I also think to have heard that in some cases broken keyboards can cause your laptop to not work anymore at all because of this but I didn't remember where I heard this, does anyone happen to know the source/correctness of that?
Yes, it is both a security leak and a useful feature: it is useful to find a lost/stolen device as the location will become visible whenever anyone powers it up with access to an internet connection.
How does find myMac work in this case?
So that means you will never use that laptop on a network again?
That's.. entirely good I suppose, but would be news to me.
Either way, seems like a terribly buggy design.
[1] https://www.reddit.com/r/PrivateInternetAccess/comments/gqkh...
It does both make sense and seem incredibly buggy. It'd have to be a fairly impressive attack vector that hits the keyboard firmware, but if you did, I suppose you'd have access to the raw key stream to exfiltrate... not curious to see if it applied on my Mac Pro (which just has a WASD keyboard - I don't use the Apple Magic Keyboard), or a MBP without touchbar (maybe this is the firmware, not the keyboard per se). I do know it is demonstrably the VPN at issue - I can disable our always-on device VPN and the problem goes away, but alas, no easily accessible source that says "verification of HID firmware" or similar.
I've even gotten the "you don't have a keyboard plugged in" error message on my laptop (because the keyboard hasn't been detected after ~30 seconds).