6 ms·
HP laptops found to have hidden keylogger
- donatj 9y agoLess of a big deal than they’re trying to make it out to be, it’s disabled by default and a leftover debugging tool.
- deleted 9y ago[deleted]
- crankylinuxuser 9y agoYeah, that's the problem with zombie code. You can have articles like this, especially when companies like Lenovo did spy on people with all sorts of bios->OS infecting spyware and MITM SSL tricks. If it's a binary and potentially readable, they probably shouldn't include the code switch to enable it. Better it never be in there to begin with. But yeah, if it's disabled by default and looks like a debugging tool, it probably is.
- mtgx 9y agoTwice in the same year? http://www.tomshardware.com/news/hp-keylogger-debugging-tool-driver-update,34418.html http://www.tomshardware.com/news/hp-keylogger-debugging-tool... How many of these "debugging tools" has HP left enabled, I wonder?
- moreless 9y agoIt's not enabled. And someone with access to your computer can just install their own keylogger anyway, so why is this even a security threat?
- jbb67 9y agoWell we didn't know it was there at all not long ago. How sure can we be now that there is no hidden remote way to turn it on?
- openasocket 9y agoThat's not a valid form of reasoning. Just because we didn't know about something before isn't an excuse to make random assumptions.
- mtgx 9y agoIn related news: https://www.engadget.com/2017/11/28/hp-quietly-installs-system-slowing-spyware-on-its-pcs/ https://www.engadget.com/2017/11/28/hp-quietly-installs-syst...
- kaputsmack 9y agoYou are being downvoted because this place like Reddit is 99% shills. Don't take comments here at face value.
- esnard 9y agoPrevious discussion: https://news.ycombinator.com/item?id=15885206 https://news.ycombinator.com/item?id=15885206
- 13of40 9y agoThere are key loggers and Key Loggers. If you need admin rights to enable it and it saves the keystrokes locally, then you probably shouldn't care. Anyone with that level of access can install something worse.
- caio1982 9y agoIt still is a keylogger in a consumer product.
- ballenf 9y agoSo is Notepad.
- bnegreve 9y agoNotepad runs in userland under the supervision of the kernel. This is a driver and could be running in kernel mode. It could make a big difference. Even if it's not malicious, I still think it is a rather serious professional mistake to ship a driver containing potentially dangerous deadcode.
- vertex-four 9y agoThere's plenty of "rather serious professional mistakes" in whatever operating system you happen to run in the first place - it's very rare that something that doesn't affect security in any meaningful way gets the attention this has.
- jsudhams 9y agoThe last time i checked the whatever you type in browser, does not end up in text file or notepad. This does show the quality thinking about security. Oh we can enable when we want check things out rather than finding way to add and remove this after informing user
- coldtea 9y agoNotepad doesn't fit the definition of a keylogger. This does.
- jchw 9y agoSo... This has ballooned from debug code with no evidence of ever being maliciously used to "loss of confidentiality" and now instead of being a keylogger it's a "hidden keylogger." Dramatic tone change for no actual new news. Sure this is getting the person's blog attention, but now I'm certain I don't agree with the alarmist title of the original post.
- kbutler 9y agoAnd the assertion that "an attacker with access to the computer could have enabled it to record what a user was typing" is somewhat silly. If the attacker has access to the computer, why not install some other key logger that would send info to the attacker's site?
- icebraining 9y agoOr as Raymond Chen is fond of saying (citing from the Hitchhikers Guide), "It rather involved being on the other side of this airtight hatchway".
- Someone1234 9y agoClaiming that an attacker would use this is nonsensical. You need write access HKLM in order to change the registry key, if you have write access to HKLM you can inject your own driver (inc. keylogger) into the OS. Plus the keypresses are context-less (i.e. you don't know what application, or window the keypress was sent to). A continuous stream of keypresses with no context is darn near useless, it doesn't even contain timestamps! Any number of off-the-shelf keyloggers would do a far better job, all of which can be auto-loaded if you have HKLM write access. They'll even tell you the exact web page a keypress was sent to and manage the job of sending that information to you...
