HACKER Q&A
📣 pyinstallwoes

How can there be cybersecurity in the long run if a screen renders text?


From the perspective of any payload reaching a user, isn't all cybersecurity open to attack vector once anything is rendered on the screen?

Then that means a sufficiently advanced attacker can compromise all information by reading electromagnetic signals within the physical boundary of where the user _physically_ is and or additionally with any injection at the software or comms level.

Is this a problem that can be solved? Any radical ideas that have been suggested?


  👤 dragonwriter Accepted Answer ✓
> Then that means a sufficiently advanced attacker can compromise all information by reading electromagnetic signals within the physical boundary of where the user _physically_ is

If an attacker can comprehensively monitor all EM signals where the target is, that pretty much eliminates all information (not jist cyber) security.

Sure, it means they can read your screen, but it also means they can read the paper on your desk, too.

Real attackers tend not to have omnidirectional high resolution full-EM-spectrum imagers in the target location.

Realistic threats mostly have countermeasures; identifying the actual threat model faces, risks associated with your data, and which countermeasures are appropriate and worthwhile is...what the security profession does, and its a continuous arms race with attackers.

If your standard for security is a 100% guarantee against unauthorized egress or insertion of data, no, nothing can guarantee that (but your biggest threats are probably still authorized users, not exotic external attacks, even if you are a high-value, government target.)



👤 retrac
As described, it seems to be essentially the same attack as someone physically in a vault with secret papers. Buy a good lock and hire some guards?

👤 wmf
No, reading stuff off a screen is not a problem; it won't let you bypass authentication or achieve remote code execution.