Hacking keystroke logger into Apple Keyboard Firmware
digitalsociety.org
digitalsociety.org
I submitted it the other day but somehow it got 0 points: http://news.ycombinator.com/item?id=737186
Or maybe people here would rather read a brief news summary than a paper? Who knows :)
If (that's a big if) this can be made practical, the fact that it depends on you already owning the machine before you use it seems to make it unattractive; if you've already got that access, there's more interesting stuff you can do.
More interesting now?
I'm just not impressed in general by hacks which begin with "first you must achieve a complete breach of the target machine's security..."
On the other hand: physical access to hardware leads to pwnage, film at 11.
It also uses a very unexpected attack vector, which means there could be some surprising effects. Remember slow-propogating floppy disk viruses? Think about the way keyboards are shuffled around offices.
It is a great hack. But as someone else already posted here: physical access to hardware ... game over.
I challenge you to find a bug in the firmware of my IBM Model M keyboard, circa 1984.
Here’s an advice, don’t make statements like “the many weaknesses in Mac OS X and Apple applications” or “Apple had a tendency to rush hardware to market” unless you can back these up.
You already made a significant exploit which no-one can dispute, don’t give “staunch Apple fans” a reason to dismiss the article.
Apple's increasing popularity seems to be attracting more hackers to target the platform. This attack combined with an iTunes Buffer Overflow attack could lead to fair amount of serious security breaches.
People love to be in the spotlight. If you can produce a story which involves Apple, you will get to be in the spotlight. It's as simple as that.
Just place a rogue receiver somewhere near.