Investigating the Overlooked
In 1943, a Bell Labs engineer noticed something odd on an oscilloscope sitting near a piece of Army cipher equipment: a spike every time the machine encrypted a letter. The device being tested was the 131-B2 teletypewriter tape mixer, part of SIGTOT, a one-time-tape cipher machine just entering Army service. On closer inspection, those spikes could be translated back into the plaintext message the machine was actually processing -- proof that an encryption machine's own electrical signature could leak the secret it was built to protect, without anyone tapping a wire or breaking a code.[1]
The discovery sat mostly unexplored for years. Then, in 1951, the CIA told the newly formed NSA that its own engineers had been experimenting with the same class of Bell teletype equipment -- and found they could read the plaintext message from a quarter mile down the signal line, with no physical connection to the machine itself.[1] That single fact turned an oscilloscope curiosity into a standing national-security problem: any electronic device processing classified information was, by default, broadcasting some version of it into the surrounding electromagnetic environment. The NSA's own classified name for the resulting countermeasure program is TEMPEST -- a real acronym, not just an evocative word, most commonly expanded as Telecommunications Electronics Materials Protected from Emanating Spurious Transmissions.[2]
Modern TEMPEST requirements aren't one universal shielding standard -- they're tiered to how close an adversary is assumed to be able to get. US and NATO zoning runs from Zone 0 (an attacker essentially in the next room, roughly one meter away) through Zone 1 (about 20 meters, or equivalent attenuation from the building's own materials) to the more relaxed Zone 2 (roughly 100 meters of effective distance).[3] A facility processing the most sensitive material at Zone 0 needs shielding an order of magnitude more rigorous than one that can assume real physical distance from a plausible listener. Most of the actual technical specifications -- what NACSIM 5100A, the controlling document since 1981, requires in decibels of attenuation for a given zone -- remain classified even today.[1]
That rigor shows up directly in what it costs to build. A Sensitive Compartmented Information Facility (SCIF) with TEMPEST requirements commonly runs $350 to $1,000-plus per square foot, with accreditation timelines of 12 to 36 months -- meaning a single closet-sized 200-square-foot secure room can carry a price tag around $200,000, driven specifically by whether the space needs to meet a 60-decibel or a 100-decibel attenuation requirement.[4] Retrofitting an existing building that wasn't designed with TEMPEST in mind is routinely more expensive than building shielded from the start.[4]
Most popular accounts of TEMPEST reduce it to a single machine leaking its own signal, but the discipline the NSA actually built -- it calls the broader field Emission Security, or EMSEC -- evaluates a system, not a component. NSTISSAM Level III, one of the governing test standards, is formally titled a laboratory test standard for tactical mobile "Equipment/Systems"; the distinction is in the standard's own name.[3] A device that passes an isolated bench test can still fail once it's actually installed -- its own cabling, the power line feeding it, and the other equipment sharing the room can couple its signal onto paths nobody tested in isolation. That's also why TEMPEST evaluation is fundamentally observational rather than calculated: an installed system gets physically measured under real operating conditions, not certified from a spec sheet, which is a large part of why accreditation runs 12 to 36 months rather than being a paperwork exercise.
Why does this matter? TEMPEST and the Trusted Foundry program already documented on this site address the identical underlying question -- can this system be trusted -- at two different points in a device's life. Trusted Foundry asks it before the device exists: who fabricated the chip, and can that fab and its ownership be trusted. TEMPEST asks it after: once the device is built, powered on, and doing its job, does it leak what it's processing to anyone close enough to listen. A chip can pass every fabrication-trust requirement in the country and still fail the second test if the finished equipment around it wasn't built to contain its own signal. Both are real, both are expensive, and neither one substitutes for the other -- which is exactly why the government runs them as two separate, parallel disciplines rather than one.
There's a third variant of the same question, at a different scale entirely: what does an entire facility's aggregate power draw reveal from a single point outside its walls, no access to any individual device required. Fabrication trust, emission trust, and aggregate trust are three separate tests -- none of them stands in for the other two.