7 ms·
Swift-Keylogger – Keylogger for MacOS written in Swift using HID
- xchaotic 9y agoIt doesn't log passwords using EnableSecureEventInput. There are probably other use cases, but Apple seems to have implemented things rather well here.
- dannyw 9y agoIt would be nice if macOS had the same permissions models as iOS, and then some. A permission before apps can access the camera, or access what keys are held down when the app isn't in the foreground - that would block this case.
- sametmax 9y agoThis would effectively kill innovation. There is a reason you can't do half the things you do on a laptop on a phone unless you root said phone.
- zaksoup 9y agoI'm not sure I buy that requiring user opt-in to camera access is why the Mac app ecosystem is is much larger than that of iOS. Can you elaborate on what apps/innovations would become impossible because of a mandatory opt-in? I cannot think of any...
- kmbriedis 9y agoKeyloggers which don't require any permissions, apparently
- icebraining 9y agoThe problem with an opt-in system is that you have to sandbox the whole app (otherwise, evading the opt-in would be trivial) and therefore lock out any advanced access not explicitly listed as an opt-in permission. If you want an example, there's F.lux, which doesn't work (without rooting) on Android and iOS.
- sametmax 9y agoEverything that is either very low level or is used for deep introspection of other parts of the system. I'm not against sandboxing, but if there should be a way to say i know what i'm installing, go with it. Otherwise you will say good bie to new ways of debugging, alternative drivers, unusual way of routing network packets, innovative UI interactions that are not part of the standards widgets, or anything you haven't think of yet. The computing experience you have today is the result of all the stuff we fiddle with for the last 30 years because it was allowed to. It would be foolish thz big players invented most of it.
- deleted 9y ago[deleted]
- ClassyJacket 9y agoThe idea is not to prevent programs doing those things, it's to prevent programs doing those things without user permission.
- oblio 9y agoIs there (or was there every) any OS app store that allowed an app to go trawling through another apps's memory? Or if you don't want to be that radical, one that at least allows overlays. I don't know of any.
- pluma 9y agoPlenty of apps on Android are allowed to draw over other apps (e.g. Facebook messenger, Lux Auto Brightness). There are also apps that use the accessibility APIs to determine what the user is seeing (e.g. LastPass with AppFill enabled). I think both of these features require explicit manual permissions (i.e. having to go to the system settings and whitelist the app) to be enabled. Also Android permission dialogs refuse to pop up if there is an untrusted screen overlay (which meant that my experience with Lux when with other apps' permission dialogs involved either manually disabling the virtual screen brightness adjustment or having it automatically disabled temporarily, which resulted in unpleasant surprises while using the phone at night).
- sametmax 9y agoThat's not the problem. The problem is that the whitelist of permissions is limited, fixed, i have no control over it and i can't easily work around it. I can't create a great way to batch install/update/migrate my phone because everything requires manual approval. I can't use my own browser or sms app on ios cause it's not allowed by the permissions system. I can't install a new driver on my phone. Remember the bs update apple did that broke the home button, forcing people to buy a new phone ? I can't prevent that either. I'm actually for permissions and sandboxes for most apps. But i want a manual override when i need one.
- BoorishBears 9y ago
- sneak 9y agoThere is also a reason I can do 99% of the things I do on a laptop on my (totally sandboxed, not rooted) iPad Pro.
- sametmax 9y agoNo you can't. You just have a very limited way to use it. Even with the same screen size, give me a laptop os and i'll be more productive, with a factor of 10. It's not a figure of style. Phone os are terribly limited.
- walterbell 9y agoDepends on workflow and apps. iPad OS has made steady progress. If Apple allowed advanced users to manually override permissions, they would gain data to help the OS to evolve much faster. See landscape architects’ experience with human foot paths.
- sametmax 9y agoThat's actually my point.
- sneak 9y agoYou’re objectively wrong, and likely have significantly outdated understanding of what is possible on a “terribly limited” “phone os”.
