We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Apple keyboards are vulnerable to hackers

2»

Comments

  • mr_fishbulb
    mr_fishbulb Posts: 5,224 Forumite
    Part of the Furniture Combo Breaker
    Thats all very well but how would this hack be used in a practical sense. Presumably you would have to have physical access to the keyboard
    You wouldn't need physical access to upgrade the firmware on the keyboard.
  • isofa
    isofa Posts: 6,091 Forumite
    kwikbreaks wrote: »
    Of course the encryption could be broken but the fact remains that it is easier to hack wired keyboards than bluetooth ones so "Far more at risk is someone with a PC, Mac or any other type of wireless keyboard transmitting over blue-tooth" is incorrect.

    I totally disagree, wireless connections are much easier to break into than anything else. This have been proven by industry professionals, Cambridge academics and everyone in between. I'd be interested to read your opposing facts to these experts.

    Your statement is utterly incorrectly from my view as someone in the industry and with more than a passing knowledge of this subject matter.
  • kwikbreaks
    kwikbreaks Posts: 9,187 Forumite
    Well bluetooth uses reasonably secure encryption but there is no encryption at all with a wired keyboard and you were the one who first mentioned that it is possible to pick up those signals not me so go figure.
  • thescouselander
    thescouselander Posts: 5,547 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 4 August 2009 at 5:14PM
    You wouldn't need physical access to upgrade the firmware on the keyboard.


    Well I suppose there are two ways

    1) Get physical acccess and change the firmware
    2) Change the firmware by running some code on the host computer


    If you have gone to the trouble of option 2 (bypassing the other security features on OSX) you could have done all sorts of other, more effective, things instead messing about with the keyboard.

    Whats the point I say.

    Also you would need another piece of malware in the host machine to interrogate the keyboard and forward the information on. If this is already there why not run the keylogger as part of this application too.
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Marty_J wrote: »
    The user would have to download a keyboard firmware update (from someone who isn't Apple). The malware would then live in the keyboard's memory.

    The last line of the report is quite telling: "many other devices have firmware update mechanisms that we believe can also be exploited by attackers for malicious purposes".

    This seems to be a problem shared by many devices with firmware that can be updated, and it's not confined to Apple keyboards.

    Presumably they choose an Apple keyboard because then it'll hit the headlines. An article called "Microsoft security problem found" wouldn't really be news.

    Nice one Marty. :rotfl::rotfl::rotfl:
    No free lunch, and no free laptop ;)
  • isofa
    isofa Posts: 6,091 Forumite
    kwikbreaks wrote: »
    Well bluetooth uses reasonably secure encryption but there is no encryption at all with a wired keyboard and you were the one who first mentioned that it is possible to pick up those signals not me so go figure.

    A knowledgeable person with a laptop and software can crack bluetooth (if he's close enough) and WEP WiFi encryption. Bluetooths security "strength" doesn't rely on uncrackable encryption, but instead on the shortwave nature of transmission.

    A knowledgeable IT/engineering student with a few high powered graphics cards running a rig can crack WPA if he knows what he's doing.

    To pickup electronic signals from a wired keyboard (I'm not talking about the OP firmware crack), but a completely standard wired keyboard, requires an enormous amount of skill coupled with hundreds, if not millions of pounds worth of sensitive equipment. It's near to impossible without these combined items.
    I mentioned this earlier to just show than anything is breakable if you have the tools, there is no such thing as 100% security.

    I'm fortunate to have seen a few of these techniques demonstrated in an IT forensics demo.

    Therefore, in my opinion, backed by a little research, wired keyboards are the most secure. Anything wired is always more secure that wireless, providing basic security measures are considered.

    So, as you so eloquently put it, "go figure". :rolleyes:


This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.1K Banking & Borrowing
  • 254.3K Reduce Debt & Boost Income
  • 455.3K Spending & Discounts
  • 247.1K Work, Benefits & Business
  • 603.7K Mortgages, Homes & Bills
  • 178.3K Life & Family
  • 261.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.