction detectors, if you have a legit need and money to spend and worry that your offices have been bugged (or are at risk of being bugged), you absolutely can hire them. This isn't really a new thing. More advanced highly portable RF equipment, portable spectrum analyzers and things built with relatively low-cost SDR that talk to Linux SBCs make the equipment to do this a lot less costly than it used to be.
If the intention is to RF "illuminate" an array of DRAM, portable GaN based amps in different bands capable of directing RF at an area (let's say, with a set of horn antennas on a plastic rolling cart being taken around an office) are also a lot smaller and less power hungry than they used to be.
Edit: Looking at the Zhang PDF, the box next to the laptop in figure 15 is a USRP 210 SDR, and a basic log periodic antenna on a PCB.
https://www.google.com/search?client=firefox-b-d&q=USRP+B210...
https://www.ettus.com/all-products/ub210-kit/
So really this boils down to "we're using a COTS SDR repurposed as a spectrum analyzer and we've written custom software to sniff what it looks like when DRAM is actively being used in a small embedded device". Some serious TSCM firms have been doing this for 35 years, just the equipment is a hell of a lot smaller and cheaper now.
> This isn’t really a new thing.
The concept isn’t necessarily new, but this is a novel approach that stimulates through optical means using a strobe, not RF.
You could just as easily stimulate a camera set to record only when motion is detected by bringing a few 2'x2' orange spray painted piece of cardboard and waving them around in a room. Or just by walking around in a room as a single person, since any usable hidden camera setup would need to be sensitive enough to capture the physical action of the person hauling a laptop with SDR and directional antenna around in the area seen by its lens.
I think this is less about a motion detecting camera and more the sudden jump in bitrate needed to encode all the new information when the scene changes quickly. This also lets them stimulate the camera at a known frequency, which I think could get them a better snr vs random emissions. unsure on how h264 or etc is actually encoded in terms of memory access patterns though
If the goal is to stimulate a H264 encoder or similar waving a theoretical big orange square around in a room will equally accomplish the same task. Though admittedly you can get some pretty damn powerful flashlights with multi-pattern strobe features for $35 (running on one 18650 or 21700 cell), so strobing a room isn't technically difficult or complicated either.
Eye of Sauron to counter Palantir. Makes sense.
Does it though? The Eye of Sauron represents the being so sufficiently single-minded that it corrupted the Palantir and weaponized them for evil ends.
AKA, you know, Peter Thiel.
Well it kind of works. The palantir was (were? are there more than one?) used for remote viewing and Sauron corrupted it for his own purposes.
Here, palantir is meant for surveillance and this corrupts that by allowing the user to use the presence of the camera to curtail surveillance rather than submit to surveillance.
Nope, still doesn’t work. The palantir — and yes, there were more than one, there had to be, they were each nodes in a kind of closed-circuit communication network; the current user of one stone could see what the current user of any another stone could see, but if one of the two current users was sufficiently powerful of mind they could deceive the other current user — weren’t surveillance devices until they’d been employed by a bad actor to that end, and that bad actor was turn the presence of the palantir untrustworthy. The analogy doesn’t work because it was trivially easy to know a palantir was present (at least one was several feet in diameter) and just as easy to know if one was actively being used (if you could see anything through one then someone was present on the other end)… the problem was you didn’t know if it was being used for good or evil once one was in the hands of Sauron precisely because the being on the other end could always be the Lidless Eye.
All you had to do to curtail the use of a palantir was throw a sheet over it… the problem was the temptation to use one was too great.
So the mitigation is to have larger memory buffers so processing/emissions can be delayed (assuming simple shielding isn't enough).
Right, but adding a big memory chip may be difficult in a video camera that must be as small as possible, except when using some expensive packaging method, with chip stacking.
Ensuring almost perfect shielding is cheaper and simpler. The camera should be completely enclosed in a metallic case, with only 2 small holes, for the camera lens and for the antenna output. Also its schematic should include adequate filtering components superposed to the integrated circuit packages, to minimize the length of the metal traces with variable potential, which radiate electromagnetic waves.
Improved shielding and filtering should reduce a lot the detection distance from the 20 meter range obtained with ordinary cameras, perhaps to a range under 1 meter.
If the camera is designed to not watch continuously, but to halt its activity for random intervals, it may have great chances to not be detected even by close sweeps with the camera detector.
Hmmm, another approach might be to constantly emit signals, so the interesting ones are lost in the noise. This is similar to another commenter about making the algorithms produce the same amount of noise regardless of input as in cryptography (time-constant, energy-constant, etc.)
The speaker in the video was extremely difficult for me to understand but the idea seems quite clever.
What I'm most surprised about is just how well it actually works... I did not think such EM fluctuations would be usably detectable from several meters away... but I suppose this may be moreso due to improper/lack of shielding in the first place, which I would think should be easily fixable in most products to mitigate this type of detection.
Youtube subtitles can help in situations like this. Although they're not able to understand perfectly either. Example (1m0s) speaker means to say 'they can be disguised' but subtitles are:
> they can be disgusted
I think the speaker genuinely gets that word wrong; a malapropism (as opposed to the auto-generated English subtitles getting it wrong).
> The speaker in the video was extremely difficult for me to understand but the idea seems quite clever.
With a bit of practice it's actually quite easy to understand the accent of Chinese speakers as they have some typical patterns and speak slowly.
I must say, I loved listening to him because this was genuine human work. Human made slides (with lots of ugliness coming with PowerPoint), human typos, human grammar mistakes, all of it. It may be flawed in some ways but this fully removed any doubts that a slop machine came even near it. So refreshing in this day and age!
Shielding is addressed in the paper. They did some testing covering it with aluminum sheet (from coke can not aluminum foil) which decreased detection range from 30 to 2m. That's still not a bad range compared to other similar projects attempting to detect hidden cameras using EM. But with a properly designed shield the detection is probably even worse. Within limitations section they mention, they had problems detecting some smartphone cameras due them using low power memory and in general being better shielded.
this adds to the field sometimes known as 'sousveillance'. i even saw one in AR that would show you the field covered by the cameras. thanks for the effort!
Something like this seems to be more practical? https://www.crowdsupply.com/scale-rf/quadrf
Yes but only for detecting 5ghz WiFi cameras (actively streaming). If it’s 2.4ghz WiFi, or Ethernet wired, or it’s just recording to an sd card, it can’t be detected using the quadRF.
This feels very impactful for national security and corporate espionage.
They already use fiber-optic borescopes with no electronics on the lens side to create distance from electronics when their targets do sweeps.
You can also have opto-mechanical listening devices where the electronics are 100 m away. There is a vibrating membrane at one end, and a laser through the fiber reads the vibrations.
Who calls cameras spy cameras? They must be angling for government contracts.
The purpose is to discover hidden cameras; an elaborate process for detecting them isn't necessary unless they're there to spy on you!
Okay who can build me one of these?
Back to microfilm for the spies
Really interesting concept! I would not have thought of EMR variation as a usable side channel for this.
IIUC, the EMR increases following scene changes (like a light being turned on or off) are a result of the fact that video codecs try hard to compress similar images. So, I speculate that an "extremely bad codec" that simply dumps raw pixels to storage would not produce such variation, and therefore remain undetectable?
Potentially, although raw pixel data presents its own challenges - one 1080p60 camera will fill a terabyte of storage in less than an hour.
A better mitigation might be to take a leaf from cryptography and develop a constant-time codec.
Like all I frames in H264 ?
Non-branching memory accesses?
Makes sense. It might be possible to develop a codec that, in addition to being constant-time, has the property that every prefix of the bits encoding a unit (e.g., a frame or block within a frame) encodes an approximate version of that unit, where the longer the prefix the more faithful the approximation is. Then each unit could be output in full to storage, and the "output file pointer" could then be wound back to a point dependent on how many bits are actually required to represent it accurately -- so keeping the full amount for a full scene change, or just a few bits for the "same as last time" common case.
Oh, that is fascinating - I think a scheme like that could very well give you constant-space as well as constant-time, while calculating and preserving the desired compression information for use in transmission (which itself could separately be made constant for detectable channels).
That's clever. I think you could improve localisation by instead of just turning the light on and off, have a spinning light like a lighthouse, and then match the timing of it with the timing of the EMR changes.
phenomenal
cool
The communists are helping us fight capitalist surveillance... Oh, the irony!
The former owner of my house has cameras littered around the outside of the house and 2 inside (these aren't discrete they're specifically security cameras). I'm like 95% sure I took over the appropriate accounts. My neighbors said that he was a former Airforce guy and was obsessed with gadgets and "spy conventions," though.
Long story short: I'd like this device please.
I feel bad for Tolkien. The names in his beautiful works are being semantically hijacked by tech bros and authoritarian types with surveillance wet dreams.
Tag 2024?