- sametmax 9y agoSo, without rooting or plugging your phone into a real computer you can: Run a database ? (good luck running postgres with the OS killing processes all the time) Run docker ? Taking screen captures anywhere ? (this one actually got me yesterday while trying to screen capture netflix on my one plus 3) Run f.lux ? Run one virtual machine with windows on it ? Capture 3G traffic with wireshark ? Install a driver to read a USB key in another partition format not allowed by the OS ? Bypass DRM ? Resize partitions to get a dual boot ? Run Wine ? (and they tried hard. Since fosdem 2014 at least) Install patches as soon as a vulnerability is discovered, and not waiting on your phone seller to wake up ? And if you just consider iOS, it's way, way worse. At least on android you have access to part of the filesystem. The thing is, in computing, nothing works exactly right. And with my laptop, I have always a way to work around problems. With phones, I'm just stuck with it. Multitasking sucks. Automation is terrible. You may install a GNU env, but it has access to so little you can't script your way out of anything.
- rubatuga 9y agoThe permission model on the Mac is that it is up to the user. Don’t run software that you don’t trust, end of story!
- ben_w 9y agoI believe that was the problem.
- LoSboccacc 9y agoFunny, I wish it was the other way around. The current model makes far to easy to impersonate elevated dialogs in iOS.
- icebraining 9y agoIs it hard to impersonate elevated dialogs on macOS?
- nfoz 9y agoYes, it would be very nice if operating systems had a sane (let alone user-friendly!) way to properly, thoroughly sandbox userland applications. It's a large reason why "web applications" became a thing -- it gives you sandboxed remote programs (and easy-access to boot!) Even if the web-browsing sandbox is flawed, it's been a convenient band-aid over a fundamental OS feature that, sadly, still doesn't properly exist.
- NiveaGeForce 9y agoLike UWP on Windows.
- Gaelan 9y agomacOS has sandboxed apps, with the same underlying model as iOS (not sure if it asks for camera permissions and such, but apps declare a list of “entitlements” and are granted only those). It’s required for App Store apps, but other than that it’s opt-in. Outside of the App Store, basically it’s just something like DEP or ASLR: a mitigation that isn’t really visible to users unless they look for it.
- tinus_hn 9y agoMost applications can’t offer the functionality you expect without a great amount of permissions. New apps in the Mac App Store have to run in the sandbox and they are quite severely limited.
- pkamb 9y agoAnd permissions do not exist for many common and expected behaviors of Mac apps, leaving the Sandbox/Mac App Store pretty unviable.
- PhisherPrice 9y agoHowever, macOS gives the user root access. This allows malware to elevate privileges by using a vulnerability or phishing for the password or elevation prompt. Once root, everything can be keylogged, even passwords.
- dangero 9y agoYes I once spent a whole day debugging an issue related to this because I was unaware of it. I was getting a game Steam ready and I was working on the Steam overlay that is triggered by the tab key. QA reported that on the login screen, you sometimes had to press tab twice to get the overlay to open. Just on that one screen. I had a piece of code that was looking for the tab keydown event to open the overlay, but in some cases the event was not being triggered. Turned out that the browser password field used EnableSecureEventInput and so the if the cursor focus was in the password input box, the tab button press would not be detected by my code. Pressing it twice worked because: -first tab press moved cursor focus out of the password box -second tab press was in the username input field which was not a secure input field, so my code received the tab keydown event. The weird part about this is since the tab keydown moves the cursor focus out of the secure text box what you receive is a tab keyup event with no keydown before it.
- passivepinetree 9y agoInteresting anecdote. What did you end up doing? Did you just leave it as-was?
