Comments

Clive Robinson August 18, 2025 11:23 AM

@ Bruce, ALL

With regards,

“It’s more a proof of concept than anything else … But it’s a start”

And it has a long way to go, with a lot of sorrow to happen as we go.

All mechanical vibrations contain energy and that can be used as a side channel.

It’s the reason I don’t use the very out of date expression “air gapping” and now use “Energy Gapping” when talking about “Emissions Security”.

It’s also why I keep warning that more “active transducers” that convert one energy type/source to another are bidirectional than are not.

Think of a DC motor it is actively converting DC current in the windings to a form of AC current but also to mechanical energy. But it is also a generator working in opposition (hence “Back EMF”). And this bidirectionally is essential to them not self destructing when starting up.

Now consider a thin semi-flexible plate like a glass window. It is transparent to some forms of energy but absorbs or transmits to others.

It’s designed to be effectively transparent to visible light as that passes mostly through the glass by transmission with some absorption losses being converted to thermal energy (a sure indicator “that work is being done”). Though some light will be reflected thus a light beam will change it’s reflection angle with any mechanical movement.

Acoustic energy is a form of mechanical energy and it will cause the glass to flex in response to the acoustic energy.

So shine a LASER on the glass at the right angle, and it will get modulated by the mechanical movement of the surface. So the signal you pick up from the reflection makes such a setup work as a long range microphone. This has been known as a “useful surveillance technology” from before the 1980’s

But we know sound can go through solid objects like glass because we hear it happening nearly every day of our lives much of the time.

Importantly though we notice that put a near vacuum between two mechanically isolated glass plates –double glazing– and the level of the sound drops significantly. Not because it is absorbed, but because the vacuum gap breaks the transmission of the mechanical energy. But as the light still goes through the LASER mic can thus be used against any reflective object on the other side of Double Glazed windows.

It’s the same principle at work here. All that is different is the the frequency of the Electromagnetic”(EM) energy is a lot lot lower for a RADAR system than it is for the LASER mic.

But this has consequences the inverse of frequency is wavelength, and there areca number of limitations that arise. Acoustic wave length is the speed of sound divided by the “Acoustic Frequency”(AF). The radio wavelength is the “speed of light” divided by the “Radio Frequency”(RF).

The difference in AF and RF of the same wavelength is ~300/300,000,000 or 1:1,000,000 or one to a million. Thus the minimum RF frequency has to be a million times the maximum AF where the first “null” in the conversion spectrum happens usually you try to work below 1/16th of that so with the maximum AF frequency being around 4kHz the minimum RF frequency would have to be 64,000,000,000 or 64Ghz. With the lowest audio frequency being around 10Hz that would be 160,000,000 or 160MHz.

So as 64GHz is not practical, various tricks would have to be used. The first is use an algorithm to invert the frequency spectrum roll off. Unfortunately that makes high frequency noise have a very significant reduction on signal to boise ratio.

Another trick is to use not the speech frequency, but the speech envelop which would be about 200Hz so 3,200,000,000 or 3.2GHz thus you could use with some loss the “Industrial Scientific and Medical”(ISM) band, so existing WiFi units close to the target, or strip down a microwave oven to get a greater range (with optional “Crispy Fried Critter”(CFC) as a side effect to the system operators, so “TinFoil Hats”(TFH) as “Personal Protective Equipment”(PPE) not an optional extra).

XYZZY August 18, 2025 11:49 AM

Humanity rushes forward towards a time when no utterance and perhaps no thought can be private. All out of some desire to prevent some perceived future threat or desire for monetary profit. Morality all but forgotten. What is this professions responsibility?

René August 18, 2025 12:23 PM

Seems a bit pointless. I assume the State security services eavesdrop on all mobile-phone communications anyway, so why would they need this?

Clive Robinson August 18, 2025 1:26 PM

@ XYZZY,

With regards,

Humanity rushes forward towards a time when no utterance and perhaps no thought can be private.

Not exactly. Like US Justice you chance of being subject to it’s downsides is inversely proportional to how much money you have.

In theory you could if you own your house and surrounds dig out from the basement down twenty or thirty feet and put in a nuclear bunker that with only minimal extra work on EMP / Shock protection would become a “SCIF” in effect “energy gapped” from the outside world.

You note,

All out of some desire to prevent some perceived future threat or desire for monetary profit. Morality all but forgotten.

Have you read “The Great American Dream”[1] recently, all you are really saying is the same thing, but from a more realistic view point of it being seen with respect to being in a resource constrained environment. As they found with the Titanic there are only so many seats in a life boat and if life boats are limited because of “profit” and you are not seen as being one of the select ones, you are left to swim then sink. It’s a variation on “The law of the jungle”. Sociologists refer to it as the “Hawks and Doves” model and apply game theory to it, which is “zero sum” so for every winner there has to be at least one looser if not more.

Which brings us to your question,

“What is this professions responsibility?”

You have not stated the “profession” you are thinking of…

But if it’s any one of the “Hawk professions” of Robber Barons and their ilk seen in corporation management and above, then as I’ve indicated they don’t have any morals or ethics.

