The heart of the problem: unintentional emissions
Every operating electronic circuit — monitor, keyboard, network cable, printer — radiates an electromagnetic trace of the signal it processes. An eavesdropper with the right equipment can reconstruct the original data from these traces: the screen image, the keys pressed, the traffic on the line.
In NATO/US literature this risk area goes by the code name TEMPEST. Wim van Eck's 1985 feat of reconstructing a monitor's image from a distance with ordinary equipment is the classic demonstration that brought the subject to the public; today's attack surface is far wider.
Standards and levels
NATO manages emission security through the three equipment levels of the SDIP-27 standard (Level A/B/C) and a zoning approach that defines a facility's environmental risk: how close an eavesdropper can get determines which level is required.
Certified TEMPEST equipment is expensive, so in most organizations the practical architecture is mixed: a shielded room for critical operations (architectural shielding), standard equipment inside, and filtering at the line and power entries.
Layers of protection
- Architectural shielding: lining the room surfaces with 80-100+ dB class materials (A300-HEMP, A190, HNG100)
- Distance and zoning: moving critical equipment away from the façade, the car park and neighbouring areas
- Cabling: shielded/fibre lines, correct grounding, line filters
- Equipment choice: certified hardware at the most critical end
- Verification: IEEE 299-based acceptance measurements and periodic checks
Frequently Asked Questions
Is TEMPEST only a concern for government agencies?
No. R&D centres, financial institutions, law firms and organizations preparing competitive examinations — anyone whose intellectual property passes through a screen and keyboard is subject to the same physics.
From how many metres can I be eavesdropped on?
It depends on the device, the ambient noise and the eavesdropper's equipment; the literature includes demonstrations over tens of metres, and under favourable conditions hundreds. A security plan is built around the 'worst-case' distance.
Doesn't software encryption close this risk?
No — the leakage occurs while the data is still on the screen or keyboard, that is, before it is encrypted. TEMPEST is the complement of cryptography, not its alternative.