About Sophie

Cybersecurity, assurance, technology, identity, and life.

“I dare do all that may become a woman. Who dares do more is none.”

New Series: Sophie Baskerville’s History of Cybersecurity

sophie @ baskerville.net ©️1977-2026 Sophie Baskerville

024 | TEMPEST


“Where should this music be? I’ th’ air, or th’ earth?”
William Shakespeare, The Tempest, Act I, Scene II[37]

Collage-style illustration in muted purple, sepia, and charcoal tones representing TEMPEST and side-channel interception during the Cold War. At the centre is a cutaway view of a concrete secure room or bunker. Inside, a man in a dark suit sits at a desk using a typewriter or cipher-related communications equipment beneath a fluorescent light. Around him are filing cabinets, a desk lamp, a wall clock, a world map, and radio or communications gear, suggesting a classified office handling sensitive messages.

The walls, floor, and ceiling of the room are shown sliced open to reveal hidden infrastructure: metal cabling, conduit runs, pipes, and an earth connection descending into the ground. Curving violet signal lines appear to leak outward from the room through the building structure, travelling along cables and into the surrounding space. These glowing lines symbolise unintended electromagnetic or conducted emissions escaping from protected equipment.

To the right, outside the building, another man sits at monitoring equipment on a rooftop or raised position, wearing headphones and watching a glowing oscilloscope-like display. An aerial beside him and other antenna structures in the background suggest remote interception of the leaked emissions. Behind him is a riverfront city skyline at dusk, with a domed building in the distance, reinforcing the atmosphere of covert surveillance in an urban government setting.

Scattered across the composition are additional visual references: antenna diagrams, engineering sketches, signal traces, strips of punched paper tape, blurred ciphertext or teleprinter output, and instrument screens displaying waveforms and spectral patterns. These elements frame the central scene and connect the image to radio engineering, cryptography, signal analysis, and eavesdropping technology. The overall effect is a dramatic visual metaphor for TEMPEST: a secure message being protected cryptographically inside a room, while the surrounding machine and infrastructure reveal information through physical side-channel leakage.

Images in this article are generated by

EU AI Marker icon

EU AI Act Regulation 2024/1689

The cipher worked. Yet the secret escaped.

The previous article asked what an interceptor could learn from a ciphertext. Shannon’s answer was exacting: define the observer, define what they can see, and do not pretend that a difficult calculation is the same thing as missing information.[33]

TEMPEST supplies the awkward next question: What else can the observer see?

Not necessarily with eyes. Perhaps with an antenna, an electrical measurement, or a detector watching changes too fast for a person to notice. A secrecy argument about the intended output says nothing about a second output omitted from the argument.

Imagine a person writing a confidential letter inside a locked office. The finished letter goes into a secure container. Unfortunately, the pressure of the pen has left readable impressions on the sheet beneath it. Nobody opened the container. Nobody defeated its lock. The information escaped through another consequence of writing.

That is an analogy, not a description of radio interception. Its purpose is to separate breaking a protection mechanism from obtaining information by a path the mechanism does not protect.

A computer has to represent information physically to do anything with it. Currents change, voltages change, switching elements operate, and signals travel along interconnections. Some of those changes can couple into nearby circuits or fields. The challenge for an observer is to find a measurable effect that retains something useful about the protected information. The challenge for the defender is to prevent that effect becoming an exploitable channel.[3][6]

There is nothing supernatural about either task. Nor is either task automatically easy.

A name that accumulated meanings

NIST uses TEMPEST for the investigation, study, and control of unintentional compromising emanations from information-processing and telecommunications equipment. The word compromising matters. Detecting that a machine is switched on is not the same as reading a document, although activity itself can sometimes be sensitive.[1]

In the NCSC’s public terminology, TEMPEST relates to passive phenomena; its wider Electromagnetic Security, or EMS, remit can include active techniques used to enhance or extract signals.

Academic papers and popular accounts often use TEMPEST more broadly, including for software deliberately generating a signal. The wider usage is real, but it must not erase the differences between the experiments.[2][12][14]

Throughout this article, the important question is what has to happen at the target. Does it operate normally while somebody listens? Must someone illuminate it with an external signal? Has hardware been implanted? Has malware already taken control of an output? Similar-looking receivers can conceal radically different prerequisites.

The name itself is best described as a cover name, as the declassified NSA history describes it. Elaborate expansions of the letters circulate. A 1995 FAA order even supplies an official expansion, so saying that no official document ever treated it as an acronym would be wrong. But later use of an expansion does not establish how the name originated. The evidence does not justify inventing a naming ceremony.[3][7]

There is also a boundary around the physics. Radio waves and visible light are electromagnetic. Sound is not. Acoustic and vibration attacks belong beside this story because they exploit the same wider failure to account for physical information, not because every form of leakage is literally a radio signal.

Same family of concerns, different assumptions.

TechniqueWhat the observer usesWhat must not be assumed
Passive leakageA by-product of ordinary operationThat malware or a planted bug is necessary
Active probingA response to an applied signalThat the target was merely being listened to
Physical implantA deliberately added collection mechanismThat unmodified equipment behaves identically
Software-created channelA program deliberately modulating an outputThat the radio path also provided initial access

This is a reading guide to the distinctions, not a replacement for any authority’s formal taxonomy.[2][12][14][21]

Before the computer screen

The wider problem predates electronic computers. During the First World War, electrical field communications could be intercepted through unintended paths involving the ground and nearby circuits. The Fullerphone, associated with Captain A. C. Fuller’s work in 1915, belongs to the history of reducing such interception. It was an engineering answer to an electrical communications problem, not an early version of modern computer encryption.[4][6]

The more direct ancestor of the familiar TEMPEST story appears in the NSA’s retrospective TEMPEST: A Signal Problem, written in 1972 and later declassified. It dates a Bell laboratory observation to 1943. A 131-B2 cipher mixer caused spikes on an oscilloscope elsewhere in the laboratory; closer investigation connected the spikes with plaintext.[3]

The account describes a subsequent demonstration across the street from a Signal Corps cryptographic centre in New York. At about 80 feet, roughly 24 metres, the engineers recorded signals and reportedly recovered about three quarters of the plaintext being processed. In 1951, it says, the problem was investigated again, including recovery around a quarter of a mile along a signal line. These are reported historical observations, not modern performance specifications.[3]

The conceptual result is extraordinary. A system using one-time key material could still disclose the message through its implementation. The mathematics had not been disproved. The machine had supplied information that the mathematics had not promised to conceal.

The story should also change how we date discoveries. The date of an internal observation, the date of an internal report, and the date the public was allowed to read that report are three different things. A later public demonstration can be important without being the first time anyone knew the effect existed.

Spycatcher: the faint message beside the loud one

Peter Wright’s Spycatcher is remembered partly for its descriptions of bugging and burglary around London. One of its more technically important episodes is less cinematic: an unintended signal sharing the infrastructure of an intended communication.

In his STOCKADE account, Wright describes French diplomatic cipher equipment and faint plaintext leakage associated with its cabling. His narrative identifies a telecommunications footway box at Albert Gate and a receiving operation in the Hyde Park Hotel. He says the technique yielded diplomatic material during 1960-1963. This is Wright’s memoir testimony, not an independently verified inventory of intelligence-service capabilities. Kuhn’s later technical history discusses the same episode.[5][6]

The point is not that the line carried an easily readable second telegram waiting for an ordinary telephone listener. A conductor can carry several superimposed electrical effects. The useful leakage may be tiny, transformed, or outside the frequencies needed for the intended service. Recovering it is a measurement and interpretation problem.

Nor does information have to remain on the wire on which it originated. Coupling is the useful term: a disturbance in one part of a system influences another part. Nearby conductors, shared references, and imperfect separation can provide paths never intended as communications links. The existence of a path does not establish usable recovery, but it explains why following the telecommunications route can matter.[3][6]

Why might a collection point close to the source help? Because the wanted trace can be attenuated or filtered as it travels, while other disturbances and the receiver’s own noise remain. This is an engineering explanation, not a claim about an undocumented instruction given to Wright.

A faint voice near its speaker may be intelligible. Farther away, behind a closed door and beside a ventilation fan, the same voice may not be. The fan need not become louder; the voice becoming weaker can be enough. Electrical measurements have an analogous problem, though the path and noise sources are different.

SUPER-TECH 1 | CLOSE TO WHAT, AND WITH WHICH NOISE?
For a chosen measurement bandwidth, a simple power signal-to-noise ratio is:

SNR = P(signal) / P(noise)

In decibels, SNR(dB) = 10 log10(SNR), where the logarithm is base ten.

Consider an illustrative receiver with noise power of one arbitrary unit. At one collection point, the useful signal contributes ten units: SNR = 10, or +10 dB. A different path attenuates that signal power by a factor of 100 before it reaches the same receiver. With the receiver noise unchanged, SNR becomes 0.1, or -10 dB. No measured intelligence capability is implied by these invented numbers.

The qualification is essential. If a path attenuates the relevant signal and dominant upstream noise equally, their ratio need not improve merely because the tap is moved nearer. Local interference, coupling, cable impedance, filtering, and receiver noise can dominate. A useful model is Y(f) = H(f)X(f) + N(f), for a path approximated as linear over the conditions considered. Real installations can require more than that model.

The useful question is not simply ‘How close can we get?’ It is ‘Where does information-bearing structure survive relative to the disturbances that mask it?’ A distance on a street map does not answer that electrical question.[6]

How a cable becomes more than a cable

A cable is usually drawn as a line joining two boxes. Electrically, it is part of a three-dimensional arrangement of conductors, return paths, insulation, connectors, and nearby objects. That arrangement determines not only whether the intended receiver gets its data, but also what other equipment might measure.

Radiated leakage is observed through electromagnetic fields travelling away from the source. Conducted leakage follows a conductive path, such as a signal or power connection. A real route can combine them: a disturbance couples into a long conductor, travels along it, and is radiated again somewhere else.[3][6][9]

Frequency describes how rapidly a pattern repeats: one hertz is one cycle per second, and one megahertz is one million hertz. A complex waveform can contain many frequency components at once. Changing electrical activity therefore need not have just one frequency. A smooth, repeating sine wave concentrates its energy at one frequency. Sharper transitions require a wider combination of frequencies to describe them. Repetitive switching can produce recognisable frequency structure, while the processed data changes aspects of the waveform. Recognising that structure is one way an analyst separates a useful observation from background activity.[6]

That does not mean an antenna receives little floating zeroes and ones. It receives a physical waveform. The observer must infer which features correspond to timing, symbols, display content, or some other relevant property.

A further trap is to imagine that a signal must be strong enough to disturb another device before it can betray information. Causing malfunction and allowing careful measurement are different thresholds. A receiver designed to look for a particular structure may recover something from a signal that no office worker notices at all.

Distance helps, generally

Distance often reduces a directly received signal. It is a useful control when the source, path, and observer are understood. It becomes a dangerous shortcut when somebody turns a convenient separation into a universal law of secrecy.

Imagine an ideal source sending the same total power outwards in all directions. Farther out, that power is spread over a larger spherical surface. Doubling the radius makes the surface area four times as large. The power density at the greater distance is one quarter of its previous value.

That is the familiar inverse-square relationship. It describes a particular propagation model. It does not say that a secret becomes unreadable at a particular radius, or that a shared cable behaves like a signal spreading freely through space.[23]

A real room adds reflections, apertures, conductors, and nearby objects. A real source has directionality. A real receiver has its own sensitivity and antenna. Equipment can also be close enough that the field does not behave like the far-field wave assumed by the simple calculation. A tidy circle is not a substitute for those facts.[22][23]

SUPER-TECH 2 | WHAT ACTUALLY FALLS AS 1/r²?
For the idealised isotropic free-space model, power flux density is:

S(r) = P / (4πr²)

P is the radiated power and r the distance. Along a fixed direction, a directional source introduces the corresponding gain. For a fixed receiving arrangement at a fixed frequency in the far field, doubling r gives one quarter of the received power: approximately 6 dB less. Ten times the distance gives one hundredth of the power: 20 dB less.

Field amplitude is different. In the plane-wave region, power density is proportional to the square of electric-field amplitude. The field amplitude therefore falls as 1/r, not 1/r². Half the amplitude and one quarter of the power describe the same 6 dB change when compared consistently.

These relationships do not supply a universal near-field rule. Nor do they describe attenuation along a cable, or guarantee monotonic changes inside a reflective building. Wavelength, source size, antenna orientation, and the relevant field region matter. The boundary between ‘near’ and ‘far’ is not a fixed number of metres for every apparatus.[22][23]

The equations explain why separation can help. They do not calculate a safe perimeter without the rest of the model.

There is an especially relevant historical warning. The NSA’s retrospective says its early 200-foot (61m) zone reflected a practical compromise about what sites could control, rather than proof that interception was impossible beyond it. That is a statement about the origins of one historical policy, not a reason to apply that distance today.[3]

The broader lesson is not that distances are useless. A distance has meaning only with the assumptions that made it relevant. Remove those assumptions, and an engineering control becomes a number performing security theatre.

A keyboard upstairs, a conductor downstairs

Two separate 2009 investigations make the conducted-path problem concrete. They are related, but combining them into one story would produce a capability neither paper establishes.

Martin Vuagnoux and Sylvain Pasini studied emanations from twelve keyboards. Their building scenario included a keyboard on the fifth floor and observations extending to the basement. They discussed shared electrical ground and a metal water pipe acting as parts of a favourable path. Results varied strongly with the environment; some difficult measurements needed a direct timing reference. They also observed direct propagation through a mains-powered computer’s shared ground and used a battery-powered laptop to remove that conductive coupling from other measurements.[9]

Andrea Barisani and Daniele Bianco separately reported PS/2 interface keyboard information appearing on power-line earth, including laboratory measurements at distances from one to fifteen metres. Their account distinguishes that conducted route from a separate laser-and-vibration experiment. PS/2 is the older keyboard interface: a result about it must not silently become a result about every modern keyboard connection.[10]

The common lesson is substantial enough without embellishment. The building’s services may be part of the information path. Being several storeys away does not necessarily mean being electrically remote.