- _Codemonkeyism 9y agowww.facebook.com<return> stephan<tab>123abc doesn't seem useless to me.
- oeuviz 9y agoJust makes me support OSS drivers more. Imagine what damage could be done with hidden code in GPU drivers nowadays.
- djsumdog 9y agoAt least with a PC, it's relatively easy to put in a fresh install, either Windows or some other operating system, which everyone in tech should do considering the recent HP/Lenovo issues (although I'm not sure if it would help I this situation if this particular exploit was in the official drivers). It's considerably harder with phones, with all of them running non standard, non upstreamable kernels, and consumers not really having alternative OSes like we do with PCs.
- tga 9y agoMost PCs come without Windows installation media and instead rely on a restore partition (keylogger included). If you try to install off random other media (e.g. MSDN), it will not recognize the OEM license that comes with the computer. Because of this, there is no trivial way (edit: OK, without buying Windows again) to get a vanilla install including only the Microsoft keylogger, but not the HP one.
- dragonwriter 9y agoThere's a trivial way, it's just not zero added cost if your PC was bundled with Windows: buy a retail version of Windows.
- pnutjam 9y agoNot true, you can reinstall the same version and it will pick up the licensing from the BIOS. You can even extract the key from the BIOS to use on a VM (same hardware) if your running linux. It's even very easy to get the install media direct from Windows, not like back in XP days. https://www.microsoft.com/en-us/software-download/windows10ISO https://www.microsoft.com/en-us/software-download/windows10I...
- tga 9y agoThanks, this used to be an issue at least Windows 8. I'm happily surprised if it's now as easy as downloading the ISO from Microsoft and reinstalling it on an OEM machine.
- 9y ago
- seanwilson 9y ago"He said the keylogger was disabled by default, but an attacker with access to the computer could have enabled it to record what a user was typing. According to HP, it was originally built into the Synaptics software to help debug errors." How bad is this really then? If an attacker could enable it, they could install another key logger anyway if this feature didn't exist? Can HP enable it remotely (I'm guessing not)?
- Someone1234 9y agoExactly. You need administrator to enable this, and you need administrator to install a different keylogger. So then the question becomes: Why use this? Well, an attacker wouldn't but the press doesn't know anything about tech' so, this fact escapes them. This is like science reporting all over again... If you have HP's update agent installed, HP are able to install drivers, so all bets are off as far as what HP could do to your machine. They could enable this via the update agent, but even assuming worst motivations there are a tens of better commercial keyloggers HP would use before this. This debug functionality likely shouldn't be shipping in retail versions of the driver (defence in depth, etc) and should be removed. But there's a ton of misinformation surrounding this bug which is frustrating, the actual security community are already bored of this one.
- gruez 9y ago>you need administrator to install a different keylogger nope. you need administrator if you want to install for all users, but there's nothing preventing a user from keylogging himself.
- Someone1234 9y agoYou need write access to: HKLM\Software\Synaptics\%ProductName%\Default Which requires administrator or equivalent, so that is preventing a user from even keylogging themselves.
- gruez 9y ago
- swarnie_ 9y agoIs this old news? I remember an audio driver (maybe?) causing a similar issue 6-9 months ago. I worked for a HP reseller at the time and could replication the issue on almost every model in our labs
- muxator 9y agoTo me, this is one more reason to never use the default install of an operating system. In this specific case, if the debugging "leftovers" were part of the official drivers, then I would say there is a good indication towards preferring a free OS.
- ryanlol 9y agoWhy does obvious bullshit like this get so much visibility? Why not "Windows found to have hidden keylogger", it also ships with functionality that allows you to capture keystrokes if you so insist?
- tonylemesmer 9y agoprevious https://news.ycombinator.com/item?id=14314795 https://news.ycombinator.com/item?id=14314795
- kaputsmack 9y agoLike Reddit this place is full of shills paid to say this is ok or not a big deal. There is a keylogger in a factory new HP notebook, but meh
- loerres 9y agoWell, Synaptics Touchpad Drivers always sucked. "Windows Precision Touchpad" is pretty good but not quite on Apples level.