Yo everyone! I have questions about using cheap and generic mechanical keyboards. For example the Royal Kludge RK61 which has wired, Bluetooth and 2.4GHz connections. My host will be Linux machines. Do you see any security issues with using keyboards like that or were there any incidents of such devices being malicious?

Another concern might be the 2.4GHz USB that’s included. Assuming it’s not doing anything malicious is the connection encrypted or would you always instead use wired or Bluetooth? Thanks for any answers!

  • scoredseqrica@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 year ago

    The boring answer is that you should always be cautious about any device that you use with your computer.

    Any device you plug into your computer, if malicious, can cause all manner of issues. From outright bricking your mobo to injecting malware. This is why you should never plug an unknown usb drive you find into your computer. Any keyboard is vulnerable to keyloggers and other snooping techniques.

    With that said, is it likely? No, not really. It’s quite difficult for a keyboard to phone home unless it’s quite sophisticated, also you’re on Linux, most malware is for windows anyway. I’ve not really heard of this type of attack being used against individuals.

    To be honest you’re probably not a target! If you work somewhere that a bad actor may want to target (the government, the power grid, military, a bank etc) and you want to use the keyboard with a work device or on the same network, then yes you should only use devices your IT team have approved to be safe. Otherwise for you at home, who isn’t being targeted by state level adversaries, a keyboard off the internet is probably fine.

    • octoffset@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Thanks for your answer! In a busy city, would you only used wired connection to it? Bluetooth is encrypted and probably fine too. Any thoughts on the included 2.4GHz dongle?