Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Security firm cracks encryption for Microsoft's wireless keyboards
Heise Security ^ | 12-1-2007 | Heise Security

Posted on 12/18/2007 9:22:32 PM PST by zeugma

Security firm cracks encryption for Microsoft's wireless keyboards

Dreamlab Technologies AG says it has found a way to sniff the data traffic between Microsoft's wireless keyboards and their base stations, which communicate with each other on the 27 MHz band. In the method they discovered, unauthorized parties are reportedly able to record and decrypt all keystrokes from such keyboards. The decoding was demonstrated using data traffic from the Wireless Optical Desktop 1000 and 2000. The security firm says that other keyboards that Microsoft sells, such as the Wireless Optical Desktop 3000 and 4000, encrypt and transmit data using the same procedure, so that they are also probably unsafe. Keyboards that use Bluetooth for communication are not vulnerable.

Max Moser and Philipp Schrödel say that decryption was very easy because the devices use a simple XOR mechanism for encryption and the keys are only one byte long. They claim that even a PDA with a slow ARM-CPU would have derived the combination quickly. Aside from not using such keyboards, there is no workaround. Microsoft has yet to react to the Swiss firm's announcement.



TOPICS: Business/Economy; Culture/Society; News/Current Events
KEYWORDS: crack; geeknews; keyboards; microsoft; wireless
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-68 next last
I really don't mean to laugh, but a one byte XOR? OMG how incredibly lame.
1 posted on 12/18/2007 9:22:33 PM PST by zeugma
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

You should enjoy this. Too funny.


2 posted on 12/18/2007 9:23:17 PM PST by zeugma (Hillary! - America's Ex-Wife!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

No different than pulling a ribbon from the trash 25 years ago.


3 posted on 12/18/2007 9:24:38 PM PST by eyedigress
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Micro-trash- The nations #1 landfill problem.


4 posted on 12/18/2007 9:29:03 PM PST by Nathan Zachary
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

so how does this affect joe six pack using one of these wireless keyboards and a hacker online 1000 miles away? Not sure I understand the way someone would de code the encryption over the internet, or is this article demonstrating this scenario in an office environment where every cubicle sits a Microsoft WirelessDesktop 1000 and while cubicle worker Tom is busily typing to a love interest that is not his wife, cubical worker Jim with a little too much time on his hands can follow Tom’s every keystroke?


5 posted on 12/18/2007 9:32:29 PM PST by Blue Highway
[ Post Reply | Private Reply | To 1 | View Replies]

To: nnn0jeh

ping


6 posted on 12/18/2007 9:33:40 PM PST by kalee
[ Post Reply | Private Reply | To 1 | View Replies]

To: Blue Highway

And if in the above example, what program/software is Jim using to accomplish this security breach?


7 posted on 12/18/2007 9:34:43 PM PST by Blue Highway
[ Post Reply | Private Reply | To 5 | View Replies]

To: zeugma

Well they’re no good for classrooms whether or not there’s a security issue. When IBM came out with it’s ill-fated “PC Jr.” back in 1983 or so, schools nationwide soon found that the kids loved pointing the keyboard at somebody else’s computer and typing away.


8 posted on 12/18/2007 9:39:21 PM PST by jiggyboy (Ten per cent of poll respondents are either lying or insane)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

I guess I should care, but I don’t. An $8 keyboard will do the job nicely. If you want iron clad security, don’t use a wireless device.


9 posted on 12/18/2007 9:44:42 PM PST by Poser (Willing to fight for oil)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Poser
I guess I should care, but I don’t. An $8 keyboard will do the job nicely. If you want iron clad security, don’t use a wireless device.

If you're not going to bother to do better than a one byte XOR, you shouldn't be calling it "encrypted". People who don't know better might think that a company like Microsoft, with all their billions of dollars could do better than your average ten year old when it comes to "encrypting" data.

10 posted on 12/18/2007 9:50:02 PM PST by zeugma (Hillary! - America's Ex-Wife!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Blue Highway
so how does this affect joe six pack using one of these wireless keyboards and a hacker online 1000 miles away? Not sure I
understand the way someone would de code the encryption over the internet, or is this article demonstrating this scenario in an office environment where every cubicle sits a Microsoft WirelessDesktop 1000 and while cubicle worker Tom is busily typing to a love interest that is not his wife, cubical worker Jim with a little too much time on his hands can follow Tom’s every keystroke?

It's not an internet attack, so that's not relevant.  Consider a corporate environment where someone might have such a keyboard, and have all of their passwords floating through the air to anyone who cared to listen. You might want to keep in mind that the vast majority of "hacking" takes place by insiders, not evildoers on the other side of the firewalls.

The real key IMO is that this is being sold as a device that "encrypts" the data channel. Put simply, it's false advertizing at best.

 

11 posted on 12/18/2007 9:54:42 PM PST by zeugma (Hillary! - America's Ex-Wife!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Blue Highway
Key strokes could be lifted in other situations like apartments that are close together. Passwords for bank accounts, Email accounts, network access etc can then be stolen by the neighborhood geek.
12 posted on 12/18/2007 10:27:16 PM PST by DB
[ Post Reply | Private Reply | To 5 | View Replies]

To: jiggyboy

I still have a PC Jr. =)


13 posted on 12/18/2007 10:27:46 PM PST by Just Lori (There is nothing democrat-"ic" about democrats.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: zeugma

Actually if I had to pay $5 more for a super encrypted wireless keyboard, I would not do it.


14 posted on 12/18/2007 10:32:52 PM PST by microgood
[ Post Reply | Private Reply | To 1 | View Replies]

To: Blue Highway
so how does this affect joe six pack using one of these wireless keyboards and a hacker online 1000 miles away?

The article also mentions that the keyboard communicates on the "27 MHz band", which is also where the old CB (Citizen's Band) is located. So, if the skip is just right (and you have your keyboard connected to a big ol' afterburner and a really big set of ears), I guess it MIGHT be possible for a hacker located on the other side of the continent to hear you...

15 posted on 12/18/2007 10:43:10 PM PST by Skibane
[ Post Reply | Private Reply | To 5 | View Replies]

To: Skibane
So, if the skip is just right (and you have your keyboard connected to a big ol' afterburner and a really big set of ears), I guess it MIGHT be possible for a hacker located on the other side of the continent to hear you...

Yeah, but only if you have a single-sideband keyboard.

16 posted on 12/19/2007 4:45:46 AM PST by antinomian (Show me a robber baron and I'll show you a pocket full of senators.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

17 posted on 12/19/2007 5:11:02 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: microgood
Actually if I had to pay $5 more for a super encrypted wireless keyboard, I would not do it.

I have never, and will never, buy a wireless keyboard or mouse.

18 posted on 12/19/2007 5:22:16 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Blue Highway
"so how does this affect joe six pack using one of these wireless keyboards"

How about when joe six pack is sitting there typing away managing his bank account online or purchasing something from a web site while 'hacker-x' is sitting outside of joe's house capturing everything. Of course this already goes on for those poor lost souls who continue to not use WPA PSK wireless access points.

19 posted on 12/19/2007 5:41:02 AM PST by KoRn
[ Post Reply | Private Reply | To 5 | View Replies]

To: zeugma
I really don't mean to laugh, but a one byte XOR? OMG how incredibly lame.

Remember back in the days of Windows NT, when all you had to do was change one registry key to turn Workstation into Server?

Some of the folks at Microsoft come up with great products. Unfortunately, most of the folks there do not.

20 posted on 12/19/2007 6:08:45 AM PST by rabscuttle385 (It takes courage to grow up and turn out to be who you really are.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-68 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson