I see a lot of ads these days for fancy mechanical keyboards from numerous brands, but the thing I always wonder about is: how do we know these keyboards dont have keyloggers or other spying tech built into them?
I see a lot of ads these days for fancy mechanical keyboards from numerous brands, but the thing I always wonder about is: how do we know these keyboards dont have keyloggers or other spying tech built into them?
the USB suspend state could be used to detect when the computer is asleep which could help with getting the login credentials, but the attack would absolutely be tempermental and realistically just installing malware on the computer via the keyboard would be easier.
Yeah. Opening a terminal and doing a web fetch to install some spyware is probably the most practical version of the potential attack.
It would still, I think, be pretty noticable when it ran (just the first time).
But you make a good point that the USB power state might a way to guess when the user is away.
I think it could be done.
For anyone reading along and worried, there’s still two bits of good news: