Ask HN: How do you tell if something has a keylogger implemented
Thanks
Thanks
A game is usually supposed to capture what buttons you press and, if it's an online game, send that over the internet, and so that would be perfectly fine as long as that's done while the game is running - so perhaps you're asking whether the game installs some malware that captures keystrokes outside of the game as well.
That would be generally detected by looking for various malware persistence mechanisms, seeing if there's something that's started on startup, possibly in a hidden way; or if there's some process that hides its activity. And if so, then you could check whether it was placed there by that game.
On the other hand, some of the anti-cheat mechanisms are so invasive that they effectively are far more capable than just a keylogger, and the game is quite open about placing them on your machine, e.g. requiring permissions to install it as a privileged driver.
Game over right there. No matter what it does or doesn't do today, you never know what they'll push in the next update, or when ownership changes hands. I'd never run a game with admin rights.
You basically have three options:
- Cross your fingers and pray that the game company isn't going to do anything malicious to your machine
- Keep your gaming PC completely isolated from your private data
- Accept that you won't be able to play some competitive games, or the competitive modes of some games (eg. the default CounterStrike multiplayer runs with usermode anticheat, but competitive matchmakers like FaceIt require you to install a kernel-level anticheat)
My wish is that multiplayer games would have the option to play on servers with anti-cheat and servers without anti-cheat. If my memory serves correctly, that is kind of how Microsoft's Halo: Master Chief Collection is, at least when played on the Steam Deck. While I don't like the entire experience (e.g., having to use a MS account), at least optional anti-cheat is a plus.
FWIW I typically choose option 2 - keeping the gaming PC separate from anything important.
Furthermore, it's funny when people cry about how kernel anticheats are invading their privacy. These anticheats are better secured and protected than 99% of the drivers for windows, which are FULL of kernel elevation exploits. Absolutely filled to brink. I could go into it more, but this thread isn't the place.
- It might detect the sandbox and refuse to run the game
- If more seriously malicious, it might quietly escape the sandbox at first opportunity - say, a sandbox-escape exploit which the game provider obtains before the user can/does install the security patch
If it's an indie game, it won't be checking if it's in a sandbox.
History has proven this to be false. Recall the sony rootkit scandal.
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
Also, didn't zoom do something somewhat shady with admin permissions and self-updating? I'm not sure how you arrived at the conclusion that this couldn't happen today.
My claim was simple. If it's a game from a big studio, it won't have a keylogger. This is simply true and has been true for a long time. If that changes, we will hear about it.
> My claim was simple. If it's a game from a big studio, it won't have a keylogger.
Your "claim" is actually a prediction, and I would bet against it with a less-vague definition of "big" and a long enough time period. It's certainly not a fact, which is how you present it.
The problem is to follow the focus of the windows and parse out relevant information to send because logging all presses will be to obvious if you read memory or disk.
Then you need to encrypt the data before you send it over the network, this is probably why all modern anti-viruses block all native HTTP traffic.
The scary part is that the Windows API allows for a process to gather all keypresses even when the app window has lost focus?!
To answer the question: open the exe in any text editor and search for SetWindowsHookEx... if it's there you know that exe can listen to everything.
So lets say we have a software, and your account can tell you when somebody else sees your info in this piece of software?
How would this work? And what does this have to do with keylogging? Genuinely asking as I'm just trying to understand what link I'm missing
Any other way can be easily circumvented. In theory, any smart enough malware could hide itself in presence of any kind of analysis tools.
The first alert was from Twitter. I am an H1B from India employed by a WITCH type Indian company working for an US client (probably top 3 in the world in what they do). One day, I saw some Twitter posts about how greencards for Indians would take decades or even 100 years. I was talking about this to a colleague on client's Microsoft Teams. Just as I mentioned this, teams got disconnected. Later that day, was talking to another colleague through same teams about same topic, again got disconnected. I thought it was odd, but dismissed. Then around 9 pm same day, I get an alert from Twitter that they prevented a suspicious login from an IP address in US.
4 weeks ago, I was talking about how my WITCH company manager is not letting anyone take vacation (from Sep-Dec, they are not letting any one take vacation unless absolutely necessary) to another colleague, through client's teams. 3 days later, I get an alert from Facebook that someone accessed by account, this time from Turkey.
Then 1 week later, got an email from Google with a security code that someone had requested for accessing the same Google account.
Don't know if I should just pack up and leave US at this point, lol!
Second, Twitter, Facebook and Google all provide enhanced account security options like Passkeys and MFA and it's clear you're not using them. Turn them on (and using your personal devices, not your work provided items) and your employer or any other random hacker is going to have a substantially harder time accessing your accounts.
I'm not a lawyer but I don't think they have legal grounds to access an employee's personal accounts even if they have captured the credentials over their property. Accessing a third-party computer without authorization (i.e. accessing Facebook using someone else's credentials without permission and just discovered on company networks and/or hardware through normal logging and monitor) is likely a violation of the Computer Fraud and Abuse Act in the US. A company has rights to read any and all data stored on their property but conditions have to be met before they could use that information for any purpose (i.e. a judge orders it because a lawsuit is in progress because you're sending company secrets through personal accounts or something).
Might an external attacker be interested in the work you're doing for the client? For example, are you working with cryptocurrency? Countries like North Korea like to steal that stuff for sanctions busting.
If I were you I would bring this up with your boss. If that conversation leads you to believe that your employer is trying to hack you, I would probably quit. Otherwise your employer should know; this could be a good time to invest in countermeasures against an external attacker.
[1] https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
https://joyofsource.com/the-full-source-bootstrap-building-f...
And will gradually become a non issue as distros incorporate it (or more likely: reproducible binaries generated from it) in their bootstrap.
if the program only doing it when requested by a remote source or some other more complex logic it's gonna be harder, you'll maybe need to reverse their communication protocol and inject network messages sent to the client to make it look like the server asked for that info. but if you reverse engineered the network protocol you don't need to listen to begin with.
so keep listen to the traffic for an extended period of time and look for suspicious activity.
A plausible way would be to determine which processes are becoming active when input events occur, if the unfocused game is one of them (good luck actually determining this!) then you can at least say it's possible, but not even then, if anything actually happens to the intercepted data or if it's just bad implementation.
almost all game have bots and bot developers go through this step, so you can save some time if you find the right forums/communities for your game where they share this kind of info among each other.
this simple inspection can at least help you weed out simpler attempts. but can't guarantee that the game is clean.
as sibling comments pointed out, these days with anti-cheat mechanism being so intrusive that they have kernel level access to your computer with some even having the kernel driver running even when the game is not running. I think that was the case for genshin impact and valorant. genshin's anti-cheat apparently was even hacked to be used by ransomware at some point in the past.
games with kernel access can do so much more than just being a keylogger, they can own your computer, listen to the traffic on you network.
it's best to treat all of them as compromised super-viruses you willingly decided to install on your computer. buy a separate computer that act as a console, isolated from the rest of your network and do nothing but gaming in it. or just don't play them.
Detectors like this detect the most common ways of implementing key logging, but there may be other ways that they don’t detect.
But how do you know if there is one installed?
Hooks are chained, so you can traverse the chain and enumerate them. This thread in Stack Overflow is about that. I haven't tried the solution, but seems legit :)
https://stackoverflow.com/questions/8564987/list-of-installe...
In a way, unless you can prove the machine code running on your CPU is not doing key logging (which is separate from recoding those logs or transmitting those logs), and you can also prove that the code is not changing, you have no evidence that there is no keylogger.
As for games and keyboards in general: games need to read your keyboard to function, so they will always be able to read what you're typing. In some operating system, that includes times where you might be running the game in the background.
I guess I’m being the change I wish to see..
But even if a game intercepts all key stroke, it may be because of normal gameplay.
If you're producing something of perceived value, then you need to consider who might be interested in and what means or length they'll go through to get it. This practice is known as threat modeling and is the only meaningful way to get "security" without wasting resources.
When you threat model often, you come to realize almost all attackers are financially motivated and bound by market constraints, which means they're looking for the highest reward for the least amount of work; very few are looking to do anything else with your data other than to use it for quick monetary gain.
So? Let them eat cake. Leave a small amount of canary crypto-currency unprotected in your home directory. Set up a public ledger alert and if that currency is transfered, you know you've been compromised, by a keylogger or something else. It's very unlikely your keystrokes are worth any more than this.
This is tangential, but for all the flack Wayland gets compared to X11, it does at least provide some reassurance that a program can only easily keylog the stuff you enter into that program.
Many commercial antivirus have generic keylogger detection - they monitor OS keylogger APIs/drivers.
I will defer to the rest of the comments for software as it is already being covered.
there are a few games out there that have this reputation-- third-party-ran nostalgic MMO private servers are a big example. the only defense that makes much sense is to virtualize that software and keep it away from sensitive data.
If its in the data, then you know.
A virus checker. That would be at your level.
As others mention you could intercept network traffic and inspect it if you want to push yourself.
There are other things, it might be stored, so you could watch files and the rate they grow in size.
you must be VERY careful you havem't put the word(s) or links into anything that syncs or ends up someplace not e2e
this is harder if you don't have access to google search data, but i've been told google trends is your friend
i've caught some weird people this way.