What the studies do not establish is that someone can attach a sensor to an arbitrary building’s earth point and immediately read every keyboard inside. That claim adds simultaneous target separation, different interfaces, unknown wiring, changing workloads, and a reliable decoding guarantee. A demonstration spanning a building is not a demonstration covering every computer in it.

The laptop qualification is equally important. Removing an external power connection can remove one conductive route. It does not switch off every electromagnetic or acoustic effect. A dock, monitor, peripheral, or other cable may also change the electrical arrangement. The noun ‘laptop’ is not a description of all its connections.[9][10][19][20]

For assessment, the useful diagram therefore includes more than rooms and walls. It includes shared services and where those services can be approached. Equally, drawing a continuous conductor is not proof that a usable signal survives along it. That is what measurement and a properly defined threat model are for.

The screen is a signal

Wim van Eck’s 1985 paper helped make computer-display interception publicly intelligible. His work, begun in 1983, demonstrated recovery from video-display emissions using adapted television-reception techniques. It was an influential public demonstration, not the first discovery that information-processing equipment could emit compromising signals.[8]

The older cathode-ray-tube display built an image through a timed scanning process. An unintended signal related to that process could contain information about brightness and position. To reconstruct a picture, an observer needed to recover the relevant timing as well as some data-related variation.

A useful analogy is hearing someone read a table without saying where its rows end. There may be plenty of information in the sound, but without the structure it is difficult to put the entries back in place. Recover the rhythm and the row boundaries, and the same stream becomes much more interpretable.

A display also repeatedly presents information. A sentence left on the screen can contribute multiple observations of similar underlying content. Under suitable conditions, aligning observations can make a weak pattern clearer. That is not the same as assuming that every changing screen can be averaged indefinitely.[6][8]

Replacing the bulky CRT with a flat panel did not remove the display connection. Kuhn’s 2004 research examined emanations from flat-panel systems and their digital interfaces. The relevant object is the display path, not merely the surface on which the person sees an image.[11]

The phrase ‘digital signal’ can be misleading here. Digital is a way of representing distinctions. The electrical waveform carrying those distinctions is still physical. It has transitions, timing, and an implementation. Calling it digital does not exempt it from electromagnetic behaviour.

SUPER-TECH 3 | REPEATING THE WHISPER
Suppose an unchanged signal is observed N times, the records can be aligned correctly, and the added noise in each record is independent, zero-mean, and has variance σ². Averaging preserves the signal while reducing the noise variance to σ²/N, or its standard deviation to σ/√N.

In that model, 100 observations reduce the noise standard deviation by a factor of ten and improve the power signal-to-noise ratio by a factor of 100, or 20 dB. This is an illustrative derivation, not a claim about a particular screen or receiver.

Changing content, correlated interference, alignment errors, and clock drift can defeat the assumptions. Increasing bandwidth can also admit more noise; narrowing it too far can discard information needed for reconstruction. An observer has to choose an appropriate representation and measurement, not merely turn up a gain control.

‘Below the noise in one trace’ and ‘not recoverable by any analysis’ are very different claims. So are ‘a recognisable feature emerged’ and ‘the entire document was recovered accurately’.[6]

Deep-TEMPEST

Santiago Fernández and colleagues’ 2024 Deep-TEMPEST study uses learned reconstruction to recover displayed information from HDMI-related electromagnetic observations. It belongs to the passive side of the story: the target need not first run malware designed to broadcast a chosen secret.[13]

One important detail is what the reconstruction receives. It can use complex signal data, retaining both in-phase and quadrature components, rather than just enhancing a conventional grey image. Those components preserve aspects of amplitude and phase that a magnitude-only representation discards.[13]

For a non-radio specialist, think of recording not only how large a repeating motion is, but also where it is in its cycle relative to a reference. Two measurements with the same size can still differ in timing. Throw away that distinction too early, and a later picture-enhancement stage cannot generally recover it.

The paper reports substantial improvements in its evaluated character-error measurements. Its real-data comparison gives 92.2% error for a raw magnitude reconstruction, 35.3% for a real-data-trained model using complex input, and 29.8% for a different training arrangement involving synthetic pre-training and real-data fine-tuning. These are different evaluated configurations, not a universal percentage of screens that can be read.[13]

More fundamentally, a character-error measure is not a probability of recovering an entire secret. Consider three hypothetical results. A partly readable paragraph reveals the topic of a confidential discussion. A reconstructed random identifier fails an exact-match check because one character is wrong. A single recovered word, APPROVED, settles the only question the observer cared about. Similar-looking reconstruction quality can have very different security consequences.

That is why an assessment should define success before admiring the picture. Does the observer need exact text, a class of document, a selected option, or merely evidence that a particular activity occurred?

SUPER-TECH 4 | LEARNING DOES NOT CREATE A SECOND MEASUREMENT
Let S be secret screen content, Y the captured signal, and Θ fixed public model parameters. For reconstruction based on that observation and model:

S → Y → fΘ(Y)

The data-processing inequality gives I(S; fΘ(Y) | Θ) ≤ I(S; Y | Θ).

Better processing can exploit information a poorer method failed to use. It cannot manufacture additional measured evidence absent from the observation. This does not make learning unimportant: turning previously unusable evidence into usable information can change the practical threat dramatically.

If training data, another sensor, or target-specific background knowledge contributes additional information, include it in the model. A plausible completion supplied by a learned prior is not automatically a correctly recovered fact. Keep the raw capture, processing choices, and validation criterion distinct. This is the connection back to Shannon, expressed in modern information-theory notation, not a new experimental claim about Deep-TEMPEST.[36]

When the computer says “yes”

A different branch of the history deliberately shapes emissions. Kuhn and Anderson’s 1998 Soft Tempest paper explored software-generated channels as well as software measures that could reduce leakage. The same broad physical mechanisms can be used to create a signal OR make one less informative.[12]

The 2025 TEMPEST-LoRa paper develops an intentional channel. Sun and colleagues assume malware is already present on the protected computer, can access the information, and can generate particular display output. That output makes leakage from a VGA or HDMI connection resemble packets understood by commercial LoRa receivers. A separate implementation uses a software-defined radio and customised signalling.[14]

LoRa is a radio technology used for low-power communications, including connected sensors. The significant result is compatibility: an ordinary commercial receiver can understand a deliberately manufactured waveform from a component not normally regarded as a radio transmitter. It is not a claim that an antenna outside the building installed the malware.[14][15]

The distinction matters especially for air-gapped systems. An air gap removes specified network paths. It does not necessarily remove every physical output from a machine. Here, the research examines how already-present malicious code could send information out by another route. Preventing initial compromise and preventing unauthorised outward transmission are related but separate parts of the defence.

The headline measurements need to retain their conditions. The paper reports an 87.5-metre outdoor result using HDMI and a commercial LoRa receiving arrangement. Its highest reported 21.6-kilobit-per-second throughput belongs to a different setting at shorter range. Custom-SDR tests reach 112 metres for HDMI and 132 metres for VGA, while the reported rate for that scheme is much lower. Through-wall observations are separate tests again.[14]

Those are not ingredients for a new claim that the researchers transmitted at the fastest speed, over the longest distance, through the thickest wall, all at once.

There are numerical inconsistencies in the paper’s rate and frame-time presentation, recorded in the source notes. They do not justify pretending no packets were received. They do justify avoiding a confident calculation of how many seconds a particular real-world file would take to steal. Besides, even 1 kbit/s moves about 5 MB in twelve hours: enough for a plain-text Complete Works of Shakespeare.

Nor does receiving a LoRa packet automatically mean that an arbitrary third-party LoRaWAN network will deliver it to the attacker. Gateways, network servers, admission, onward routing, and access to the recovered data are separate questions. An attacker-controlled receiver is already enough to make the demonstrated channel interesting; universal cooperation from surrounding infrastructure need not be invented.[15]

The practical change is that collection equipment need not always look like the conspicuous apparatus imagined by an old site assessment. That is a reason to revisit the assumptions, not to treat every nearby sensor gateway as proof of espionage.

Knowing the screen before hearing the signal

Not every interesting advance requires a better receiver. Sometimes an observer knows more about what the target is likely to display.

A 2026 demonstration by Leonardo Teodoro, Kemuel L. Vieira, and Saulo Queiroz explored this question using public information associated with Brazilian electronic voting. They displayed an emulated voting interface on a VGA system and recovered information from its emissions through a masonry wall. The paper explicitly states that it did not test official voting-machine hardware.[16]

The useful research question is whether knowledge of the resolution, layout, contrast, and limited set of possible screen contents helps interpret the observation. It is not evidence that real votes were intercepted, altered, or linked to named voters. Those would require different demonstrations and, in several cases, a different security property altogether.

The distinction is easy to explain. Two televisions can show the same programme while having different circuits inside. Matching the picture does not establish matching electromagnetic behaviour. Equally, demonstrating leakage from an emulation can be a legitimate reason to investigate the real system, provided that the next step is not quietly treated as already completed.

That brings the discussion back to Shannon. An observation does not have to reproduce a whole screen to change the probabilities of the choices that matter. It must, however, actually contain discriminating evidence. A conspicuous signal shared by many devices is not automatically a reliable fingerprint of one particular application.

Not every side channel is radio

The electromagnetic story includes light. A detector can measure variations much faster than a human eye can follow. Kuhn’s 2002 work examined recovery of CRT information from time-varying light, including reflected light. The detector did not have to form an ordinary photograph of the screen. That result depended on the temporal behaviour of the display and the optical environment; it was not a finding that any reflection reveals any modern screen.[17]

Loughry and Umphress examined information leaked by optical indicators on communications equipment. Some indicators conveyed more than a reassuring impression of activity. Their distinctions between device state, activity, and content are useful throughout this field: an apparently simple blinking light can support several different kinds of inference.[18]

Sound supplies a neighbouring, physically different channel. Genkin, Shamir, and Tromer’s acoustic work demonstrated cryptographic-key extraction from particular vulnerable implementations. The measured sound reflected computation-dependent behaviour; the attack was not a microphone directly resolving every processor instruction at clock speed. Later work by Genkin, Pipman, and Tromer examined electrical-potential fluctuations accessible through a computer’s chassis or connections. Those papers concerned cryptographic keys, not the keyboard presses of the 2009 experiments.[19][20]

A further category is deliberately implanted equipment. The NSA’s GUNMAN history describes modified typewriters used for espionage and discusses the earlier Great Seal listening device. These belong to technical intelligence history, but an inserted device changes the explanation. It is not evidence that the same result follows from listening to an unmodified typewriter.[21]

Why keep all these distinctions? Because the remedy depends on the cause. Reducing ordinary emissions, preventing malicious code, detecting a physical implant, and controlling an active probing signal are not four names for the same job.

The family resemblance is information escaping through an overlooked physical route. The prerequisites remain different.

SUPER-TECH 5: CAN ULTRASOUND POWER THE BUG?
Surprisingly, yes. Research into ultrasonic wireless power transfer has demonstrated batteryless devices which harvest incoming acoustic energy and communicate back by altering the reflected sound. One 2023 experiment combined acoustic power transfer with backscatter communication over a three-metre path.[38] Medical-implant research has similarly demonstrated simultaneous ultrasonic powering and return telemetry.[39] Airborne ultrasonic power transfer to very small devices has also been demonstrated experimentally.[40]

None of this, by itself, demonstrates a covert implant extracting information from an air-gapped computer. The implant still needs some way to obtain the information. But it removes an assumption which is very easy to make unconsciously: that a clandestine electronic device must contain its own power source.

There is a splendid Cold War precedent. The Soviet Great Seal listening device discovered in the US Ambassador’s Moscow residence in 1952 contained no battery. An external radio beam supplied the energy; speech altered the resonant device; the returning radio signal carried the audio information. Peter Wright, of Spycatcher fame, was involved in analysing the device; he describes having to repair its damaged membrane before he could demonstrate how it worked.[5][21][41]

Modern acoustic power and backscatter systems apply a remarkably similar idea using sound rather than radio.

Sometimes the incoming signal is not merely the interrogation. It is the power supply.

Shielding is an assembly, not a material adjective

The immediate response to invisible emissions is often to ask for a metal box. A box may be part of the answer. The word metal is not the answer.

Electromagnetic shielding reduces the field reaching or leaving a region. Its performance depends on the material, frequency, field conditions, geometry, and the complete construction. Doors, seams, ventilation, cable entries, and connections are not afterthoughts. They are parts of the boundary. Wilson and Ma’s 1986 NBS study of shielding measurements is a useful reminder that both the material and the measurement arrangement contribute to the result.[22]

A simple analogy is waterproof clothing. Good fabric does not make an open zip waterproof. Nor does measuring a square of fabric tell you whether water enters at the cuff of the assembled coat. The physics is different, but the distinction between a material property and an assembled-system property is exactly the point.

The corresponding electrical problem is more demanding than simply closing visible gaps. The required path for a power cable or signal connection can also become an unwanted route for information. Filtering attenuates unwanted components of electrical signals carried along a conductor. Shielding addresses fields crossing a boundary. They can work together, but they are not interchangeable words.

A filter must also allow the intended function to continue. A device which achieves perfect isolation by preventing all power, data, cooling, and human access has solved a rather different problem from the one in the requirement.

Commercial descriptions can be useful starting points. They can also combine standards names, material claims, and illustrative distances in ways that invite over-reading. Interelectronix’s shielding overview, for example, is best treated as an explanatory lead, not as the authoritative text of a protected standard or a certificate for an installation.[34]

The ETM4U rack page makes a particularly helpful qualification: a rack is not automatically a fully certified TEMPEST solution merely because of its description. The integrated equipment, connections, and final configuration matter. That is a supplier’s stated limitation, not an independent validation of a particular purchase.[28]

It also illustrates why ‘TEMPEST approved’ needs a noun. Approved product? Tested platform? Accredited laboratory? Certified configuration? Assessed site? Those are different objects, with different evidence behind them.

Shielding also has ordinary engineering obligations. It must not create unsafe electrical arrangements, trap unacceptable heat, obstruct maintenance so badly that the enclosure is routinely left open, or depend on seals nobody knows how to inspect. Security controls still have to survive contact with the people who operate and maintain them.

This is where apparently mundane work becomes central: correct assembly, verified replacements, consistent production, careful maintenance, and knowledge of the tested configuration. A gasket or cable termination rarely gets the hero photograph. It may nevertheless be holding the boundary together.

Space has a ceiling, a basement, and a legal context

Distance in TEMPEST assessment is not merely geometry. It also concerns where an observer could place equipment, remain, make a connection, or approach a relevant service without being discovered and stopped.

Two important terms are controlled space and inspectable space. Their exact definitions depend on the applicable authority and scheme. Treating remembered terminology from one national document as universal can reverse the meaning of an assessment.

In the historical policing/Government distinction I worked with, inspectable space concerned space under complete organisational control. Controlled space concerned the authority to investigate and, where necessary, remove suspicious equipment. Those are different tests. Owning the building is not identical to having control over every occupied part of it; having a power to act is not identical to continuously excluding an observer.[24]

A public FAA order from 1995 allocated the term inspectable space differently, combining a practical-exploitation judgement with legal authority. The point is not to settle all terminology by choosing one definition. It is to identify which definition the particular assessment is using.[7]

For a non-specialist, the underlying questions are straightforward. Who can enter? Who can stay? Who can install or leave equipment? Who can inspect it? Who can require its removal? How quickly could anything suspicious be discovered? An organisation’s lease, authority, staffing, and response arrangements can give different answers.

A police or military organisation may have relevant powers and arrangements that an ordinary office occupier does not. That is a conditional statement, not a claim of unlimited control over neighbouring roads or premises. The historical policing example depended on the circumstances, including suitable waiting or parking restrictions. No general rule that every adjoining public area is controlled follows from the organisation’s name.[24]

And even where a power exists, its practical effect must be examined. A right to investigate an object is not the same as reliably noticing it. Noticing it after the relevant information has been collected is not necessarily timely protection.

Consider a hypothetical organisation occupying the middle floor of a shared building. Its security drawing shows a generous distance from the entrance and strong control of the corridor. But the room below belongs to somebody else, and a service route joins both floors. The drawing may accurately describe the corridor while failing to describe the relevant exposure.

This example does not establish that leakage exists or can be decoded. It establishes that the question has not yet been answered. The next step is to assess the actual equipment, paths, accessible locations, and applicable controls, not to declare either automatic safety or automatic compromise.

The site can also change without the computer changing. A neighbouring tenancy changes hands. A previously inaccessible area opens for maintenance. A cable route is altered. A radio installation appears nearby. Whether any of those changes matters requires analysis, but each can change an assumption on which earlier assurance depended.

The security boundary is a combination of physics, access, authority, and time. It is not simply the boundary of the estate.

Infuriatingly arbitrary guidance

There is a particular difficulty in explaining protection against a secret capability. A rule can reveal something about the technique it is designed to frustrate.

In 2012 I prepared simplified policing guidance on this subject. It deferred to CESG’s GPG14, which was CONFIDENTIAL in that context, not merely RESTRICTED. The simplified guidance could present decisions while withholding some of the explanation behind them. That could make its rules look arbitrary to a reader who was not being given the underlying reasoning.[24]

I am not reproducing that document or its assessment rules here. The important point is the separation between usable defensive instructions and the explanation that could expose capabilities, methods, or sources.

This was not a uniquely British arrangement. The public 1995 FAA order explained an administrative TEMPEST programme while referring the assessment criteria to a CONFIDENTIAL instruction. Public NCSC material also identifies GPG14 and supporting implementation guidance without making the detailed controlled material equivalent to a general public checklist.[7][31]

The result can be frustrating. A person asked to follow an unexplained rule may decide it is bureaucratic superstition. A person given the complete explanation may learn exactly which weakness an intelligence collector exploits, what access is required, or what defeats the technique. The amount of explanation is itself a security decision.

That does not make every obscure instruction correct. Age, context, scope, and the competent authority still matter. It means that the absence of a public derivation is not proof that no derivation exists.

Where the detailed rationale cannot safely be disclosed, the effectiveness of guidance depends partly on confidence in the national technical authority issuing it. That confidence is cumulative and institutional: credibility earned through accurate, proportionate advice elsewhere can make apparently arbitrary controls easier to accept. Conversely, loss of credibility in one part of an authority’s remit can spill into unrelated areas, encouraging people to second-guess, ignore, or “improve” rules whose underlying justification they are not permitted to see. When explanation must be withheld, credibility becomes part of the control system.

Capabilities and methods are not only a list of exotic instruments. They include what can be recovered, in which circumstances, how long collection takes, which ambiguities can be resolved, and which changes defeat the method. Confirmation can also disclose information: an experienced person validating a speculative public claim may add more than the original author knew.

Even a negative statement can matter. Saying that an organisation cannot recover a certain kind of signal, or that a particular countermeasure reliably defeats its equipment, can reveal a limit that another party would find useful.

This is why a historical paper, a research demonstration, a supplier page, and personal operational knowledge should not be casually blended into one authoritative voice. A public source supports what that source establishes. It does not automatically authorise contemporary confirmation by somebody who knows more.

A forty-year-old assurance question, asked again

The historical literature is not only about clever interception. It is also about choosing proportionate protection.

In 1986 the US General Accounting Office published DOD Tempest Protection: Better Evaluations Needed To Determine Required Countermeasures. Its recommendations included conducting evaluations before implementing countermeasures, both to protect classified information appropriately and to avoid unnecessary expenditure. It also addressed inconsistent requirements imposed on industry. That is a documented historical audit position, not a contemporary assessment of any particular device.[29]

David Boak’s 1981 communications-security history makes a related distinction between assessing vulnerability and assessing the actual threat. Showing that an effect can be exploited under conditions is not the same as establishing who is attempting it at a particular installation. Both questions matter to a protection decision.[32]

The issue has not remained confined to historical archives. A letter dated 4 March 2026 in the USA, signed by Senator Ron Wyden and Representative Shontel M. Brown, requested a GAO investigation into TEMPEST threats and mitigation. Among its questions were the costs and feasibility of manufacturer countermeasures and whether more information could be disclosed consistently with protecting sources and methods. An attached Congressional Research Service memorandum supplied background. These are a request and a background document, not the findings of a completed investigation.[30]

That distinction matters as much as the technical distinctions. A call for investigation is evidence that a question has been raised. It is not, on its own, a measurement of the prevalence, range, or success of exploitation.

The argument for taking the subject seriously does not depend on confusing those categories. The historical reports establish that the problem is old. The modern experiments establish that relevant mechanisms remain possible in contemporary equipment and configurations. The assurance question is how those findings apply to the information and installation actually being protected.

What a defensible protection argument looks like

A non-specialist does not need to design an antenna to ask the right questions. The aim is to make the route from sensitive information to possible observation explicit enough that responsibilities cannot fall between organisational boxes.

Start with the information. What would disclosure cause? Must the observer recover an exact key, a whole document, a few characters, a chosen option, or merely the fact that activity is taking place? A risk statement about ‘data’ is too vague to distinguish those outcomes.

Then identify where that information exists. The answer may include input devices, memory, display connections, local screens, printers, and equipment handling decrypted material. Encrypting one network link is relevant, but it does not account for every point before encryption and after decryption.

Next identify the credible path. What could radiate, what could couple into a conductor, and where does that conductor go? Which accessible places matter? Which connected devices and services belong inside the assessment? A device inventory and a building drawing need to meet one another.

Then state the adversary’s assumed access. Passive observation of normal operation is one case. A malicious program constructing a convenient signal is another. An implant or an active probe is another again. The difference changes which preventive measures can realistically interrupt the chain.

Finally, define the evidence of adequate protection and who owns it. Is it a test result for a product, a platform, an assembled configuration, or an installation? Does the evidence cover the actual connections, operating modes, and maintenance state? What changes require reconsideration?

From a reassuring phrase to an answerable question

Reassuring phraseQuestion the assurance case still needs to answer
‘It is encrypted.’Where does plaintext exist, and which other observations are outside the encryption claim?
‘It is air-gapped.’Which paths were removed, and what physical outputs remain?
‘The equipment is shielded.’Which assembly, frequencies, penetrations, connections, and operating conditions were assessed?
‘We control the site.’Which spaces and services, in all directions, and with what practical authority and response?
‘Nothing was detected.’With what apparatus, workload, duration, uncertainty, and success criterion?
‘It was tested before.’Which configuration was tested, and have the relevant assumptions changed?

These questions do not mean that every office needs a purpose-built shielded room. They mean that a decision not to use one should follow an assessment rather than a misunderstanding of what encryption or distance provides.

For classified or otherwise highly sensitive work, emanations risk belongs in the design and assurance process early enough to influence equipment, architecture, premises, and operating arrangements. Discovering late that an essential path was never inside the protection boundary is usually more expensive than drawing the boundary properly at the start.

Protect the installation that will actually be operated

Product and platform assurance have their place. The NCSC’s public CFTCS description includes initial product examination and production assurance. Its CPTAS description separately addresses mobile platforms. The NSA’s public certification-programme description also distinguishes manufacturer and test-service arrangements. The existence of these schemes is useful evidence of an established discipline, not a blanket guarantee for whatever a customer subsequently connects.[25][26][27]

A practical protection design may combine lower-emission equipment, suitable shielding and filtering, separation of sensitive paths, appropriate physical space, and controlled operating arrangements. The useful separation is often called RED/BLACK: keeping sensitive unencrypted processing and paths appropriately separated from associated protected or less-sensitive ones. The actual information and coupling relationships matter more than the colour assigned to a cable.[6][42]

Masking, noise, or deliberate interference can appear in the literature too. They require their own engineering and authorisation case. Filtering a conductor is not the same thing as injecting noise into it. Adding radio noise is not automatically safe for neighbouring services, and it is not proof that a capable observer cannot separate the useful signal. The 2026 interface paper’s proposed adaptive jamming is a research suggestion, not a demonstrated ready-made control.[16]

Software changes may also affect emissions or their interpretation, as Soft Tempest explored. But a countermeasure that makes a display harder for its legitimate user to read, or relies on an observer never adapting, needs more justification than an attractive demonstration. Protecting confidentiality should not casually discard usability, accessibility, or operational correctness.[12]

The recurring engineering requirement is to evaluate combinations. A well-filtered power input does not answer the external display path. A well-shielded rack does not answer an unassessed peripheral. A restricted room does not answer an accessible shared service. Controls can reinforce one another, but only when their boundaries join up.

Keep the assurance alive

Testing establishes evidence about conditions. It does not make those conditions permanent.

A cable is replaced. A dock is added. Equipment is relocated. A software update changes display behaviour. A panel is opened for maintenance and reassembled differently. A gasket degrades or is not put back following access. Nearby occupancy changes. None of those events automatically proves a compromise. Each can, however, change something the previous protection argument relied upon.

The sensible lifecycle question is therefore not merely ‘Does it still work?’ It is ‘Is the previous assurance still applicable?’

Document the tested configuration, relevant operating states, permitted substitutions, maintenance responsibilities, and retest triggers. Give somebody responsibility for changes that cross organisational boundaries: desktop support may own the cable, facilities the route, security the room, and nobody the combined information path unless that role is assigned.

Negative results need the same discipline. A failure to recover information during one test can support a bounded conclusion about that test. It is not proof that no method, workload, receiver, or future arrangement could obtain it. Equally, a laboratory success does not prove that every nominally similar installation is exposed. Both conclusions need their conditions.

The artefact is the route nobody meant to build

The obvious objects for this chapter are a cipher mixer, a recovered screen image, an antenna, or an imposing shielded enclosure. All are useful. None is the whole subject.

The more revealing artefact is the unintended channel: a relationship between information inside a system and an observation outside the boundary its designers thought mattered.

Sometimes that channel is a faint component on a cable. Sometimes it is a radiated display signal that becomes legible only after careful reconstruction. Sometimes a malicious program makes an ordinary connection behave as part of a transmitter. Sometimes the route includes the building itself.

The history runs from electrical communications and wartime cipher equipment to keyboards, digital displays, learned reconstruction, and software-manufactured radio packets. The equipment changes. The central question remains: what has the implementation made observable that the security claim did not account for?

There is a human system around the physics too. Engineers identify the path. Operators preserve the intended configuration. Facilities staff maintain the boundary. Assessors distinguish evidence from assumptions. Authorities decide which explanations can be shared. A control which exists only in one team’s diagram has not yet joined that system.

Shannon asked what the intercepted message reveals.

TEMPEST asks what the rest of the machine reveals while the message is being protected.

The Cipher Worked. Yet the Secret Escaped.

Purple Signature of Sophie Ada Mathison Violet Baskerville
References & Source notes

[1] NIST Computer Security Resource Center. TEMPEST.

Glossary entry drawing on CNSSI terminology.

Definition of compromising emanations; an activity definition, not proof of an acronym origin.

Official glossary

[2] National Cyber Security Centre. TEMPEST and Electromagnetic Security.

Published 1 August 2016; page review dated 29 November 2021.

The UK public passive/active distinction and the scope of TEMPEST and EMS services. Scheme descriptions do not establish a particular installation’s compliance.

NCSC scope and services

[3] National Security Agency. TEMPEST: A Signal Problem.

Cryptologic Spectrum 2(3), Summer 1972, pp. 26-30; subsequently declassified.

Printed pp. 27-28 describe the Bell laboratory discovery, the Varick Street demonstration, conducted leakage, and the pragmatic basis of the historical 200-foot zone. Historical observations are not current limits.

Declassified original

[4] Imperial War Museums. Fullerphone Trench S.

Museum object COM 176.

Historical precursor: Captain A. C. Fuller’s 1915 work on field communications and resistance to unintended interception. The object record is not a claim that the later TEMPEST programme existed in 1915.

Museum catalogue

[5] Peter Wright with Paul Greengrass. Spycatcher: The Candid Autobiography of a Senior Intelligence Officer.

1987. Chapter 8, STOCKADE discussion.

Memoir testimony about diplomatic plaintext leakage, the Albert Gate footway box, and the Hyde Park Hotel operation. Edition pagination varies; Kuhn [6] cites pp. 109-112 of the Australian edition. No independent operational corroboration is implied.

Bibliographic record

[6] Markus G. Kuhn. Compromising emanations: eavesdropping risks of computer displays.

University of Cambridge Technical Report 577, December 2003.

Original doctoral research and historical synthesis: display leakage, signal reconstruction, measurement conditions, and the distinction between radiated and conducted paths. Also provides the Spycatcher edition reference.

Full technical report

[7] Federal Aviation Administration. TEMPEST Countermeasures for Facilities.

Order 1600.67, 18 January 1995.

Historical public order: Inspectable Space, an official acronym expansion, and reference to sensitive assessment criteria. It is not presented as current UK terminology or law.

Original order

[8] Wim van Eck. Electromagnetic Radiation from Video Display Units: An Eavesdropping Risk?

Computers & Security 4 (1985), pp. 269-286.

Original CRT-era display-interception research. The account distinguishes demonstrated observations from projected ranges and does not generalise the apparatus to arbitrary modern displays.

Original paper

[9] Martin Vuagnoux and Sylvain Pasini. Compromising Electromagnetic Emanations of Wired and Wireless Keyboards.

18th USENIX Security Symposium, 2009.

Section 6 includes the building scenario, shared conductors, and the battery-laptop qualification. Experimental conditions and timing-reference limitations remain part of the result.

USENIX paper

[10] Andrea Barisani and Daniele Bianco. Sniffing Keystrokes with Lasers and Voltmeters.

Black Hat USA, 2009.

The power-line investigation concerns PS/2-related leakage through earth. The laser-vibration investigation is a separate physical channel; neither supplies a universal building-wide keyboard capability.

Conference paper

[11] Markus G. Kuhn. Electromagnetic Eavesdropping Risks of Flat-Panel Displays.

Privacy Enhancing Technologies, 2004.

Original research showing why the whole digital-display system and its interconnections matter, rather than the presence or absence of a cathode-ray tube alone.

Original paper

[12] Markus G. Kuhn and Ross J. Anderson. Soft Tempest: Hidden Data Transmission Using Electromagnetic Emanations.

Information Hiding 1998, LNCS 1525, pp. 124-142.

Software-manufactured emissions and software techniques for reducing information leakage. The malicious-software and passive-observation cases require different access assumptions.

Original paper

[13] Santiago Fernández, Emilio Martínez, Gabriel Varela, Pablo Musé, and Federico Larroca. Deep-TEMPEST: Using Deep Learning to Eavesdrop on HDMI from its Unintended Electromagnetic Emanations.

arXiv:2407.09717v1, July 2024.

Section 6, Tables 1-2: complex versus magnitude input, training conditions, and character-error evaluation. Numerical comparisons in the article refer to this version, not an assumed later publication.

Version-specific paper  |  Version record

[14] Xieyang Sun, Yuanqing Zheng, Wei Xi, Zuhao Chen, Zhizhen Chen, Han Hao, Zhiping Jiang, and Sheng Zhong. TEMPEST-LoRa: Cross-Technology Covert Communication.

ACM CCS 2025, pp. 678-692. DOI: 10.1145/3719027.3744817.

Section 3.2 states the prior-malware threat model. Sections 5.2-5.5 and Figures 12, 16-18 distinguish receiver arrangements, ranges, payloads, and rates. The proceedings PDF contains the numerical issues discussed in the source notes above.

Proceedings / DOI

[15] LoRa Alliance. What is LoRaWAN Specification.

Official architecture overview.

Gateway, network-server, and application roles, including security arrangements. Receiving a compatible radio packet does not establish arbitrary onward delivery through every operational network.

Architecture overview

[16] Leonardo Teodoro, Kemuel L. Vieira, and Saulo Queiroz. Demo: Pre-Characterization of Electromagnetic Side-Channel Leakage Using Publicly Available Information: A Case Study on E-Voting Interfaces.

arXiv:2605.25142v2, 31 May 2026; ICASSP Show & Tell demonstration.

Abstract, sections IV-V, and Figure 1 expressly concern a VGA emulation. No official voting hardware or real polling event was tested. The article does not infer vote alteration or an electoral outcome.

Version record  |  Version-specific PDF

[17] Markus G. Kuhn. Optical Time-Domain Eavesdropping Risks of CRT Displays.

IEEE Symposium on Security and Privacy, 2002, pp. 3-18.

Time-varying optical leakage, including diffuse reflections. The finding depends on the display and observation process and is not a universal claim about modern screens.

Original paper

[18] Joe Loughry and David A. Umphress. Information Leakage from Optical Emanations.

ACM Transactions on Information and System Security 5(3), August 2002, pp. 262-289.

Indicator-light leakage, including the distinctions between state, activity, and content. The linked later online rendition does not change the original 2002 publication date.

Online paper rendition

[19] Daniel Genkin, Adi Shamir, and Eran Tromer. RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis.

2013 report; CRYPTO 2014.

Author project page and paper on implementation-dependent acoustic recovery of cryptographic keys. This is not a keyboard-keystroke experiment.

Author project and paper

[20] Daniel Genkin, Itamar Pipman, and Eran Tromer. Get Your Hands Off My Laptop: Physical Side-Channel Key-Extraction Attacks on PCs.

2014. IACR ePrint 2014/626.

Computation-dependent electrical-potential leakage through chassis and connections, on the implementations and attack conditions described by the authors.

Author project and paper

[21] National Security Agency. Learning from the Enemy: The GUNMAN Project.

Released historical study.

Modified typewriters and the neighbouring history of planted technical collection devices. The examples illustrate a distinct access assumption, not passive leakage from unmodified equipment.

Released historical study

[22] Perry F. Wilson and Mark T. Ma. A Study of Techniques for Measuring the Electromagnetic Shielding Effectiveness of Materials.

NBS Technical Note 1095, May 1986.

Primary metrology: field type, geometry, fixture, contact impedance, and measurement conditions. A material measurement and an installed-system assessment are different objects of evidence.

Original report

[23] International Telecommunication Union. Calculation of free-space attenuation.

Recommendation ITU-R P.525-5, November 2024.

Free-space propagation relations used to check the inverse-square teaching model. Those equations are not a universal near-field, indoor, or conducted-path model.

Recommendation record  |  Full recommendation

[24] Sophie Baskerville. Historical account of preparing simplified policing TEMPEST guidance in 2012.

Author testimony, supported by the retained contemporaneous notes.

The guidance, numerical decision rules, and private contact details are not reproduced or linked as a public document.

[25] National Cyber Security Centre. Formal TEMPEST Certification Scheme (CFTCS).

Official public scheme description.

Product examination and production assurance. Consult the actual certificate and its scope for a particular product or procurement.

Product scheme

[26] National Cyber Security Centre. Platform TEMPEST Accreditation Scheme (CPTAS).

Official public scheme description.

Mobile-platform assurance, distinct from product certification and from a general guarantee about every installation.

Platform scheme

[27] National Security Agency. National Security Agency TEMPEST Certification Program.

May 2025 public programme description.

Manufacturer and test-service arrangements. Facility recognition and a specific product/configuration result must not be treated as interchangeable.

Programme description

[28] ETM4U. TEMPEST 19-inch Systems According to NATO SDIP Standards.

Commercial product and integration description.

Especially the qualification under “From Standard Rack to Verified TEMPEST Solution”. The page is not an independent test report or a certificate for an arbitrary populated rack or site.

Supplier systems page

[29] US General Accounting Office. DOD Tempest Protection: Better Evaluations Needed To Determine Required Countermeasures.

NSIAD-86-132. Published 27 June 1986; publicly released 8 July 1986.

The official record and historical recommendations support evaluation before countermeasure implementation. They are not present-day measurements of product performance.

GAO record  |  Full report

[30] Ron Wyden and Shontel M. Brown. Letter requesting a GAO investigation of TEMPEST threats and mitigation.

4 March 2026. Accompanied by the Congressional Research Service memorandum Background on TEMPEST, 27 January 2026.

A dated request and public background account, not a completed finding. The letter expressly qualifies potential disclosure by the protection of sources and methods.

Letter and attached CRS memorandum

[31] National Cyber Security Centre. TEMPEST and EMS Policy.

Public document guide.

Identifies GPG14 and associated guidance. Listed issues and public metadata are not a substitute for checking which controlled documents apply to an actual assessment.

Public policy note

[32] David G. Boak. A History of U.S. Communications Security, Volume II.

July 1981; subsequently released by NSA.

“TEMPEST Update”, printed p. 39, discusses changing technology and the distinction between vulnerability assessment and threat assessment.

Released history

[33] Claude E. Shannon. Communication Theory of Secrecy Systems.

Bell System Technical Journal 28(4), October 1949, pp. 656-715.

The preceding artefact: security claims depend on the observation and system model. The physical-channel discussion is the present article’s application of that distinction.

Original-page facsimile

[34] Interelectronix. Shielding Standards.

Commercial explanatory page.

A source of standards and construction leads, not an authoritative acceptance specification. Broad material claims are not adopted; the shielding explanation is checked against the engineering sources [22][23][35]

Supplier explanatory page

[35] IEEE Technology Navigator. Permeability; Skin effect.

Publisher-hosted technical explanations.

Used narrowly for the simple linear permeability relation and the good-conductor skin-depth model. The three-skin-depth decibel example is calculated in this article, not a measured enclosure result.

Permeability  |  Skin effect

[36] Claude E. Shannon. A Mathematical Theory of Communication.

Bell System Technical Journal 27, July and October 1948, pp. 379-423 and 623-656.

Information and uncertainty framework. SUPER-TECH 4 uses modern conditional mutual-information notation for an explicitly stated data-processing argument; it is not a claim that Shannon analysed today’s learned reconstruction systems.

Full paper

[37] William Shakespeare, The Tempest, Act I, Scene II & Act III, Scene II

“Air” maps neatly onto radiated electromagnetic leakage; “earth” onto conducted leakage through earths, cabling, shared services, and structures. And Ferdinand is trying to determine where an unexpected signal is coming from. Worse still, the music is being produced by Ariel, who is invisible. Shakespeare appears to have accidentally written an emanations-security metaphor three centuries before anyone had the decency to invent electronics.
folger.edu – Where should this music be?
folger.edu – The isle is full of noises

[38] Peter Oppermann and Bernd-Christian Renner. Acoustic Backscatter Communication and Power Transfer for Batteryless Wireless Sensors.
Sensors 23(7), 2023, article 3617. DOI: 10.3390/s23073617.
Experimental batteryless sensor combining acoustic wireless power transfer with piezoelectric backscatter communication. The prototype achieved combined power transfer and communication over 3 metres, with more than 4 mW received at that distance and a 2 kbit/s uplink. Useful evidence that the incoming acoustic field can provide both the operating energy and the carrier from which a passive device communicates back.
Open-access paper

[39] Shaul Ozeri and Doron Shmilovitz. Simultaneous backward data transmission and power harvesting in an ultrasonic transcutaneous energy transfer link employing acoustically dependent electric impedance modulation.
Ultrasonics 54(7), September 2014, pp. 1929–1937. DOI: 10.1016/j.ultras.2014.04.019.
Experimental biomedical work in which the same implanted ultrasonic transducer harvested energy and returned data by altering its acoustic reflection. The experiment demonstrated 1,200 bit/s backward communication while simultaneously transferring 20 mW to the implant. This supports the point that an ultrasonically powered device need not choose between receiving power and returning information.
doi.org

[40] Angad S. Rekhi, Butrus T. Khuri-Yakub, and Amin Arbabian. Wireless Power Transfer to Millimeter-Sized Nodes Using Airborne Ultrasound.
IEEE Transactions on Ultrasonics, Ferroelectrics, and Frequency Control 64(10), October 2017, pp. 1526–1541. DOI: 10.1109/TUFFC.2017.2737620.
Experimental and modelling work on airborne ultrasonic power delivery to millimetre-scale devices. The authors demonstrated recovered electrical power corresponding to a simulated range of about 1.05 metres, supporting the narrower claim that very small devices can in principle be powered acoustically through air. It is not evidence of a covert implant, nor of information extraction by such a device.
doi.org

[41] Wikipedia. The Thing (listening device).

Background on the Soviet passive resonant-cavity listening device concealed inside a carved Great Seal of the United States and presented to Ambassador W. Averell Harriman in 1945. The article covers its external RF illumination, lack of an internal power supply, discovery in 1952, and association with Leon Theremin. Used here as an accessible explanatory source alongside the more authoritative NSA history [21] and Wright’s account [5], rather than as the sole evidence for technical or operational claims.

wikipedia.org

[42] NIST Computer Security Resource Center. RED/BLACK concept. Glossary definition sourced from CNSSI 4009-2022. Defines separation of circuits, components, equipment, and systems handling classified plaintext RED information from BLACK information.
https://csrc.nist.gov/glossary/term/RED_BLACK_concept