3 ms·
Definitely a good start but in a targeted attack scenario that's pretty trivial to bypass, if someone brags about having the latest Das Keyboard or something t
by shittyadmin 7y ago
Definitely a good start but in a targeted attack scenario that's pretty trivial to bypass, if someone brags about having the latest Das Keyboard or something that's all it'd take... we need cryptographic authentication in the USB specification or at least a randomized serial that'd be unique per device so an attacker would need physical access to clone your keyboard.
I believe modern Thunderbolt already has this sort of cryptographic device authentication, which means not only physical access but at least a bit of reverse engineering skill, a much higher barrier than knowing their keyboard model.
- Reelin 7y agoIt's particularly frustrating because of how trivial the solution appears to be. Trust on first use is more than sufficient in this case, so asymmetric cryptography with a randomized key would be fine. I realize mass produced electronics can be very cost sensitive and that a PKI chip might add a whole $0.70 to your product (https://www.digikey.com/en/product-highlight/a/atmel/atsha204a-full-turnkey-security-device https://www.digikey.com/en/product-highlight/a/atmel/atsha20...), but still. I paid ~$50 for my keyboard! I would not have begrudged the manufacturer an extra dollar or two in order to ensure my system's security.