{"id":798,"date":"2026-07-28T01:32:11","date_gmt":"2026-07-28T05:32:11","guid":{"rendered":"https:\/\/constantinpoindexter.com\/blog\/?p=798"},"modified":"2026-07-28T01:35:14","modified_gmt":"2026-07-28T05:35:14","slug":"hey-tscm-crew-the-cable-was-always-talking","status":"publish","type":"post","link":"https:\/\/constantinpoindexter.com\/blog\/hey-tscm-crew-the-cable-was-always-talking\/","title":{"rendered":"Hey TSCM Crew! The Cable Was Always Talking"},"content":{"rendered":"\n<p><strong>TrojPix, TEMPEST, and the Eternal Return of the Compromising Pixel, my counterintelligence reading for those who own more than one spectrum analyzer<\/strong><\/p>\n\n\n\n<p>Every eighteen months or so, the security-adjacent internet rediscovers that copper radiates. There is a burst of excitement, a headline containing the word &#8220;unhackable&#8221; in scare quotes, and a great many people who have never held a near-field probe explaining to one another that air-gapped systems are now obsolete. Then everyone goes back to leaving the SCIF door propped open with a fire extinguisher.<\/p>\n\n\n\n<p>This cycle&#8217;s entry is TrojPix, and credit where it is due, a good paper. It is not, however, a game-changer.<\/p>\n\n\n\n<p><strong>What the researchers actually did<\/strong><\/p>\n\n\n\n<p>TrojPix comes out of Shandong University and Quan Cheng Laboratory, authored by Guoming Zhang and colleagues, and is accepted to the 35th USENIX Security Symposium (Zhang et al. 2026). The mechanism is elegant in its parsimony. Digital video interfaces encode pixel data using Transition-Minimized Differential Signaling, and TMDS (being a high-speed switching serial protocol over unbalanced-enough copper) radiates. Everyone has known this since the 80s.<\/p>\n\n\n\n<p>The contribution is that the authors demonstrate the mapping is deterministic and controllable. Modify pixel values in a way the human visual system cannot resolve, the canonical example being the least significant bit of the blue channel, and you produce a predictable, addressable change in the electromagnetic signature on the cable. The display becomes a modulator. The cable becomes the antenna. User-mode malware becomes a transmitter without touching a driver, a device, or an administrator&#8217;s password.<\/p>\n\n\n\n<p>They evaluated across nine COTS monitor manufacturers and fifteen COTS video cables, in two operational modes: fake screen-off, in which the display appears dark while continuing to transmit, and foreground embedding, in which the payload rides inside whatever the user is legitimately looking at. Reported results: peak throughput of 8.1 Mbps, maximum range of 208 meters, average bit correct rate around 99 percent, and structural similarity indices of 0.998\u20130.999 with a fifty-person perceptual study in which nobody noticed anything (Zhang et al. 2026). The prior state of the art in this niche managed 21.6 kbps at 87.5 meters (The Hacker News 2026). That is genuinely good engineering. Now let us be adults about it.<\/p>\n\n\n\n<p><strong>The 8.1 Mbps that does not exist at 208 meters<\/strong><\/p>\n\n\n\n<p>The single most-repeated distortion in the coverage, and in every breathless social media repost, is the implicit bundling of peak throughput and maximum range into one system. They were measured separately, a point The Hacker News (2026) had the discipline to state explicitly and almost nobody else did.<\/p>\n\n\n\n<p>This should be obvious to anyone who has ever done a link budget. Channel capacity is a function of signal-to-noise ratio. SNR falls off with distance, and the emission in question is an unintended one, meaning the transmit power is whatever leaked out of a cable that was designed to comply with FCC Part 15 and CISPR 32. You do not get megabit rates at two hundred meters off parasitic radiation. You get megabit rates in the lab at short standoff, and you get the two-hundred-meter figure at a data rate that would embarrass a 1200-baud modem. Both numbers are true. A sentence containing both of them is NOT.<\/p>\n\n\n\n<p><strong>The receiver is not in anyone&#8217;s pocket<\/strong><\/p>\n\n\n\n<p>The reporting indicates the collection side used a USRP X310 with a directional antenna and a low-noise amplifier. That is several thousand euros of gear, commercially available, but not a dongle taped to a Raspberry Pi in a hedge (HackingPassion 2026). This matters enormously, and it matters in the counterintelligence\/countermeasures favor.<\/p>\n\n\n\n<p>Think about what the adversary&#8217;s collection geometry actually requires: a stable, powered, aimed platform maintaining a favorable path to a specific building elevation, for however long the exfiltration takes, without being noticed. That is not a cyber problem. That is a physical surveillance detection problem, i.e., the discipline in which our C.I. community has ninety years of institutional practice. The attack has not defeated the perimeter. It has converted the adversary&#8217;s problem into one that is squarely inside your area of competence, and made it harder for him, because now he has to bring an ice cream truck or telco-looking van. <\/p>\n\n\n\n<p><strong>Priority, or: read your own literature<\/strong><\/p>\n\n\n\n<p>Wim van Eck (1985) published the foundational demonstration that video display emanations could be reconstructed at a distance. Thirteen years later, Markus Kuhn and Ross Anderson described &#8220;Soft Tempest&#8221;, and here it is worth quoting their own framing of the attack case, malicious code encoding stolen information in a machine&#8217;s RF emissions, optimized for some combination of reception range, receiver cost, and covertness, specifically via the video cable (Kuhn and Anderson 1998, 124\u201342). Kuhn&#8217;s dissertation extended this to displays generally (Kuhn 2003), Loughry and Umphress (2002) did the optical analogue, and Mordechai Guri has spent a decade industrializing the entire genre, most relevantly with PIXHELL, which modulates pixel patterns to produce acoustic emissions from LCD coils and capacitors (Guri 2024).<\/p>\n\n\n\n<p>TrojPix is Soft Tempest with twenty-eight years of better DSP, a modern SDR, and a proper imperceptibility evaluation. That is a real contribution. It is an engineering delta, not a conceptual one, and describing it as a &#8220;new air-gap bypass&#8221; is a bit like announcing the discovery of the wheel with rubber on it.<\/p>\n\n\n\n<p><strong>The precondition swallows the finding<\/strong><\/p>\n\n\n\n<p>TrojPix is an exfiltration channel. It is not an access vector. The malware must already be resident on the isolated host, which means it arrived by the ordinary routes, i.e., a dirty thumbdrive, supply chain, firmware, a human being with a badge and a grudge, etc. Stuxnet and Agent.BTZ crossed air gaps on USB drives, not over radio.<\/p>\n\n\n\n<p>So the risk equation is unchanged in its dominant term. If the adversary can get arbitrary code onto an isolated machine, you have a very serious problem already. The interesting question was never whether he could get the data out. It was whether he could get 400 megabytes out in six minutes instead of dribbling an AES key over a weekend. TrojPix improves his egress bandwidth. It does not improve his ingress.<\/p>\n\n\n\n<p><strong>The threat model wanders off the reservation<\/strong><\/p>\n\n\n\n<p>The paper, and every article about it, invokes military command centers, nuclear control systems, and financial institutions. Note what was actually tested, i.e., consumer monitors from Dell, Samsung, LG, AOC, Philips, Lenovo, TCL, Huawei, and Redmi, and fifteen commodity cables (Cyber Press 2026). Facilities that genuinely hold the data being invoked do not run Redmi panels on unshielded HDMI. They run inspectable-space doctrine, RED\/BLACK separation, shielded enclosures, and equipment procured against emanation-security criteria, i.e., the framework that has existed since NSTISSAM TEMPEST\/1-92 and its national equivalents. If your accredited space is leaking recoverable TMDS at 208 meters, TrojPix is not your problem. You&#8217;ve f.  up and your accreditation is. Conversely, in the open-plan office where those Redmi monitors actually live, there is a wireless network and the adversary will simply use it, because he is not a masochist.