I don't think this is generally worth it as a security measure, but the goal is not to protect against automation. Instead, custom on-screen keyboards are attempts to thwart keyloggers.
I don't think this is generally worth it as a security measure, but the goal is not to protect against automation. Instead, custom on-screen keyboards are attempts to thwart keyloggers.
Commercial malware doesn't work this way. The term "keylogger" is a misnomer.
"Keylogging" without context provides an unintelligible stream of garbage that might have well be from a random number generator. Most malware that I've seen either directly target the browser or the operating system, but in both cases they're looking for an unencrypted HTTPS stream, that they can re-package, upload, and store. With the goal to sell batches of credentials for specific websites.
Many people have this unusual belief that a user's stream of keys would look like e.g. www.example.com(13)username(9)password(13). But that isn't how users typically interact with their browsers, MOST websites are accessed via a search engine or favorites/bookmarks, and users often won't use the keystrokes to navigate between input elements.
Again, CONTEXT is everything with "keylogging," since most of the value is generated from WHERE not just WHAT. "Targeted credential theft" is a better way to describe it since they're stealing structured HTTP form data, not raw keyboard input (and even if they were steaming keycode inputs, they'd likely still be using the browser's context to do so).
So, in my opinion, most malware wouldn't even be aware or need specific support to bypass this virtual keyboard "security" because by the very nature of them they aren't operating at this layer anyway.
One of those "Things programmers believe about malware" articles needs to be written. There's a lot of "Schrödinger's cat"-level thinking going on, wherein malware is both running with full rights of the user while ALSO somehow needs to rely on raw keystrokes to record anything.
I would guess approximately no one does this as standard behavior.
In any case, both hardware and software keyloggers exist which would be thwarted by an onscreen keyboard. If I recall correctly, mouse keyboards became popular when keyloggers started being more known, and the following generation of malware took screenshots every time you clicked.
It’s a very obsolete security measure but did make sense briefly.
I don't know about commercial malware, but at least in the 90s (which is when these kinds of on-screen keyboards started to appear), it was not unusual to find on a computer "infected" with malware a text file containing every key that was pressed since the malware was installed.
Yes, nowadays malware tends to be much smarter: also capturing an image of the area around the mouse pointer on every click (which is the reason some on-screen keyboards blank the keys when you click), only logging when the window has an specific title (which is the reason some online banking sites add lots of random spaces and punctuation to the window title), or even using lower-level code to hook into the browser and directly capture the form contents on submission (which is the reason several online banking sites require you to use invasive "anti-malware" plugins which attempt to prevent these kinds of hooks).
And yes, there is malware that collects unencrypted traffic, but that is _appreciably_ more complex to design and implement than simple keylogging. There's also malware which pulls credentials directly out of the web browser memory, although improved protections on cross-process memory access are making this much harder to do on real operating systems. Both of these are better methods, but they are harder and operating systems are intentionally implementing measure to defeat them. For mostly historic reasons straightforward keylogging remains easy and reliable on modern computers.
But it doesn't really refute the kind of snapshot-in-time voodoo that government websites tend to build out and then never change because if doing so were to cause a problem, then someone could get blamed. I've never seen such a UI contraption in the "private" sector of banking. Not that they don't have their own obtuse slow moving corporate bullshit like snake oil "2FA" with varying requirements, it's just less bad.
FWIW related to this topic does anyone know the details of how the IRS website just decides to spit out "Permission Denied" when trying to obtain an EIN? I think it's an Akamai? message, probably due to some user surveillance garbage, but haven't investigated further. Even coming from my own naive residential IP with surveillance-friendly Chromium I still got it. I figured I'd wait a few days and try again, but same thing. It worked fine from a vanilla iPhone on the cell connection, but unfortunately I ended up doing that too late and missed the window to lock in April's rate.
Couldn't you do that with a bookmarklet, so it would just take one click?
Like, this brand of "security" is being persisted with, in 2022, when virtually nothing else uses this sort of approach, and the writing's been on the wall for so long you almost can't see the wall for the writing anymore. And yet.
At the end of the day from an actual-security standpoint there's a lot to be said for generally rooting this kind of thing out and doing away with it, but given the direct association to vaults and banks and government (and probably military) systems and whatnot it's one situation where the blowback might genuinely cause enough bad press to require a summary firing or two as a token of reassurance to the type of old-world mindset in charge of this sort of thing. Maybe.
*shrug* that's a worst-case-scenario imagining what might happen, at least. I honestly have no idea. I just get strong "swim away!!" vibes from it, heh
1. They don’t have network access by default. It’s not a simple confirmation screen to enable network access. You have to go into settings
2. Apps can explicitly disallow third party keyboards for password entry.
3. Keyboards run out of process from the app.
And yes, iOS has extensibility support for third party password managers.
Of course, a physical keylogger is a different beast, but really, if you got physical access enough to install an actual piece of hardware...