Live data from Hacker News

HP laptops found to have hidden keylogger

bbc.co.uk

11–20 of 64 posts

Re: HP laptops found to have hidden keylogger

#12
post #7

There are key loggers and Key Loggers. If you need admin rights to enable it and it saves the keystrokes locally, then you probably shouldn't care. Anyone with that level of access can install something worse.

The salient variable when it comes to key loggers is knowledge of its existence.

Re: HP laptops found to have hidden keylogger

#13
post #9

So... This has ballooned from debug code with no evidence of ever being maliciously used to "loss of confidentiality" and now instead of being a keylogger it's a "hidden keylogger." Dramatic tone change for no actual new news. Sure this is getting the person's blog attention, but now I'm certain I don't agree with the alarmist title of the original post.

And the assertion that "an attacker with access to the computer could have enabled it to record what a user was typing" is somewhat silly.

If the attacker has access to the computer, why not install some other key logger that would send info to the attacker's site?

Re: HP laptops found to have hidden keylogger

#14
At least with a PC, it's relatively easy to put in a fresh install, either Windows or some other operating system, which everyone in tech should do considering the recent HP/Lenovo issues (although I'm not sure if it would help I this situation if this particular exploit was in the official drivers).

It's considerably harder with phones, with all of them running non standard, non upstreamable kernels, and consumers not really having alternative OSes like we do with PCs.

Re: HP laptops found to have hidden keylogger

#15
"He said the keylogger was disabled by default, but an attacker with access to the computer could have enabled it to record what a user was typing.

According to HP, it was originally built into the Synaptics software to help debug errors."

How bad is this really then? If an attacker could enable it, they could install another key logger anyway if this feature didn't exist? Can HP enable it remotely (I'm guessing not)?

Re: HP laptops found to have hidden keylogger

#16
post #8
post #2

Less of a big deal than they’re trying to make it out to be, it’s disabled by default and a leftover debugging tool.

Twice in the same year? http://www.tomshardware.com/news/hp-keylogger-debugging-tool... How many of these "debugging tools" has HP left enabled, I wonder?

It's not enabled. And someone with access to your computer can just install their own keylogger anyway, so why is this even a security threat?

Re: HP laptops found to have hidden keylogger

#17
post #7

There are key loggers and Key Loggers. If you need admin rights to enable it and it saves the keystrokes locally, then you probably shouldn't care. Anyone with that level of access can install something worse.

It still is a keylogger in a consumer product.

So is Notepad.

Re: HP laptops found to have hidden keylogger

#18
post #9

So... This has ballooned from debug code with no evidence of ever being maliciously used to "loss of confidentiality" and now instead of being a keylogger it's a "hidden keylogger." Dramatic tone change for no actual new news. Sure this is getting the person's blog attention, but now I'm certain I don't agree with the alarmist title of the original post.

The previous one in the audio(!) drivers was as bad as it could have been:

https://www.bleepingcomputer.com/news/security/keylogger-fou...

"writes all keystrokes to a local file at:

C:\users\public\MicTray.log"

Note: Public folder! All keystrokes. Discovered May 2017, preinstalled on 28 HP laptop models. Other hardware that uses this driver may also be affected.

Edit, to the other commenters in other threads: please don't mix them, there are two "keyloggers." The one in the audio(!) driver was always on, recording by default to the publicly accessible file, as seen here.

The one in the new news is a code in the keyboard driver that can be turned on (and here it's important to know if the switch is publicly accessible) but isn't on by default. Depending on how that one is turned on and where the result is logged, it can be not worthy to worry too much. But these details also matter.

Re: HP laptops found to have hidden keylogger

#19
post #13
post #9

So... This has ballooned from debug code with no evidence of ever being maliciously used to "loss of confidentiality" and now instead of being a keylogger it's a "hidden keylogger." Dramatic tone change for no actual new news. Sure this is getting the person's blog attention, but now I'm certain I don't agree with the alarmist title of the original post.

And the assertion that "an attacker with access to the computer could have enabled it to record what a user was typing" is somewhat silly. If the attacker has access to the computer, why not install some other key logger that would send info to the attacker's site?

Or as Raymond Chen is fond of saying (citing from the Hitchhikers Guide), "It rather involved being on the other side of this airtight hatchway".

Re: HP laptops found to have hidden keylogger

#20
post #8

Earlier quoted context omitted.

Twice in the same year? http://www.tomshardware.com/news/hp-keylogger-debugging-tool... How many of these "debugging tools" has HP left enabled, I wonder?

It's not enabled. And someone with access to your computer can just install their own keylogger anyway, so why is this even a security threat?

Well we didn't know it was there at all not long ago. How sure can we be now that there is no hidden remote way to turn it on?
Post reply on HN