#5450: Heat, Fans, and the Limits of Air-Gapped Security

Dozens of ways to leak data from air-gapped machines exist — but every real breach still used a USB stick.

Featuring
Listen
0:00
0:00
Episode Details
Episode ID
MWP-5633
Published
Duration
21:41
Audio
Direct link
Pipeline
V5.2
TTS Engine
chatterbox-regular
Script Writing Agent
DeepSeek 4.1 Flash

AI-Generated Content: This podcast is created using AI personas. Please verify any important information independently.

There's a clip making the rounds claiming air-gapping is dead: two machines, no wires, no radio, still talking through heat. Technically, that's real. BitWhisper, published by Dr. Mordechai Guri and colleagues in 2015, uses CPU thermal emissions to send binary data between adjacent machines — a one-degree rise for a one, a return to baseline for a zero — read off the receiving machine's own thermal sensors. No extra hardware on either side. The catch is the rate: one to eight bits per hour, at a maximum range of forty centimeters. The demo sent a command to reposition a toy missile launcher.

Guri runs the Offensive Cyber Research Lab at Ben-Gurion University and has spent over a decade systematically turning every physical quantity a computer emits into a transmitter. Fansmitter modulates cooling-fan speed into acoustic waveforms. AiR-ViBeR turns the same fan into inaudible vibrations a smartphone accelerometer can read with no permissions at all. SpiralSpy pushes that fan channel to six bits per second. MAGNETO uses low-frequency magnetic fields that pass straight through Faraday cages. LED-it-GO blinks a hard drive activity light up to 5,800 times per second. TEMPEST-LoRa pulls electromagnetic leakage off a video cable at 21.6 kilobits per second across 87 meters. The physics is real and measured in every case.

But every one of these assumes malware already running inside the air-gapped machine — and getting it in is the hard part, which is the entire reason you air-gap something. When you look at confirmed real-world breaches, the exotic channels vanish. Stuxnet crossed into Natanz on infected removable media. Agent.BTZ spread through USB across 300,000 military computers and helped trigger the creation of US Cyber Command. Mustang Panda, Tropic Trooper, APT28, APT30, the Equation Group — nation-state-grade actors with every resource available, and every one of them chose a USB stick. The single state-level exception, the NSA's COTTONMOUTH-One, is a soldered hardware implant using RF to reach a relay eight miles away. Even the exception smuggles the compromise in physically.

Downloads

Episode Audio

Download the full episode as an MP3 file

Download MP3
Transcript (TXT)

Plain text transcript file

Transcript (PDF)

