Keyboard Security


#1

The $1399 funding option and above (librem 5) say that a keyboard and a mouse are included. This made me question the security of any keyboard, and if yours are checked for malicious software in it.

I may understand this wrong, (I’m not a tech guy) but if any hardware can have software in it, does this theoretically mean that a keyboard you buy can compromise your security by recording logs (key hits & patterns) and then send them over to a server?

Thank you


#2

Attacks have been demonstrated that used keyboard firmware.


#3

i don’t know of any cheap wired keyboards that have chips that can be compromissed in such ways as you describe.
perhaps in order to exploit a keyboard like that you need a model that is wireless and has additional macro or programability functions onboard like many of the GAMER oriented brands that come with proprietary 3d party installs for rgb/profiles/scripts/on-board memory etc. in short we have to be specific about what the actual TYPE of keyboard it is.


#4

That does not mean that such keyboards do not exist.

No, a keyboard does not need to be a wireless keyboard or a gamer keyboard in order to be exploitable. See Chen’s paper, via the link above.


#5

so it is - hacker > keyboard > pen > sword
so who hacks the hacker ? brain-computer-interface ?