https://en.wikipedia.org/wiki/The_Thing_(listening_device)
And then I thought, something similar might be possible for video. Turns out, yep.
https://ieeexplore.ieee.org/document/8719264
The Eye of Sauron paper does acknowledge the limitations that would likely prevent it from working against such a device. Impressive nonetheless. True privacy/security is just very hard!
> In 1985, Wim van Eck published the first unclassified technical analysis of the security risks of emanations from computer monitors.[2][3] This paper caused some consternation in the security community, which had previously believed that such monitoring was a highly sophisticated attack available only to governments; van Eck successfully eavesdropped on a real system, at a range of hundreds of metres, using just $15 worth of equipment plus a television set.
https://en.wikipedia.org/wiki/Van_Eck_phreaking
In this context "emanations" means a signal allowing the listener to reconstruct the image and read the words on the screen.
I'm not sure if it works with modern monitors (CRTs were pretty high voltage!), but they are also quite "loud" in EMF. A fun experiment is to walk around your house with a portable radio in AM mode. You can "hear" all the electronics!
That said, if you're using a wireless keyboard it's pretty much a given that the keystrokes can be recovered by timing analysis regardless of the manner of wireless connection. At least unless you happen to hunt and peck painfully slowly.
Embedded touch is a whole'nuther issue. One could certainly remotely measure the radiated emissions of a cell-phone to get finger proximity and position in at least one if not both XY dimensions.
My father worked in defense. He shared lore about the genesis of tempest, the requirement to use faraday cages to protect secrets, gear, etc.
The story goes that some kind of red team set up shop down the road from some missile tests (or something) with some simple gear. Afterwards, they shared the launch codes used, shocking all the brass. Hence the need for shielded comms.
> The Thing was designed by Soviet Russian inventor Leon Theremin, best known for his invention of the theremin, an electronic musical instrument.
An interesting read is Spy Catchers written by first science officer from MI5 in cold war. he was tasked with reversing listening devices and making them.. it doesnt spill all the beans but givea a good insight into how far they were already then.
u can hardly imagine what tech exists now 40-60 years later as electronics and computers have shrunk drastically and infinitely more weird material properties are discovered....
And the Moog company, specializing in high tech products, started by a cousin of the synthesizer guy: https://en.wikipedia.org/wiki/Moog_Inc.
https://media.defense.gov/2021/Jul/13/2002761779/-1/-1/0/LEA...
Haseltine’s The Spy in Moscow Station is also a fascinating account of events.
Also there are ways to detect diode junctions now.
If the intention is to RF "illuminate" an array of DRAM, portable GaN based amps in different bands capable of directing RF at an area (let's say, with a set of horn antennas on a plastic rolling cart being taken around an office) are also a lot smaller and less power hungry than they used to be.
Edit: Looking at the Zhang PDF, the box next to the laptop in figure 15 is a USRP 210 SDR, and a basic log periodic antenna on a PCB.
https://www.google.com/search?client=firefox-b-d&q=USRP+B210...
https://www.ettus.com/all-products/ub210-kit/
So really this boils down to "we're using a COTS SDR repurposed as a spectrum analyzer and we've written custom software to sniff what it looks like when DRAM is actively being used in a small embedded device". Some serious TSCM firms have been doing this for 35 years, just the equipment is a hell of a lot smaller and cheaper now.
The concept isn’t necessarily new, but this is a novel approach that stimulates through optical means using a strobe, not RF.
[0] straight link to where he explains retroflection https://youtu.be/0MtRxX0crjU?t=3019
Also many other videos where he explains how to solve hard problems are really good too.
e: There seems to be commercial product using retroreflection advertised Youtube
The idea is that cameras read/write to a disk. That cause electromagnetic radiation that is detectable.
Then this drone does [something/move/stimulus] to trigger more read/write/EM radiation.
But part of me can’t believe this is the cutting edge in 2026? Feels like 60s engineers would’ve thought about this
So basically we can detect locally driven AI devices too, anything physical AI is going to be carrying a fuckton of memory.
I had wondered time to time, as a guest, but also as a host (if guest left devices after).
But maybe with a sharp filter (there's a gap between up- and downlink) it can be used with a RTLSDR. But the RTLSDR hates close strong signals as its 8-Bit ADC doesn't have much dynamic range.
Is properly shielding something really that difficult or expensive that people are not shielding their gear? Or is more of nobody gives a damn to be bothered?
I saw this once in a pre-production cell phone where tact-switch IO inputs were being spuriously activated. Figuring out that part of the UI required pushing physical buttons, suddenly made sense of "why do your batteries only last an hour".
I'm actually quite certain that he did. Imagine the scoop, opening your conference presentation with what you found upstairs the evening before!
AKA, you know, Peter Thiel.
Here, palantir is meant for surveillance and this corrupts that by allowing the user to use the presence of the camera to curtail surveillance rather than submit to surveillance.
All you had to do to curtail the use of a palantir was throw a sheet over it… the problem was the temptation to use one was too great.
Ensuring almost perfect shielding is cheaper and simpler. The camera should be completely enclosed in a metallic case, with only 2 small holes, for the camera lens and for the antenna output. Also its schematic should include adequate filtering components superposed to the integrated circuit packages, to minimize the length of the metal traces with variable potential, which radiate electromagnetic waves.
Improved shielding and filtering should reduce a lot the detection distance from the 20 meter range obtained with ordinary cameras, perhaps to a range under 1 meter.
If the camera is designed to not watch continuously, but to halt its activity for random intervals, it may have great chances to not be detected even by close sweeps with the camera detector.
What I'm most surprised about is just how well it actually works... I did not think such EM fluctuations would be usably detectable from several meters away... but I suppose this may be moreso due to improper/lack of shielding in the first place, which I would think should be easily fixable in most products to mitigate this type of detection.
With a bit of practice it's actually quite easy to understand the accent of Chinese speakers as they have some typical patterns and speak slowly.
I must say, I loved listening to him because this was genuine human work. Human made slides (with lots of ugliness coming with PowerPoint), human typos, human grammar mistakes, all of it. It may be flawed in some ways but this fully removed any doubts that a slop machine came even near it. So refreshing in this day and age!
> they can be disgusted
I think the speaker genuinely gets that word wrong; a malapropism (as opposed to the auto-generated English subtitles getting it wrong).
You can also have opto-mechanical listening devices where the electronics are 100 m away. There is a vibrating membrane at one end, and a laser through the fiber reads the vibrations.
IIUC, the EMR increases following scene changes (like a light being turned on or off) are a result of the fact that video codecs try hard to compress similar images. So, I speculate that an "extremely bad codec" that simply dumps raw pixels to storage would not produce such variation, and therefore remain undetectable?
A better mitigation might be to take a leaf from cryptography and develop a constant-time codec.
Long story short: I'd like this device please.
A consumer-grade device to perform a quick run over my hotel/airbnb that detects 90% (or even 50%) of hidden cameras would be useful because the status quo (doing nothing) detects ~0%.