meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 9th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 9 November 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Gaming Keyboard Exfiltrates Data; Logitech Will Brick Harmony Link; Amazon Introduces Addtl Security

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, November 9th, 2017 edition of the Sands and a Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and today I'm recording from Miami, Florida.

0:12.3

Software extensions to keyboards on mobile devices have long been known to exfiltrate data.

0:20.1

Many of these software keyboards have legitimate reasons to do so, like for example for

0:26.6

auto-completion algorithms or for spell checkers and like that run as a cloud service, so

0:33.6

keystrokes need to be exfiltrated in order to actually provide these services.

0:39.8

But of course this feature can easily be abused in particular if a company loses control over

0:45.0

these cloud services or of course if a keyboard is created by a malicious entity.

0:52.6

Mechanical keyboards have so far not used features like this until now.

0:57.0

Recently, users of the Mantis Tech, 104 key mechanical gaming keyboard, found that their key

1:06.0

strokes are being exfiltrated to a web service in China.

1:11.1

Keyboards typically do not have network connectivity,

1:14.8

but in this case, the special driver used by the keyboard

1:19.3

is used to exfiltrate the data.

1:22.1

This cloud driver, as it is referred to,

1:25.3

is collecting performance data

1:27.4

and passing it to the manufacturer of the keyboard.

1:31.3

Of course, this performance data includes actual keystrokes, or at least it can include them from the data I have seen.

1:40.3

However, it isn't clear if the actual keystrokes are being exfiltrated or if it's really only

1:46.7

the number of keys that are being pressed but either way confidential data is leaked and of course

1:53.8

this cloud driver could easily exfiltrate additional key data and definitely could exfiltrate keystrokes.

2:03.9

The report I will link to in the show notes includes the IP address and additional details

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.