HP laptops found to have hidden keylogger
11–20 of 64 posts
Re: HP laptops found to have hidden keylogger
#12There are key loggers and Key Loggers. If you need admin rights to enable it and it saves the keystrokes locally, then you probably shouldn't care. Anyone with that level of access can install something worse.
Re: HP laptops found to have hidden keylogger
#13So... This has ballooned from debug code with no evidence of ever being maliciously used to "loss of confidentiality" and now instead of being a keylogger it's a "hidden keylogger." Dramatic tone change for no actual new news. Sure this is getting the person's blog attention, but now I'm certain I don't agree with the alarmist title of the original post.
If the attacker has access to the computer, why not install some other key logger that would send info to the attacker's site?
Re: HP laptops found to have hidden keylogger
#14It's considerably harder with phones, with all of them running non standard, non upstreamable kernels, and consumers not really having alternative OSes like we do with PCs.
Re: HP laptops found to have hidden keylogger
#15According to HP, it was originally built into the Synaptics software to help debug errors."
How bad is this really then? If an attacker could enable it, they could install another key logger anyway if this feature didn't exist? Can HP enable it remotely (I'm guessing not)?
Re: HP laptops found to have hidden keylogger
#16Less of a big deal than they’re trying to make it out to be, it’s disabled by default and a leftover debugging tool.
Twice in the same year? http://www.tomshardware.com/news/hp-keylogger-debugging-tool... How many of these "debugging tools" has HP left enabled, I wonder?
Re: HP laptops found to have hidden keylogger
#17Re: HP laptops found to have hidden keylogger
#18So... This has ballooned from debug code with no evidence of ever being maliciously used to "loss of confidentiality" and now instead of being a keylogger it's a "hidden keylogger." Dramatic tone change for no actual new news. Sure this is getting the person's blog attention, but now I'm certain I don't agree with the alarmist title of the original post.
https://www.bleepingcomputer.com/news/security/keylogger-fou...
"writes all keystrokes to a local file at:
C:\users\public\MicTray.log"
Note: Public folder! All keystrokes. Discovered May 2017, preinstalled on 28 HP laptop models. Other hardware that uses this driver may also be affected.
Edit, to the other commenters in other threads: please don't mix them, there are two "keyloggers." The one in the audio(!) driver was always on, recording by default to the publicly accessible file, as seen here.
The one in the new news is a code in the keyboard driver that can be turned on (and here it's important to know if the switch is publicly accessible) but isn't on by default. Depending on how that one is turned on and where the result is logged, it can be not worthy to worry too much. But these details also matter.
Re: HP laptops found to have hidden keylogger
#19So... This has ballooned from debug code with no evidence of ever being maliciously used to "loss of confidentiality" and now instead of being a keylogger it's a "hidden keylogger." Dramatic tone change for no actual new news. Sure this is getting the person's blog attention, but now I'm certain I don't agree with the alarmist title of the original post.
And the assertion that "an attacker with access to the computer could have enabled it to record what a user was typing" is somewhat silly. If the attacker has access to the computer, why not install some other key logger that would send info to the attacker's site?
Re: HP laptops found to have hidden keylogger
#20Earlier quoted context omitted.
Twice in the same year? http://www.tomshardware.com/news/hp-keylogger-debugging-tool... How many of these "debugging tools" has HP left enabled, I wonder?
It's not enabled. And someone with access to your computer can just install their own keylogger anyway, so why is this even a security threat?