Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Radio Hack Steals Keystrokes from Millions of Wireless Keyboards
wired.com ^ | 07/26/2016

Posted on 07/26/2016 9:08:16 AM PDT by BenLurkin

You should be able to trust your wireless keyboard. And yet security researchers have been warning people to be suspicious of wireless computer accessories using sketchy radio protocols for years. Those warnings peaked five months ago, when hackers at the security firm Bastille found that millions of cheap keyboard and mouse dongles let hackers inject keystrokes onto your machine from hundreds of yards away. Now, in case you missed that message, the same researchers have extended their attack to millions more devices—and this time, they can not only inject keystrokes, but also read yours, too.

On Tuesday Bastille’s research team revealed a new set of wireless keyboard attacks they’re calling Keysniffer. The technique, which they’re planning to detail at the Defcon hacker conference in two weeks, allows any hacker with a $12 radio device to intercept the connection between any of eight wireless keyboards and a computer from 250 feet away> What’s more, it gives the hacker the ability to both type keystrokes on the victim machine and silently record the target’s typing.

The keyboards’ vulnerability, according to Bastille’s chief research officer Ivan O’Sullivan, comes from the fact that they all transmit keystrokes entirely without encryption. The manufacturers’ only plan against attackers spoofing or eavesdropping on their devices’ communications is to depend on the obscurity of the radio protocols used. “We were stunned,” says O’Sullivan. “We had no expectation that in 2016 these companies would be selling keyboards with no encryption.”

(Excerpt) Read more at wired.com ...


TOPICS: Computers/Internet
KEYWORDS: hacking; internet; tech; wifi; wireless
Navigation: use the links below to view more comments.
first 1-2021-35 next last

1 posted on 07/26/2016 9:08:16 AM PDT by BenLurkin
[ Post Reply | Private Reply | View Replies]

To: BenLurkin

I like my wired Lenovo keyboard, sure it isn’t nice and shiny like those expensive wireless keyboards and it just always work and does not need batteries. And hackers can’t easily hack it.

Wow, sometimes old tech is best


2 posted on 07/26/2016 9:12:48 AM PDT by arl295
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

First thing I do with a new laptop is totally and permanently disable the wireless.
Ok, maybe first I put the band-aid over the camera...
draw the curtains in my Faraday cage...
but seriously, wireless is mischief waiting to happen.


3 posted on 07/26/2016 9:14:49 AM PDT by Buttons12
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Looks like I’ll be swapping out both of my wireless keyboards. Thanks for posting this.


4 posted on 07/26/2016 9:15:16 AM PDT by Two Kids' Dad (((( Hillary Clinton is a felon. As yet unindicted, but a felon nonetheless ))))
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

looks like a general purpose 2.4 Ghz RF sniffer: http://www.geeetech.com/wiki/index.php/Crazyradio


5 posted on 07/26/2016 9:15:17 AM PDT by bigbob (The Hillary indictment will have to come from us.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: arl295
My wife and I have been having this debate for a few years. I go with the hard wire system. She likes the battery bleeding wireless variety. I tell her if it is not nailed down someone will steal it, count on it. Now I guess I have to add, if it is not hard wired, it is susceptible to being stolen from the air.
6 posted on 07/26/2016 9:16:16 AM PDT by Mouton (The insurrection laws maintain the status quo now.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: arl295

Security by obscurity, isn’t.


7 posted on 07/26/2016 9:16:56 AM PDT by The Antiyuppie ("When small men cast long shadows, then it is very late in the day".)
[ Post Reply | Private Reply | To 2 | View Replies]

To: BenLurkin

I’m more worried they will intercept my mouse’s movements. ;^)


8 posted on 07/26/2016 9:20:55 AM PDT by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin
Pfffft, this is nothing. Ask either of my two sons what I can do to their computers easily, anytime I want. I can inject keystrokes, scramble their video, freeze and reboot their computers anytime I want, whether or not they have a wireless or wired keyboard attached to it.

I just key up 1,500 watts on 40 or 75 Meters on my ham rig into the fan dipole and watch the fun begin!

I love keying up and hearing the screams of "DAD!!!!" from two floors up. Makes them want to move out of the house faster.

9 posted on 07/26/2016 9:23:28 AM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Buttons12

Kinda stunned at the lack of an authentication protocol — including a checksum based on a confidential key would be quite enough.


10 posted on 07/26/2016 9:23:54 AM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: The Antiyuppie

Isn’t that the Apple motto?