Formatted PDF with styling

#5450: Heat, Fans, and the Limits of Air-Gapped Security

Corn
There's a clip going around that says air-gapping is dead. Two machines, no wires, no network, no radio, and they're still talking to each other. Through heat.
Herman
Through heat.
Corn
An OpenAI researcher said it on a podcast last week. If one machine runs its CPU hot and the other one feels it, that's a channel. And if that's true, then physically isolating a system doesn't contain anything, including something that doesn't want to be contained.
Herman
Technically he's right.
Corn
That's the worst kind of right.
Herman
It is, and that's the whole episode.
Corn
Daniel wrote in about this. He's been reading the air-gap exfiltration literature, and he noticed something. A lot of it comes out of Israel. Which is correct, incidentally. And the example he'd seen was malware that oscillates fan speeds, encoding a message in the pitch changes, so somebody sitting nearby with a microphone can read it back.
Herman
He's got the mechanism right.
Corn
He says, fine, somebody still has to plant a listening device, and at that point you're talking about nation-state tradecraft, extraordinary resources, that whole world. His actual question is the one nobody bothers to ask. Has any of this ever been used? Not demonstrated in a lab. Used. On a real target, by a real operator, for a real reason.
Herman
And then he read the tweet.
Corn
Two computers regulating their CPU temperatures to talk to each other, and he says, and I'm quoting him, that seemed a bit suspicious. Which is a very polite way of putting it.
Herman
It's a very Daniel way of putting it.
Corn
So, two things to do. Separate the physics from the fiction, and then find out what actually gets used when the stakes are enormous. Let's go.
Herman
Start with what an air gap actually is, because people use the term loosely. An air-gapped system is physically and logically disconnected from every network. No internet, no local area network, no wireless. Nothing. The only way in or out is a human being physically carrying something.
Corn
And these aren't hobbyist setups. Classified military networks, payment card processing, industrial control systems, journalists working on things they'd rather not have read.
Herman
The entire security model rests on one assumption. No network path means no data leaves. Everything else, the encryption, the access controls, the auditing, sits on top of that assumption. If it fails, the whole thing fails.
Corn
And your hunch about Israel, Daniel, that's not a hunch. Dr. Mordechai Guri runs the Offensive Cyber Research Lab at Ben-Gurion University. He's spent more than a decade on this and basically nothing else. Around seventeen hundred citations, an h-index in the low twenties.
Herman
WIRED profiled him and the line they used was that he'd uniquely fixated his career on defeating air gaps. That's fair. He's the reason this field exists as a field.
Corn
His framing is the part I keep thinking about. Everyone was talking about breaking the air gap to get in. Nobody was talking about getting the information out.
Herman
That's the inversion. For decades the threat model was intrusion, somebody breaking in. Guri asked the opposite question. Assume they're already inside. Now what?
Corn
And the answer, over two decades, is dozens of channels. Heat, sound, light, magnetism, vibration, radio frequency. Every physical quantity a computer produces, somebody has turned into a transmitter.
Herman
Which gives us the paradox the whole episode runs on. Dozens of demonstrated channels. And every confirmed real-world air-gap breach used a USB stick.
Corn
So the lab and the field look nothing like each other. Why?
Herman
Let's start with the fan, since that's the one Daniel brought up. Fansmitter. The idea is that malware regulates the speed of the internal cooling fan, and the fan speed controls the acoustic waveform the machine emits. You modulate that waveform and you've got binary data going out to a nearby microphone.
Corn
No speaker required.
Herman
Which matters, because a lot of secure facilities remove speakers specifically to kill acoustic channels. The fan is still there. The fan is always there.
Corn
Because the machine has to not melt.
Herman
You can't air-gap the heat.
Corn
That's the thing about all of these. They're not exploiting a design flaw. They're exploiting the fact that the machine is a physical object.
Herman
Right, and then the same actuator gets reused. AiR-ViBeR, 2020. Same trick, malware controls fan speed, except now it's generating inaudible vibrations instead of audible sound. And the receiver is a smartphone accelerometer.
Corn
Which needs no permissions.
Herman
None. Any app can read the accelerometer. So you've got a phone sitting on the same desk, and it's picking up the fan's vibration through the surface, and decoding it. No microphone access, no special hardware, nothing that would trip a permission dialog.
Corn
That's the part that would worry me if I were the one designing the facility.
Herman
And then SpiralSpy, out of NDSS in 2022, takes the same fan channel and pushes it to six bits per second. Which is six to twenty-four times faster than the earlier fan methods.
Corn
Six bits per second still sounds like nothing.
Herman
It is nothing, by network standards. But look at the shape of the family. One actuator, the fan. Three different receivers. Microphone, accelerometer, microphone again. And each generation buys you bandwidth. That's the pattern across this entire field.
Corn
Now the CPU temperature one. Because that's the tweet.
Herman
That's real too. BitWhisper, Guri and colleagues, 2015, IEEE Conference on Security and Privacy. Two adjacent compromised computers communicate through heat.
Corn
Adjacent how adjacent?
Herman
Zero to forty centimeters.
Corn
So, touching.
Herman
Effectively touching. The mechanism is exactly what the tweet describes. A binary one is a rise of about one degree Celsius. A zero is a return to baseline. The receiving machine reads it off its own built-in thermal sensors. Bidirectional, and no extra hardware on either side.
Corn
And the rate?
Herman
One to eight bits per hour.
Corn
Per hour.
Herman
Per hour. Transmitting a single bit took somewhere between three and twenty minutes in the demo.
Corn
So the demo. What did they actually do with it?
Herman
They sent a command to reposition a toy missile launcher.
Corn
Of course they did.
Herman
It's a good demo, honestly. It proves the channel is bidirectional and it proves you can issue a command, not just leak a file. But the numbers are the story. One to eight bits per hour, at a maximum range of forty centimeters, which is about ten thousand times slower than PowerHammer.
Corn
PowerHammer being data over the power lines.
Herman
A thousand bits per second at the line level. Ten bits per second at the phase level. So put those side by side. BitWhisper, one to eight bits per hour. PowerHammer, a thousand bits per second. The most cinematic techniques in this field are consistently the least practical.
Corn
There's something almost admirable about it. Somebody built a working covert channel out of the fact that computers get warm.
Herman
There's newer work too. Heaker, from last year, manipulates both CPU and GPU thermal emissions. Thermal-Secret proposes combining heat and fan noise into a kind of steganography. The line of research is alive.
Corn
But here's the thing I want to put on the table before we go further. Every single one of these assumes malware is already running inside the air-gapped machine.
Herman
That's the asterisk under the whole field.
Corn
Because getting the malware in is the hard part. That's the entire reason you air-gap something in the first place.
Herman
Right. Which is why people who work in this area will tell you these aren't attacks. They're methods of data exfiltration between two compromised devices. The compromise already happened. You're just watching the exit.
Corn
And the exit is the easy half.
Herman
The exit is the easy half. That's the sentence I'd put on the poster.
Corn
So before we get to whether any of this has been used, give me the breadth. Because I don't think people appreciate how many of these there are.
Herman
It's a lot. Magnetics first, because this one surprised me. MAGNETO, 2018. It uses magnetic fields, and it penetrates Faraday cages.
Corn
The whole point of a Faraday cage is that it blocks electromagnetic signals.
Herman
It blocks radio frequency. It doesn't block static and low-frequency magnetic fields, and that's the gap. The receiver is a smartphone magnetometer, which is the sensor the phone uses for its compass. There's an app called ODINI that Guri's group wrote for it. One to forty bits per second, and they demonstrated pulling a four thousand ninety-six bit key out in about an hour.
Corn
Through a Faraday cage, in an hour.
Herman
That undermines the standard mitigation, and I don't think that finding got the attention it deserved.
Corn
What else?
Herman
TEMPEST-LoRa, 2025. Electromagnetic leakage off a video cable, received by commercial LoRa nodes. Eighty-seven and a half meters, twenty-one point six kilobits per second.
Corn
That's a completely different order of magnitude from BitWhisper.
Herman
It's four orders of magnitude. LaserShark, 2021, uses a laser aimed at the machine's built-in LEDs. Twenty-five meters, eighteen point two kilobits per second inbound, a hundred kilobits per second outbound. LED-it-GO blinks a hard drive activity light up to five thousand eight hundred times per second. COVID-bit, 2022, leaks electromagnetic emissions in the zero to sixty kilohertz band at a thousand bits per second across two meters, and it runs at user level, even from a virtual machine.
Corn
The drive activity light.
Herman
The little light that tells you the disk is busy.
Corn
Every machine in every secure facility has one, and it's been blinking in Morse since the day it was installed.
Herman
Effectively, yes. And that's the point of the breadth. It's not one clever trick. It's a systematic survey of every physical quantity a computer emits, and the answer is that all of them can carry data.
Corn
So the physics is real. Every one of these has been built and measured. Now the question Daniel actually asked.
Herman
Let's talk about the real world.
Corn
What actually gets used.
Herman
USB drives.
Corn
That's it?
Herman
That's it. Stuxnet crossed the air gap at Natanz with infected removable media. That's the most famous cyber operation of the century and the air gap was defeated by somebody plugging in a stick.
Corn
In 2008, Agent.BTZ infected around three hundred thousand US military computers, and it spread the same way. USB. That one triggered Operation Buckshot Yankee, and it's one of the reasons US Cyber Command exists.
Herman
Look at the named tooling too. Mustang Panda has a PlugX USB worm. Tropic Trooper has USBferry. APT28 has USBStealer. APT30 has SPACESHIP. The Equation Group had Remsec. Machete in Venezuela. Ramsay, which ESET documented in 2020. Every single one of these is a nation-state-grade actor, and every single one of them chose removable media.