If you are thinking of the “dove professions” such as “Developer” then they are as “serfs to the robber barons” controlled by “the dream” of success through hard work. The Robber Barons keep you from having actual assets so you are subject at every turn by their rent seeking behaviours. Why do you think the price of homes is so high yet wages are for most the lowest they have ever been since before WWII and real poverty is rife?

But what about the “licensed professions” that importantly are regulated by law and modern day Guilds. They have imposed codes of behaviour “to be in their boat”. Thus their Guild gives them the power of “collective bargaining”. And in return conduct rules that stop egregious behaviour to those that pay the tax of the guild to use their limited number of members services. The fact they could do what Robber Barons and others could not ment they were tolerated.

It was by the way the development of Guilds that gave rise to Unions that had collective bargaining for their members but only through strength of numbers. The Robber Barons though realised that even with hawkish violence and murder of Union-Busting they were outnumbered and would eventually loose. So they stopped the Unions getting legal protection and in fact got legislation to stop Unions. Thus most workers are very definitely in “Dove Professions” that at best are called “Trades” and get driven down for lack of legal protections. Such doves can not afford to have morals or even ethics and petty criminal behaviour tends to increase as a compensatory mechanism to put food on the table etc.

[1] James Truslow Adams, described it in 1931 shortly after the start of the 1929 “Great Depression as,

“That dream of a land in which life should be better and richer and fuller for everyone, with opportunity for each according to ability or achievement.”

It’s changed over nearly a century and is now seen as we head into the next “Great Depression” as,

“The belief that anyone, regardless of where they were born or their socioeconomic status, can attain their own version of success in a society in which upward mobility is possible for everyone.

The American dream is believed to be achieved through sacrifice, risk-taking, and hard work, rather than by chance.”

Now apply a “constrained environment” you get into the “my slice of the pie” problem. That is if I want a larger slice then it is has to be at someone else’s expense. That means some one has to be sacrificed for my greed etc, it is the thinking pattern of a criminal psychopath and makes believers either criminals or victims of criminals. Which is taking us into a feudalistic society via “Rent Seeking” the lie of the “free market” have created “Robber Barons” again.

ResearcherZero August 21, 2025 3:28 AM

Professional responsibility is a system set up to protect the instigators, the professionals, the administrators and the for-profit companies from the victims.

You may need to employee someone capable of using ChatGPT who will fiddle the numbers.

With the careful manipulation of statistics, a lot of abuses can be appear to look like not many at all. It is best to publish the figures as a percentage of the population. This way many hundreds of abuses, or thousands of cases of invasion of privacy, appear as a minuscule ~0.1% of the population. That does not sound like very much and would make such incidents appear uncommon. Do not search any one in first class. They will complain.

Between April and June 14,899 devices were searched by Customs and Border Protection.

‘https://techcrunch.com/2025/08/20/device-searches-at-the-us-border-hit-record-high-new-data-shows/

Would you like a beating with your search and detainment?
https://www.nbcnews.com/news/us-news/immigration-detention-human-rights-abuses-report-rcna222499

Grim Squeaker August 22, 2025 8:05 AM

@Clive Robinson re: cell phone “Energy Gapping”:

How much of an obstacle to effective “direct acoustical” eavesdropping of the sort identified in this column is the use of an earphone? Obviously the difficulty in detecting and analyzing the phone wielder end of the conversation is unchanged, but I would suspect that detecting the other end of the conversation (again, directly via acoustic eavesdropping) would be a great deal more difficult. Depending on the circumstances, this differential might influence the advisability of repeating what one hears from the other party in such a conversation 😉

Clive Robinson August 23, 2025 10:26 PM

@ Grim Squeaker,

With regards,

“How much of an obstacle to effective “direct acoustical” eavesdropping of the sort identified in this column is the use of an earphone?”

It rather depends on the “earphone” size, damping and the frequency of the EM signal you are using as the Doppler or offset RADAR.

The earphone has various vibration modes that are wavelength and speed of sound in the channel dependent. Whilst the idea is simple to explain the mathematics gets a little involved.

I think it was @RobertT that did some modeling of this for PC speakers back when BadBIOS was in the news.

But rule of thumb is the stiffer the channel and the more dense it is, the faster the speed of sound and the further the mechanical vibration will propagate down it (we’ve all seen the movies where someone puts their ear on a railroad track to hear if a train is coming). If you are lucky enough to have been at a quiet railway station waiting you can hear the rails twitch whilst being safe on the platform and the train still being 5000ft / 1500m or more away. Almost the first thing you note is the frequency response is of quite a high frequency compared to that coming from the train as it comes into the station. This is because of the vibration modes for the physical cross section of the rail.

The modern earphone / earbud is physical quite small and is designed to work as an acoustic tube that has the vibration mode not across the tube but along the axis. And is made from a hard medium density plastic.

This means that you would need to use an EM signal as a minimum in the far Infra-red. So you would be better off reverting back to the LASER mike.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.