11 posted on 07/26/2016 9:24:06 AM PDT by arl295
[ Post Reply | Private Reply | To 7 | View Replies]

To: usconservative

Well that’s rude to the neighbors too. FCC used to care about that, at least.


12 posted on 07/26/2016 9:24:40 AM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: BenLurkin

I’m sorry, but I have always thought that only an idiot would use a wireless keyboard or mouse with a computer. It’s not as if you need to be running around your house with a keyboard and mouse, you are only ever going to be using it within the range of a cord in the first place.

I can see using them if you are using a television for a monitor and want to lay on the couch across the room, but for most purposes, they’re just adding another annoyance with the need to change batteries.


13 posted on 07/26/2016 9:24:46 AM PDT by Boogieman
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mouton

Even if it is hard wired it can sometimes be spied on (though injecting data may not be possible).


14 posted on 07/26/2016 9:25:58 AM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: usconservative

Ha... haven’t they realized they can just turn off the wi fi antenna and run an ethernet cable to the router to avoid that???


15 posted on 07/26/2016 9:26:35 AM PDT by Boogieman
[ Post Reply | Private Reply | To 9 | View Replies]

To: BenLurkin

I wonder if any of our high tech IT gurus in FR know if using a VPN app with their encrypted servers prevents this danger.

Anyone? Buehler? Anyone?


16 posted on 07/26/2016 9:26:40 AM PDT by wildbill (If you check behind the shower curtain for a slasher, and find one.... what's your plan?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Of course you can do the same thing with wired keyboards too. It’s a little more difficult, the equipment is a little more expensive, but it can be done and has been done. It’s one of the reasons secure facilities put that magnetic shielding on windows. The fact is if somebody wants your keystrokes and you’re not turning your house into a military grade facility they will get them.


17 posted on 07/26/2016 9:30:46 AM PDT by discostu (Joan Crawford has risen from the grave)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

I have a Zagg Wireless keyboard using it with an Apple IPAD.

I haven’t read the article, but I’m leery of my security after hearing about this.


18 posted on 07/26/2016 9:33:44 AM PDT by Perseverando (For Progressives, Islamonazis & other Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HiTech RedNeck
Neighbors don't have an issue, I've asked and verified. They get zero interference, even on their cheap, crappy Chinese made baby monitors.

I run a clean station. The problem for both my sons is they're close enough to the fan dipole that their computers suffer from fundamental front end overload.

Neighbors are far enough away that they don't have that issue.

Now, about your FCC comment: The FCC's position on interference from Ham Radio Operators has changed dramatically. If one of my neighbors were to complain, the FCC would tell them succinctly to get the problem fixed with their devices manufacturer. The problem isn't mine, it's the device they purchased.

With so much of our electronics made in China or elsewhere now, the FCC can no longer regulate electronic shielding and rf protection on consumer devices. If you look in a relatively modern device manual, you'll find a paragraph in the front or back of the manual from the FCC which states "this device must accept interference ...." along with some other language. That interference is broadly based, including ham radio.

Conversely, I've had issues with my neighbors devices such as pool filter motors, air compressors, car battery chargers and other devices throwing massive interference into the air that I've picked up and has interfered with my operations. The FCC says my neighbors MUST remedy their interference issues/stop using those devices and quit interfering with me. The premise is I have a Federal License to transmit and receive, they do not. Their devices are considered "transmitting" by the FCC and since the neighbors don't have a license to do so, they're in violation.

Realistically is the FCC going to do anything about my neighbors interference? Not until I attempt to remedy the situation myself, and then complain like HELL to the FCC if they don't. I've had three cases of neighbors devices (named above) interfering with me. All three were successfully and amicably resolved with those neighbors by my providing parts and expertise to fix the issue.

I'm very fortunate that I have great neighbors who've been very supportive of my hobby. Several have called my amateur radio antenna tower "a work of art" and others think it's "cool." The one who hated it moved away several years ago.

19 posted on 07/26/2016 9:36:37 AM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 12 | View Replies]

To: Boogieman
I've hardwired everything to their computers and put rf chokes on every input cable, built AC line filters and more. The problem is they're just too close to the antenna.

I jokingly say I can do it with 1,500 watts, the reality is I can do it with as little as 200. Only happens on 40 and 75/80 meters.

Fortunately for them, I've gotten more into the digital modes (JT-65) lately and aren't running more than 25 watts on any band. :-)

20 posted on 07/26/2016 9:39:17 AM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 15 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson