How Vulnerable Are Computers to an 80-Year-Old Spy Technique? Congress Wants Answers

US Lawmakers Seek Investigation Into Risks of Side-Channel Surveillance on Modern Devices
Photo: WIRED

US Lawmakers Seek Investigation Into Risks of Side-Channel Surveillance on Modern Devices

Two US lawmakers, Senator Ron Wyden and Representative Shontel Brown, are urging a federal investigation into the risk that modern computers, smartphones, and other devices could be monitored using a long-known espionage method based on unintended electronic emissions. The technique—historically codenamed TEMPEST by the National Security Agency and now broadly described as side-channel attacks—relies on analyzing electromagnetic signals, sound, or vibrations produced by electronic components to infer sensitive information such as keystrokes, cryptographic keys, or internal computer operations.

In a letter sent to the Government Accountability Office (GAO), the lawmakers requested a formal study evaluating how vulnerable consumer devices might be to these attacks and whether government action is needed to require stronger protections. They argue that while the US government takes extensive precautions to shield classified systems from these emissions—often using specially shielded facilities called Sensitive Compartmented Information Facilities (SCIFs)—similar protections are not required for consumer electronics. According to Wyden and Brown, this leaves businesses and individuals potentially exposed to sophisticated surveillance techniques that could be used for espionage or intellectual property theft.

The phenomenon has been known since the 1940s, when Bell Labs discovered that military encryption machines emitted radio signals that could reveal clues about their internal operations. Since then, researchers have repeatedly demonstrated experimental attacks that recover data from computers by analyzing electromagnetic radiation or acoustic signals. Some prototypes have used inexpensive equipment placed near the target device to reconstruct partial information.

However, cybersecurity experts note that such attacks remain technically complex and generally require proximity to the target system. They are therefore more relevant to high-value targets—such as government agencies, defense contractors, or companies developing strategic technologies—than to the average person. Improvements in energy-efficient hardware have also reduced the amount of electromagnetic leakage from many modern devices.

Nevertheless, researchers warn that advances in artificial intelligence and signal processing could make it easier to extract useful information from noisy emissions in the future. The Congressional Research Service report commissioned by the lawmakers suggests potential policy responses, including regulatory pressure from agencies such as the Federal Communications Commission or the Federal Trade Commission to encourage manufacturers to include stronger countermeasures in consumer devices.

Leave a Reply

Your email address will not be published. Required fields are marked *