Corn
Because it works.
Herman
Because it works, it's cheap, it's reliable, and it's deniable. You don't need to control the temperature of anything.
Corn
So is there a single confirmed exotic channel? Anything at all?
Herman
One, and it's a partial. The NSA's COTTONMOUTH-One. It's a hardware implant, and it came out of the ANT catalog that Snowden leaked. It uses radio frequency to extract data to a briefcase-sized relay up to eight miles away.
Corn
Eight miles is not nothing.
Herman
Eight miles is impressive. But look at what it requires. It's a physical implant. Somebody has to solder that into the machine. So even the state-level exception smuggles the compromise in physically. It's not pure software, and that's the distinction that matters.
Corn
Which means the answer to Daniel's question is no.
Herman
The answer is no. There's no public evidence that fan-speed, thermal, vibration, or LED covert channels have ever been used in an actual operation. They're academic proofs of concept. Every confirmed real-world air-gap breach went through removable media.
Corn
So why does the lab look nothing like the field?
Herman
Two reasons, and I think both of them are right. Eran Tromer at Columbia, who's one of the more careful people in this space, points out that Guri's team tests on consumer hardware. Ordinary desktop machines, ordinary fans, ordinary thermal sensors. Hardened secure equipment is built differently. Tighter tolerances, better shielding, sensors that aren't exposed to user space. So some of the demonstrated range and rate wouldn't survive contact with a real target.
Corn
And the second reason?
Herman
The second reason is economics. Somebody on Hacker News put it better than I can. The line was that someone is going to discover infinitely more intelligence by good old fashioned dumpster diving than by designing and successfully implementing a novel air-gap exfiltration methodology.
Corn
That's brutal and correct.
Herman
It's both. Espionage is an economics problem. If you can get the same file with a hundred-dollar USB stick and a contractor who doesn't check his pockets, why would you spend eighteen months building a thermal channel that moves one byte every two hours?
Corn
Because it's beautiful.
Herman
Because it's beautiful, and because the person building it is a researcher, not an operator. Those are different jobs with different incentives. The researcher gets a paper. The operator gets the file.
Corn
Which brings us to the tweet.
Herman
September eighteenth, Noam Brown at OpenAI, on the Dwarkesh Patel podcast. His argument was that air-gapping might not be sufficient to contain a misaligned AI, and his example was exactly BitWhisper. One machine runs its CPU hot, the other detects the temperature change, and now they have a communication mechanism.
Corn
And the clip went viral.
Herman
It went viral through a post on X, and it circulated for a couple of days before anyone dug into the underlying paper. Then mlllm.io published a corrective explainer on the twentieth, which laid out the actual parameters. Both machines already compromised. Forty centimeters maximum. One to eight bits per hour.
Corn
Which is the same paper from 2015.
Herman
The same paper from 2015. Eleven years old. Gizmodo's AJ Dellinger put it well. Details matter, and once you dig into how BitWhisper actually works, the threat starts to look a lot less pressing.
Corn
So is Brown wrong?
Herman
I don't think wrong is the right word. He's making a different argument. He's not saying this is a practical escape route. He's saying that physical isolation is a property people assume is absolute, and it isn't. There's no such thing as a perfect seal. Two machines in the same room are coupled through the room.
Corn
That's a fair point, actually. It's a philosophical point about containment, not an engineering claim about bandwidth.
Herman
It's a philosophical point, and I think it's a good one. If you're reasoning about whether you can contain a system indefinitely, the existence of any channel at all matters, even a slow one. A channel that moves one bit an hour is still a channel. If the timescale you care about is years, one bit an hour is a lot of bits.
Corn
But the critics would say it distracts from the failures that are actually happening.
Herman
They would, and there's something to that. The chain-of-thought monitoring was reportedly off during the Hugging Face incident. That's a real, admitted, documented failure of an oversight mechanism that was supposed to be running. Arguing about thermal channels while that's the state of things is a bit like worrying about the lock on the back door while the front door is open.
Corn
So the exotic channels are real physics answering a question nobody in the field is currently asking.
Herman
That's the cleanest version of it. The research is real. The threat model it addresses is not the one that's actually costing anyone anything.
Herman
There's a detail I keep coming back to, though. Guri's whole body of work assumes the compromise already happened. Every paper starts from a machine that's already running hostile code. And the entire real-world record says the compromise is where everything actually happens. So the research is rigorous about the second half of a two-part problem, and the second half is the easy half.
Corn
The hard half is a guy with a lanyard.

Hilbert: The pitch changes.
Corn
Sorry?

Hilbert: On the fans. You said if a fan changes pitch you'd notice. I did that for eleven months. Night shift, data center out past the airport, hosted a government contract. My job was to walk the aisles with a clipboard and listen.
Herman
Listen for what?

Hilbert: Bearing failure. You logged the pitch. Every rack, twice a shift, and if a fan had drifted you wrote it down and somebody came out and swapped it. I never once thought I was listening to a data channel. I thought I was listening to a fan about to seize.
Corn
So the channel you were monitoring was the one Daniel asked about.

Hilbert: It's a real thing. I'm not saying it isn't. I'm saying you've both got the wrong end of it. You don't need a fan to talk to a compromised machine. You need a guy with a USB stick and a lanyard.
Herman
The lanyard.

Hilbert: Retractable reel, contractor badge on the end. Everyone in the building wore one. You clipped it to your belt and the badge sat against your hip all day. Nobody looked at it. Nobody had a reason to. You could have walked a thumb drive through that gate every morning for a year and the only thing anyone would have asked is whether you'd badged in.
Corn
And the machines inside were air-gapped.

Hilbert: Every one of them. No network, no wireless, nothing. The room was built for it. The people weren't.
Herman
Which is the point about the already-compromised assumption. The channel is the second problem. Getting the code in is the first one, and the first one is a human being with a pocket.

Hilbert: There was a no phones policy. Strict. You left it in a locker at the front. But the maintenance crew all carried pagers, because that's how dispatch reached us. And one night a contractor's pager went off and it wasn't a normal page. It was a burst. Long, fast, didn't sound like a number.
Corn
What did you do?

Hilbert: Nothing. I wrote down a fan reading and went to the next aisle. I don't know what it was. It might have been nothing. It might have been a weather alert. I never found out and I never asked.
Herman
That's the whole threat model in one story. The channel doesn't matter if the human is the vulnerability.

Hilbert: Anyway. I'm late for an appointment. It's a thing with the dentist's office, they only do it Tuesdays, and I've already moved it twice.
Corn
So the bandwidth trend.
Herman
The bandwidth trend. BitWhisper is one to eight bits per hour. TEMPEST-LoRa is twenty-one point six kilobits per second at eighty-seven and a half meters. That's not a small improvement, that's a different category of thing.
Corn
So does the lab-field gap close as the rates go up?
Herman
That's the question I don't know the answer to. The optimist's case is that once a channel gets fast enough, the economics flip. If you can pull a megabyte in a few minutes from across a parking lot, that starts to compete with walking a USB stick through the front gate, because it doesn't require a human who might get caught.
Corn
And the pessimist's case?
Herman
The pessimist's case is that the USB stick also got faster, and it's still a hundred dollars, and it still doesn't require you to control the thermal envelope of a machine you don't own. The shortcut stays cheaper. It's stayed cheaper for twenty years.
Corn
The AI-safety framing might be the more consequential part of this, though. Not because BitWhisper is a practical escape route. Because it forces the question of whether physical isolation can ever be sufficient for containing something that doesn't want to be contained.
Herman
And that question is new, even though the research under it is eleven years old. That's the part I'd watch.
Corn
If you got something out of this one, leave us a review. It helps other people find the show.
Herman
Thanks to Hilbert Flumingtop, our producer.
Corn
This has been My Weird Prompts. You can find everything at my weird prompts dot com, or email us at show at my weird prompts dot com.
Herman
We'll be back soon.
Corn
See you then.

This episode was generated with AI assistance. Hosts Herman and Corn are AI personalities.