Amex sends USB trojan keyboards in ads
catless.ncl.ac.uk
catless.ncl.ac.uk
A barcode scanner, for instance, can be designed so that it just sends the digits contained in the code when you scan, and thus magically work in applications that just have regular text entry boxes in their UI.
The Yubikey (http://www.yubico.com/products/yubikey/) is another example, where a security-conscious company have chosen the keyboard HID method of delivering encryption keys to host computers.
You forgot the part about its fake USB DEV/PROD ID (masquerading as an Apple keyboard) and the part about trying to send local data to some "masked" URL.
The power line has already been used, but not in the incoming direction.
It was successfully used many years ago to smuggle information out of a highly secured place by modulating the power usage of a drive array, this was enough to allow a sensor coil placed around one of the wires powering the installation to pick up the bits.
Slow as hell, and probably quite noisy but it did work.
I wished I could dig up a citation for it, it was quite an impressive hack, and they never did figure out who did it.
It mentions this idea of modulating power usage, and a few other clever ones, though I didn't see a reference to it being used in the past.
I'm sure it's been done plenty of times though, not just recently. The nasty thing about it is that such a leak can be in place for a long time before it is discovered.
here is a wikipedia article about it:
http://en.wikipedia.org/wiki/Power_analysis
Which states that it was introduced in '98, but I'm quite sure of when I heard about it because I remember who told me (a systems programmer for a bank that I worked for in those years).
http://www.defcon.org/images/defcon-17/dc-17-presentations/d...
EDIT: sorry, that PDF is less informative than the talk was. He had a bunch of demonstration material that's not included here, apparently.
We got the idea from the same hack you mention; though as with yourself my boss cant recall any other details apart from remembering it sounded really cool at the time :D
A CD most certainly can pretend to be a keyboard, though. Autoplay is arbitrary code execution, and arbitrary code execution can do anything.
"Hello. I'm a keyboard."
"User pressed Logo + R."
"User typed 'http://example.com/trojan.exe.
"User hit enter."