Does this apply to all bluetooth keyboards? Sounds like some public-key crypto could make it safe: embed some unique keys at manufacturing time and use some small crypto library (like tweetnacl) to communicate and have mutual authentication. For the paranoid there could be a way to update the keys so that not even the vendor can sniff the keystrokes. Isn't there a RFC for something similar?
That's the entire point. The crypto is not very good. Also it doesn't apply to all bluetooth keyboards because Microsoft uses a proprietary protocol to communicate apparently (at least this series of keyboards).
Hold my beer while I perform a table flip and throw away all my Microsoft Wireless Keyboards