<\/p>\n\n\n\n<p><strong>What the sweep community should actually take away are three things, none of which fit in a post, but here we go.<\/strong><\/p>\n\n\n\n<p>The emission is physics, so the countermeasures are physical. Fiber-optic video links carry no exploitable copper transient. Shielding, zone control, and RF jamming of the relevant band remain the answers they have always been. No patch removes Maxwell&#8217;s equations from the environment.<\/p>\n\n\n\n<p>Deliberate modulation is, paradoxically, easier to catch than passive leakage. A van Eck emanation is an unstructured artifact. A TrojPix emission is a structured, periodic, deliberately regular signal bearing a fixed relationship to the pixel clock. Structure is what your analyzer is for. The implication is not that sweeps are futile; it is that episodic sweeps are futile and persistent spectrum monitoring against a characterized baseline is not.<\/p>\n\n\n\n<p>The fake-screen-off mode is a gift. A monitor that is off should not be receiving an active TMDS stream. That is a host-side, software-detectable state inconsistency, and it costs nothing to instrument. The stealthiest mode in the paper is also the one with the loudest logical tell.<\/p>\n\n\n\n<p>The authors withheld operational detail and initiated disclosure with cable manufacturers, and nothing resembling this has been observed in the wild (HackingPassion 2026). It is laboratory work mapping the boundary of the physically possible, which is precisely what USENIX exists to publish.<\/p>\n\n\n\n<p>I am recognizing here and <a href=\"https:\/\/constantinpoindexter.com\/blog\" target=\"_blank\" rel=\"noopener\" title=\"sharing\">sharing<\/a> that the air gap was never a control. It is a topology. Anyone who mistook it for a control had a problem long before a graduate student in Jinan started flipping the blue channel. So, no. A collector can&#8217;t just sit 200m away and read your mail, but, . . . <\/p>\n\n\n\n<p>~&nbsp;<a href=\"https:\/\/www.linkedin.com\/in\/constantinpoindexter\" target=\"_blank\" rel=\"noreferrer noopener\">C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA\/NCISS OSINT certification, DoD\/DoS BFFOC Certification<\/a><\/p>\n\n\n\n<p><strong>Bibliography<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cyber Press. 2026. &#8220;TrojPix Attack Uses Imperceptible Pixels to Steal Data From Air-Gapped Networks.&#8221; July 2026. https:\/\/cyberpress.org\/trojpix-attack-air-gapped\/.<\/li>\n\n\n\n<li>Guri, Mordechai. 2024. &#8220;PIXHELL Attack: Leaking Sensitive Information from Air-Gap Computers via &#8216;Singing Pixels.'&#8221; Offensive Cyber Research Lab, Ben-Gurion University of the Negev.<\/li>\n\n\n\n<li>HackingPassion. 2026. &#8220;TrojPix Steals Data From Air-Gapped Computers Through the Screen.&#8221; July 2026. https:\/\/hackingpassion.com\/trojpix-air-gap-attack\/.<\/li>\n\n\n\n<li>Kuhn, Markus G. 2003. &#8220;Compromising Emanations: Eavesdropping Risks of Computer Displays.&#8221; PhD diss., University of Cambridge. Technical Report UCAM-CL-TR-577.<\/li>\n\n\n\n<li>Kuhn, Markus G., and Ross J. Anderson. 1998. &#8220;Soft Tempest: Hidden Data Transmission Using Electromagnetic Emanations.&#8221; In Information Hiding: Second International Workshop, IH&#8217;98, edited by David Aucsmith, 124\u201342. Lecture Notes in Computer Science 1525. Berlin: Springer.<\/li>\n\n\n\n<li>Loughry, Joe, and David A. Umphress. 2002. &#8220;Information Leakage from Optical Emanations.&#8221; ACM Transactions on Information and System Security 5 (3): 262\u201389.<\/li>\n\n\n\n<li>Poller, Jack. 2026. &#8220;When &#8216;Air-Gapped&#8217; Stops Meaning Anything: What TrojPix Should Teach Every CISO.&#8221; Security Boulevard, July 8, 2026. https:\/\/securityboulevard.com\/2026\/07\/when-air-gapped-stops-meaning-anything-what-trojpix-should-teach-every-ciso\/.<\/li>\n\n\n\n<li>The Hacker News. 2026. &#8220;New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions.&#8221; July 2026. https:\/\/thehackernews.com\/2026\/07\/new-trojpix-attack-leaks-data-from-air.html.