Even a sealed-off computer can leak secrets through faint radio emissions
Cutting a machine off from every network does not make it private. Its circuits give off weak electromagnetic signals, and a listener nearby can reconstruct what it is doing. The US National Security Agency wrote a specification, codenamed TEMPEST, covering exactly this kind of attack, one of many ways computers betray their owners.
Security people separate a few ideas. A vulnerability is a flaw in how a system is built or run, and most known ones are catalogued in the Common Vulnerabilities and Exposures database. It becomes exploitable once someone has working code that abuses it. A threat is anything that could harm hardware, software or data, and the person behind it is a threat actor, better known in the press as a hacker. Protection is not purely digital either: plain metal locks still guard against tampering.
Malicious software comes in distinct species. A virus hijacks another program and copies itself, but only spreads when someone opens the infected file; a worm needs no help from anyone. Trojan horses pose as useful software, spyware such as keyloggers records every keystroke, and scareware uses alarming pop-ups claiming the law has been broken. Ransomware scrambles files and demands payment, usually in Bitcoin. Other attacks need no malware at all: a denial-of-service assault can lock a victim out simply by entering the wrong password repeatedly, and distributed versions harness botnets of hijacked machines, which are far harder to block than one address.
Eavesdropping is especially sneaky because it barely slows anything down. Attackers can plant listening software, leave, and return later to collect what it gathered. The FBI and NSA used tools named Carnivore and NarusInSight to monitor internet providers. In man-in-the-middle attacks, an intruder impersonates one side of a conversation, for example by faking a Wi-Fi network name, sometimes called a Pineapple attack after a popular gadget.
Who gets hit varies. A UK government report in April 2023, surveying 2,263 businesses, 1,174 charities and 554 education institutions, found 32 percent of businesses and 24 percent of charities recalled a breach in the previous year. The rate was 69 percent among large businesses, while home users mostly face untargeted attacks cast as widely as possible.
Source: Computer security