{"id":4220,"date":"2016-07-28T02:16:52","date_gmt":"2016-07-27T18:16:52","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=4220"},"modified":"2016-07-28T02:17:28","modified_gmt":"2016-07-27T18:17:28","slug":"2016-wireless-keyboard-security-still-sucks","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2016\/07\/2016-wireless-keyboard-security-still-sucks\/","title":{"rendered":"In 2016 Your Wireless Keyboard Security Still SUCKS – KeySniffer"},"content":{"rendered":"

So you’d probably imagine that Wireless Keyboard Security is a 1998 problem and you shouldn’t even have to worry about that any more. And you’d be wrong – two-thirds of wireless keyboards, from MAJOR manufacturers are not even vaguely secure.<\/p>\n

\"In<\/p>\n

It turns out, in 2016 when cryptography is mainstream, open-source and fairly easy to implement with proven libraries for every language – wireless keyboards still communicate in plain text.<\/p>\n

Millions of low-cost wireless keyboards are susceptible to a vulnerability that reveals private data to hackers in clear text.<\/p>\n

The vulnerability \u2013 dubbed KeySniffer \u2013 creates a means for hackers to remotely \u201csniff\u201d all the keystrokes of wireless keyboards from eight manufacturers from distances up to 100 metres away.<\/p>\n

\u201cWhen we purchase a wireless keyboard we reasonably expect that the manufacturer has designed and built security into the core of the product,\u201d said Bastille Research Team member Marc Newlin, responsible for the KeySniffer discovery. \u201cUnfortunately, we tested keyboards from 12 manufacturers and were disappointed to find that eight manufacturers (two thirds) were susceptible to the KeySniffer hack.\u201d<\/p>\n

The keyboard manufacturers affected by KeySniffer include: Hewlett-Packard, Toshiba, Kensington, Insignia, Radio Shack, Anker, General Electric, and EagleTec. Vulnerable keyboards are always transmitting, whether or not the user is typing. Consequently, a hacker can scan for vulnerable devices at any time.<\/p><\/blockquote>\n