<\/li>\n\n\n\n<li>van Eck, Wim. 1985. &#8220;Electromagnetic Radiation from Video Display Units: An Eavesdropping Risk?&#8221; Computers &amp; Security 4 (4): 269\u201386.<\/li>\n\n\n\n<li>Zhang, Guoming, Huiting Zhang, Zhenwei Lu, Heqiang Fu, Xin Gao, Riccardo Spolaor, Yetong Cao, Yanni Yang, and Pengfei Hu. 2026. &#8220;TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel Modulation.&#8221; In Proceedings of the 35th USENIX Security Symposium. Berkeley, CA: USENIX Association. https:\/\/www.usenix.org\/conference\/usenixsecurity26\/presentation\/zhang-guoming.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>TrojPix, TEMPEST, and the Eternal Return of the Compromising Pixel, my counterintelligence reading for those who own more than one spectrum analyzer Every eighteen months or so, the security-adjacent internet rediscovers that copper radiates. There is a burst of excitement, a headline containing the word &#8220;unhackable&#8221; in scare quotes, and a great many people who &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/constantinpoindexter.com\/blog\/hey-tscm-crew-the-cable-was-always-talking\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Hey TSCM Crew! The Cable Was Always Talking&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":800,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[85,208,73,40,74,149,341,209,75,342],"class_list":["post-798","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-c-constantin-poindexter","tag-cia","tag-counterespionage","tag-counterintelligence","tag-countermeasures","tag-dia","tag-hey-tscm-crew-the-cable-was-always-talking","tag-nsa","tag-spy","tag-tscm"],"aioseo_notices":[],"rttpg_featured_image_url":{"full":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking.png",1672,941,false],"landscape":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking.png",1672,941,false],"portraits":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking.png",1672,941,false],"thumbnail":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking-150x150.png",150,150,true],"medium":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking-300x169.png",300,169,true],"large":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking-1024x576.png",525,295,true],"1536x1536":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking-1536x864.png",1536,864,true],"2048x2048":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking.png",1672,941,false],"twentyseventeen-featured-image":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking.png",1672,941,false],"twentyseventeen-thumbnail-avatar":["https:\/\/constantinpoindexter.com\/blog\/wp-content\/uploads\/2026\/07\/Hey-TSCM-Crew-The-Cable-Was-Always-Talking-100x100.png",100,100,true]},"rttpg_author":{"display_name":"C. Constantin Poindexter","author_link":"https:\/\/constantinpoindexter.com\/blog\/author\/constantin-poindexter\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/constantinpoindexter.com\/blog\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","rttpg_excerpt":"TrojPix, TEMPEST, and the Eternal Return of the Compromising Pixel, my counterintelligence reading for those who own more than one spectrum analyzer Every eighteen months or so, the security-adjacent internet rediscovers that copper radiates. There is a burst of excitement, a headline containing the word &#8220;unhackable&#8221; in scare quotes, and a great many people who&hellip;","_links":{"self":[{"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/posts\/798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/comments?post=798"}],"version-history":[{"count":2,"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/posts\/798\/revisions"}],"predecessor-version":[{"id":802,"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/posts\/798\/revisions\/802"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/media\/800"}],"wp:attachment":[{"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/media?parent=798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/categories?post=798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/constantinpoindexter.com\/blog\/wp-json\/wp\/v2\/tags?post=798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}