{"id":141,"date":"2015-01-18T08:10:28","date_gmt":"2015-01-18T08:10:28","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=141"},"modified":"2020-12-08T23:51:17","modified_gmt":"2020-12-08T22:51:17","slug":"this-weeks-keysweeper-keyboard-gate","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2015\/01\/18\/this-weeks-keysweeper-keyboard-gate\/","title":{"rendered":"This weeks KeySweeper &ldquo;keyboard&rdquo; gate"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">Today I like to reflect a news, that has been widely spread through websites: A guy has created an aduino based sniffer for microsoft wireless keyboard that can log keystrokes. The solution was called KeySweeper. Here a few words about the situation, after the \"dust has settled\". <\/p>\n<p><!--more--><\/p>\n<h3>The message, that has spread this week<\/h3>\n<p>Wireless keyboards transmits keystrokes to a receiver \u2013 and this signals may be logged via a second RF receiver. A guy created an aduino based sniffer, to log keystrokes from Microsoft's wireless keyboards. Details are documented <a href=\"http:\/\/samy.pl\/keysweeper\/\">within this blog article&nbsp; and<\/a> <a href=\"https:\/\/twitter.com\/samykamkar\">@SamyKamkar<\/a> has postet <a href=\"https:\/\/twitter.com\/samykamkar\/status\/554684533769912321\">this tweet<\/a>. <\/p>\n<p><img decoding=\"async\" alt=\"\" src=\"https:\/\/i.imgur.com\/kx2Wje6.jpg\"><br \/>(KeySweeper, Source: <a href=\"http:\/\/samy.pl\/keysweeper\/\">samy.pl<\/a>) <\/p>\n<p>To sum it up, the message was: A small device, looks like an USB charger, can be used to sniff wireless keyboards from Microsoft, because they use a non-encrypted transmission.<\/p>\n<h3>\u2026 but the truth is?<\/h3>\n<p>After the \"words has been spread over the web\", Microsoft has posted a statement, published by <a href=\"http:\/\/arstechnica.com\/security\/2015\/01\/meet-keysweeper-the-10-usb-charger-that-steals-ms-keyboard-strokes\/\" target=\"_blank\" rel=\"noopener noreferrer\">arstechnica.com here<\/a>: <\/p>\n<blockquote>\n<p>Keyboards from multiple manufacturers are affected by this device. Where Microsoft keyboards are concerned, customers using our Bluetooth-enabled keyboards are protected from this type of attack. In addition, users of our 2.4GHz wireless keyboard designs from July 2011 onwards are also protected because these keyboards use Advance Encryption Standard (AES) technology.<\/p>\n<\/blockquote>\n<p>In brief: Yes, there has been a vulnerability to snipp un-ecoded keyboard data. But this is not restricted to Microsoft products. But the main topic: wireless keyboards from Microsoft, produced after July 2011, are using AES encryption. So KeySweeper is useless and won't work (a fact, that hasn't mentioned in many articles). And other vendors does the same. <a href=\"https:\/\/web.archive.org\/web\/20190925123312\/https:\/\/www.logitech.com\/images\/pdf\/roem\/Logitech_Adv_24_Ghz_Whitepaper_BPG2009.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">This Logitech document<\/a> from 2009 talks about wireless keyboard encryption too. <a href=\"http:\/\/blog.rot13.org\/2012\/12\/is-wireless-keyboard-safe-for-your-passwords.html\" target=\"_blank\" rel=\"noopener noreferrer\">Here is another interesting article<\/a> about that topic.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I like to reflect a news, that has been widely spread through websites: A guy has created an aduino based sniffer for microsoft wireless keyboard that can log keystrokes. The solution was called KeySweeper. Here a few words about &hellip; <a href=\"https:\/\/borncity.com\/win\/2015\/01\/18\/this-weeks-keysweeper-keyboard-gate\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1319],"tags":[70,69],"class_list":["post-141","post","type-post","status-publish","format-standard","hentry","category-general","tag-keysweeper","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/141","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=141"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/141\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=141"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=141"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=141"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}