Your Wireless Keyboard Can Give Your Secrets Away: Study

Advertisement
By Andrea Peterson, The Washington Post | Updated: 27 July 2016 16:00 IST
Every keystroke you make on some wireless keyboards can be spied on by hackers lurking nearby, according to research released by cyber-security firm Bastille Tuesday. The "vast majority" of low-cost wireless keyboards are vulnerable to an attack researchers have dubbed "KeySniffer," according to the company.

"When we purchase a wireless keyboard we reasonably expect that the manufacturer has designed and built security into the core of the product," said Marc Newlin, the Bastille researcher who discovered the vulnerability, in a press release. "Unfortunately, we tested keyboards from 12 manufacturers and were disappointed to find that eight manufacturers (two-thirds) were susceptible to the KeySniffer hack."

The attack allows hackers up to 250 feet away to eavesdrop on people as they type - potentially sucking credit card numbers, usernames, passwords and personal information shared with confidants, according to the researchers. The heart of the problem is that the connections between computers and the identified keyboards don't use encryption, unlike more costly models, and are left vulnerable to a hacker with special equipment costing less than $100.

Advertisement

The issue does not affect Bluetooth keyboards because they are subject to industry standards that require stronger security measures, according to Bastille. However, the company said some keyboards from major manufacturers, including Toshiba and HP, that rely on radio signals are vulnerable. In HP's case, Bastille found that its "HP Wireless Classic Desktop wireless keyboard" was vulnerable, while Toshiba's PA3871U-1ETB wireless keyboard was also affected. Toshiba and HP did not immediately respond to a request for comment.

Kensington, the maker of another vulnerable keyboard called the Kensington ProFit Wireless Keyboard, released a statement saying it has taken "all necessary measures to close any security gaps and ensure the privacy of users" and has released a firmware update for the device that includes encryption. You can find a full list of the affected devices here.

Advertisement

Bastille says it reached out to manufacturers before going public with its research, but that many of the devices aren't able to be updated to defend against the attacks. The cyber-security firm recommends replacing the keyboards with Bluetooth or wired models. It remains unclear if any of the keyboard makers plans to offer refunds or replacements to consumers who purchased the vulnerable models.

 2016 The Washington Post

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  2. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  3. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  4. Google AI Pro Subscribers Now Get 5TB of Storage Across Drive, Photos
  5. Apple May Skip Classic Black Finish for iPhone Pro Models for Second Year
  6. Best Mobiles Under Rs. 30,000 in India
  7. OnePlus Nord 6 First Impressions
  8. PS Plus Monthly Games for April Revealed
  1. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  2. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  3. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  4. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  5. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  6. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  7. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
  8. DoT Reportedly Extends SIM Binding Mandate Till the End of 2026
  9. Government Migrates 16.68 Lakh Official Email Accounts to Zoho Cloud, Spends Rs. 180 Crore
  10. Infinix Note 60 Pro India Launch Date Revealed; Company Teases Active Matrix Feature on Rear Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.