Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

This USB wall charger secretly logs keystrokes from Microsoft wireless keyboards nearby
venturebeat.com ^ | January 12, 2015 | Emil Protalinski

Posted on 01/14/2015 11:50:55 AM PST by Second Amendment First

Privacy and security researcher Samy Kamkar has released a keylogger for Microsoft wireless keyboards cleverly hidden in what appears to be a rather large, but functioning USB wall charger. Called KeySweeper, the stealthy Arduino-based device can sniff, decrypt, log, and report back all keystrokes — saving them both locally and online.

This is no toy. KeySweeper includes a web-based tool for live keystroke monitoring, can send SMS alerts for trigger words, usernames, or URLs (in case you want to steal a PIN number or password), and even continues to work after it is unplugged thanks to a rechargeable internal battery. That’s an impressive list of features, especially given that Kamkar told VentureBeat the whole process “took a few days” including a few over Christmas break and this past weekend when he decided “to properly document it.”

This “spy tool” only affects Microsoft wireless keyboards, and it allegedly works with many, if not most, of them. As a result, we reached out to let the company know. “We are aware of reports about a ‘KeySweeper’ device and are investigating,” a Microsoft spokesperson told VentureBeat.

KeySweeper exploits multiple bugs, including the fact that all Microsoft keyboards use the same first byte in their MAC address. Along with a few other holes, it can thus allegedly decrypt any Microsoft keyboard nearby without having to specify its MAC address first.

Kamkar told VentureBeat that he tested KeySweeper “on a brand new keyboard I purchased only a few weeks ago from Best Buy.” Naturally he hasn’t tested it on all Microsoft keyboards — that’s a claim the company will undoubtedly have to verify itself.

In the meantime, Kamkar has put together a walkthrough video for a more in-depth look of KeySweeper:

Kamkar says the unit cost for KeySweeper ranges from $10 to $80, depending on which functions you require. The hardware breakdown is as follows:

$3 – $30: An Arduino or Teensy microcontroller can be used. $1: nRF24L01+ 2.4GHz RF Chip which communicates using GFSK over 2.4GHz. $6: AC USB Charger for converting AC power to 5v DC. $2 (Optional): An optional SPI Serial Flash chip can be used to store keystrokes on. $45 (Optional): Adafruit has created a board called the FONA which allows you to use a 2G SIM card to send/receive SMS, phone calls, and use the Internet directly from the device. $3 (Optional if using FONA): The FONA requires a mini-SIM card (not a micro-SIM). $5 (Optional, only if using FONA): The FONA provides on-board LiPo/LiOn battery recharging, and while KeySweeper is connected to AC power, the battery will be kept charged, but is required nonetheless.

As for the software, the primary code is installed on the microcontroller, while the web-based backend uses jQuery and PHP. KeySweeper’s source code and schematic are available on GitHub.

KamKar hopes his project will do more than just give would-be spies a how-to guide. He told VentureBeat: “I hope this creates pressure to ensure that we have proper encryption in new wireless products that come out!”


TOPICS: News/Current Events
KEYWORDS:
Navigation: use the links below to view more comments.
first 1-2021 next last
keysweeper
1 posted on 01/14/2015 11:50:55 AM PST by Second Amendment First
[ Post Reply | Private Reply | View Replies]

To: Second Amendment First

How many people just leave a charger plugged in like that? The only time I plug in a charger is when I’m charging something.


2 posted on 01/14/2015 11:54:34 AM PST by Oshkalaboomboom
[ Post Reply | Private Reply | To 1 | View Replies]

To: Second Amendment First; null and void

Now our wall warts are spying on us!...........................


3 posted on 01/14/2015 11:55:30 AM PST by Red Badger (If you compromise with evil, you just get more evil..........................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Second Amendment First

The basics of computer security?

1. Never use wireless anything.


4 posted on 01/14/2015 12:00:29 PM PST by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: Oshkalaboomboom

“How many people just leave a charger plugged in like that? The only time I plug in a charger is when I’m charging something.
****************************************************************************************************
Interesting bit from the article:

“...KeySweeper... even continues to work after it is unplugged thanks to a rechargeable internal battery....”


5 posted on 01/14/2015 12:10:03 PM PST by House Atreides
[ Post Reply | Private Reply | To 2 | View Replies]

To: Oshkalaboomboom
How many people just leave a charger plugged in like that?

