HP keylogger
zwclose.github.io
zwclose.github.io
Indeed, this is pretty benign compared to the "feature" in Windows 10 which does log and send that information if you enable it... and I believe this is enabled by default:
https://images.techhive.com/images/article/2015/08/0904-win1...
I really wish the "security" people would stop "crying wolf" constantly with things like this.
I personally appreciate the post, because i like to be aware of what could be potentially recorded or transmitted on machines i use. It doesn't have to "be worse than windows10" to be useful info to some users, and we certainly shouldn't expect all security-minded blog posts to be breaking news to be taken seriously.
Context aside i find it fun to watch things unravel or peer into how other people work!
This answer explains and also has a link to ms with more detail on how it’s blocked: https://stackoverflow.com/questions/3169675/how-to-use-setwi...
Malicious keyloggers are used all the time of course, but I believe they all require some sort of exploit or way to effectively gain admin privileges.
The answer was about intercepting messages sent to an already escalated process (i.e. monitoring administrator processes from a user's context, even if they're technically an administrative user).
It works for one user context process monitoring another user context process. It doesn't work for IE or Edge due to LowPriv context isolation.
Perhaps you've heard of the disaster known as X?
It's pretty clear that 'security' has never been a concern for Linux desktop developers, what software would you choose to run on your open source hardware instead of linux?
Here are a plenty of exploit mitigations that simply do not exist for Linux, https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W...
I'm speaking of Intel's management engine. Hacked.
I'm also speaking of Apple's secure enclave processor. Hacked and unencrypted.
Yeah, it'll by you some time. But when the target's nice and fat and juicy, well do I have a story for you...
Perhaps they just recognised that it could explode into a Superfish sized PR problem and went to fire off some angry calls to Synaptics for not surrounding their debug prints with ifdef.
I wonder if the old driver was WHQL-certified as well... (Although I'm under the impression that just needs to pass the SDV)