- imron 9y ago> but Apple seems to have implemented things rather well here. Reading up on it further [0] it seems you could write an anti-keylogger. Just have an app that calls EnableSecureEventInput and never disables it and no other processes would be able to capture key input: "The system will no longer pass keyboard intercept processes keyboard events if your process has enabled secure input even when your process is moved to the background. It now becomes your process' responsibility to call DisableSecureEventInput when secure entry input is not required, such as when your process detects that it is moving to the background." 0: https://developer.apple.com/library/content/technotes/tn2150/_index.html https://developer.apple.com/library/content/technotes/tn2150...
- TrickyRick 9y agoAlthough that would probably break some apps. See for example: https://news.ycombinator.com/item?id=15488964 https://news.ycombinator.com/item?id=15488964
- imron 9y agoI'm sure it would, so you could have an icon in the task bar that could temporarily enable keylogging again.
- RaleyField 9y agoIt's still wrong. Relevant XKCD https://xkcd.com/1200/ https://xkcd.com/1200/
- splicer 9y agoThanks to a vulnerability I reported a decade ago: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0724 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0724
- goerz 9y agoSo are there any keyloggers for MacOS in the wild that still manage to capture keystrokes with EnableSecureEventInput, or can I consider this as "secure"? Also, is there a way to tell when/for which processes EnableSecureEventInput is active?
- goerz 9y agoAnswering my own question: EnableSecureEventInput does not protect from processes that have root privileges, see https://security.stackexchange.com/questions/47749/how-secure-is-secure-keyboard-entry-in-mac-os-xs-terminal https://security.stackexchange.com/questions/47749/how-secur... A good way to check whether EnableSecureEventInput is enabled is to start the Keyboard Viewer that comes with MacOS and see if it echoes keystrokes.
- jasonmp85 9y agoDoes Keyboard Viewer still come with macOS? I thought it disappeared years ago…
- yeeeeeeeeee 9y agoReading this makes me miss swift :( Braces on new line tho what are you doing my friend?!
- Traubenfuchs 9y agoA keylogger in C# for Windows doesn't require any permissions either and I actually used that to implement a global keyboard-shortcut listener.
- unknownymouse 9y agoThe security in macOS is tougher than in windows
- deleted 9y ago[deleted]
- 21stio 9y ago".. Heck, even the $300 chromebook we recently got has 16GB of RAM.. " I don't think sth like that exists.. which one is it?
- niklasrde 9y agoI mean, you can get the HP Chromebook 13 with 16GB of RAM.. but not for $300.
- Retr0spectrum 9y agoDid you reply to the wrong post?
- cjsawyer 9y agoChromebooks are disappointing because they can have great hardware but you need to jump though hoops to install any real software, and even that's sketchy depending on the model.
- jen729w 9y agoReadme: License MIT Free Software, Hell Yeah! Code (Keylogger.swift, lines 5 & 6): // Created by Skrew Everything on 14/01/17. // Copyright © 2017 Skrew Everything. All rights reserved. Umm.
- jonchang 9y agoPlease articulate your concerns with this. Is it because it's copyrighted? I think most open source software is under copyright; but the license (MIT in this case) grants end-users certain rights that can be revoked if that license is broken.
- walterbell 9y agoCorrect, copyright is what enables the license, free software or otherwise.
- jen729w 9y agoHey. Sorry, it appears that I am totally wrong. I just assumed that those statements were totally conflicting, but ten seconds on Google tells me that’s not so. At least I learned something. My apologies.
- giancarlostoro 9y agoYeah usually open source software grants some permissions but retains copyright ownership. This somewhat disallows abuse of Open Source projects, and is probably part of what makes something like the GPL enforceable in court. IANAL
- extra88 9y agoSince the MIT license grants end-users certain rights, shouldn't the "all rights reserved" statement be removed?
- aroch 9y agoNo, you're reserving all rights that a copyright indicates and then granting specific exceptions (i.e. "I won't enforce my copyright against you if you follow these rules") without giving up those rights
- huntsends 9y agoNicely done, I am also looking for an app something like this for my website www.huntsends.com
- deleted 9y ago[deleted]