Earlier quoted context omitted.
> If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password Probably easier/safer to display a random number on-screen and then ask the user to retype it into the device. I figure numbers are less likely to run into problems when the keyboard isn't US-standard QWERTY. For more paranoia/portability, show the user a repeating rhyt…
Then in a walk-by attack the attacker can just type the number or play the game. Hopefully they wouldn't know the user's password.
Confirming a new device should always be separate from the dozens of unique and distinctive scenarios where a user might (or might not) need to authenticate themselves.