Quite a few. I was over at my mother's just the other day, and pulled out her Ipad charger, telling her that it does draw power just plugged in alone, and reminded her that even each of the GFI outlets draw upwards of 50w/day.

6 posted on 01/14/2015 12:12:05 PM PST by Calvin Locke
[ Post Reply | Private Reply | To 2 | View Replies]

To: proxy_user

I really don’t use much wireless except for a micro keyboard for stand alone thin clients.

Every paper shuffler I support either has one or wants one. They also want dual big monitors and their own printer.


7 posted on 01/14/2015 12:17:02 PM PST by wally_bert (There are no winners in a game of losers. I'm Tommy Joyce, welcome to the Oriental Lounge.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Oshkalaboomboom

Leave mine in my office plugged in all the time.


8 posted on 01/14/2015 12:22:53 PM PST by Lee'sGhost ("Just look at the flowers, Lizzie. Just look at the flowers.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: Second Amendment First
My camera charger looks just like that.....

(switching to wired keyboard)

9 posted on 01/14/2015 12:42:03 PM PST by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 1 | View Replies]

To: sneakers

bttt


10 posted on 01/14/2015 12:44:34 PM PST by sneakers
[ Post Reply | Private Reply | To 1 | View Replies]

To: Second Amendment First

I’ve suspected that Arduino is the back door for many of these “Internet of Things”


11 posted on 01/14/2015 1:20:12 PM PST by Zathras
[ Post Reply | Private Reply | To 1 | View Replies]

To: Calvin Locke
and reminded her that even each of the GFI outlets draw upwards of 50w/day

If she has a 50W lamp plugged in it and turned on, then yes. But no, the ground fault interrupt outlet does not draw anything on it's own.

12 posted on 01/14/2015 1:24:08 PM PST by Monitor ("The urge to save humanity is almost always a false-front for the urge to rule it." - H. L. Mencken)
[ Post Reply | Private Reply | To 6 | View Replies]

To: proxy_user

I have worked at one place where wireless devices were explicitly prohibited due to security reasons.


13 posted on 01/14/2015 1:39:48 PM PST by Fred Hayek (The Democratic Party is now the operational arm of the CPUSA)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Monitor

Last time I checked (probably a dozen years ago), there’s a National Semi part inside each one (doesn’t matter the brand), and when all is said and done, it draws 2w/hour just being connected.


14 posted on 01/14/2015 1:41:12 PM PST by Calvin Locke
[ Post Reply | Private Reply | To 12 | View Replies]

To: Calvin Locke; Monitor

Here is a discussion on it.

http://www.garagejournal.com/forum/showthread.php?t=209624&showall=1


15 posted on 01/14/2015 2:33:29 PM PST by ansel12 (Civilization, Crusade against the Mohammedan Death Cult.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Second Amendment First
When are these gadgets going to start talking to us and controlling our movements?
16 posted on 01/14/2015 4:24:34 PM PST by Cecily
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger; COUNTrecount; Nowhere Man; FightThePower!; C. Edmund Wright; jacob allen; ...
Nut-job Conspiracy Theory Ping!

To get onto The Nut-job Conspiracy Theory Ping List you must threaten to report me to the Mods if I don't add you to the list...


17 posted on 01/14/2015 5:58:33 PM PST by null and void (The aggregate effect of competitive capitalism is indistinguishable from magic)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Second Amendment First

i figured everyone knew wirless keyboards were easily plucked from the air

this just allows joe-average to install it and receive the info over the net


18 posted on 01/14/2015 6:38:33 PM PST by sten (fighting tyranny never goes out of style)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Second Amendment First
Let's face it. Every single thing we do online is tracked and stored. There is a huge underground bunker of government officials who are, as I type this, monitoring the online activity of every single American. They are all giggling and making fun of us.

I just want to say hello to them and let them know that I know they are out there.

19 posted on 01/14/2015 6:42:31 PM PST by SamAdams76
[ Post Reply | Private Reply | To 1 | View Replies]

To: proxy_user

You forgot 2: See 1. /snark


20 posted on 01/14/2015 9:28:31 PM PST by piytar (No government has ever wanted its people to be defenseless for any good reason.)
[ Post Reply | Private Reply | To 4 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson