Now, if this EC chip is vulnerable, a malicious keyboard can have direct DMA access (just like FireWire controllers, EC is usually connected to the main PCI bus)... no need for drivers here.
Direct direct memory access access?
Also connecting EC directly to some PCI bus does not make much sense from both system design and cost perspectives. Usual place to connect EC to is LPC, which is explicitly designed for such devices (things on motherboard like serial/parallel/game ports, TPM, FDC, keyboard controller/EC, BIOS flash and various ). Random review of datasheets found by google seems to indicate that chips that are only embedded controllers and do not contain additional ISA based peripherals (like ISA DMA controller itself) tend to not even implement the pin required for LPC DMA/bus master transactions (as it is not required for anything in normal operation).
It's not clever, can't use DMA and generally is the dumbest thing in the entire machine.
If they somehow manage to work around it I'd eat a box of lightbulbs. It's hard enough to coerce it to work to start with.
Source: I used to design embedded PC kit from the board level.
But one question remains: how does the EC control stuff like the bluetooth radio and webcams? They're USB devices to the OS, so in theory there should be a USB hub inside the EC?
edit to add: some Intel south bridges have integrated EC which makes things a little uncertain.
In any case, a malicious keyboard can simulate keypresses and pwn your machine that way. No evil driver needed.
See other post about embedded firmware and DMA.
Indeed: https://hakshop.myshopify.com/collections/usb-rubber-ducky/p...
Connection-wise it looks like this:
http://i.imgur.com/ayFybSd.png
Keystrokes can be dangerous on their own but engineering a solution to this that assumes the correct state of the machine and can operate software is unlikely simply due to the margin of error.