BSI ID: G 0.15
Eavesdropping refers to targeted attacks on communication connections, conversations, noise sources of all kinds or IT systems for the purpose of gathering information. This ranges from unnoticed, secret listening in on a conversation to highly technical, complex attacks to intercept signals transmitted via radio or cables, e.g. with the aid of antennas or sensors. It is not only because of the low risk of detection that eavesdropping on lines or radio connections is a threat to information security that should not be ignored. In principle, there are no eavesdropping-proof cables. The only difference between cables is the effort required to eavesdrop on them. Whether a line is actually being tapped can only be determined with a great deal of technical effort. The unprotected transmission of authentication data in plain text protocols such as HTTP, FTP or Telnet is particularly critical, as these are easy to analyse automatically due to the clear structure of the data. The decision to eavesdrop on information somewhere is essentially determined by whether the information is worth the technical or financial effort and the risk of discovery. The answer to this question depends greatly on the individual capabilities and interests of the attacker.
Examples:
In the case of telephone calls, it is not only the interception of conversations that may be of interest to an attacker. The information transmitted during signalling can also be misused by an attacker, e.g. if the password is transmitted in plain text during login due to an incorrect setting in the end device.
With unprotected or inadequately protected wireless transmission (e.g. if a WLAN is only secured with WEP), an attacker can easily eavesdrop on all communications.
Emails can be read throughout their entire journey through the network if they are not encrypted. Unencrypted emails should therefore be compared to postcards rather than traditional letters.