Host Hunters

Webmaster => Safety and Security => Topic started by: spidy on December 11, 2017, 07:09:30 AM

Title: HP laptops found to have hidden keylogger.
Post by: spidy on December 11, 2017, 07:09:30 AM
http://www.bbc.com/news/technology-42309371

HP laptops found to have hidden keylogger

Image copyright HP
Image caption Hundreds of HP laptop models were affected
Hidden software that can record every letter typed on a computer keyboard has been discovered pre-installed on hundreds of HP laptop models.

Security researcher Michael Myng (https://zwclose.github.io/HP-keylogger/) found the keylogging code in software drivers preinstalled on HP laptops to make the keyboard work.

HP said more than 460 models of laptop were affected by the "potential security vulnerability".

It has issued a software patch for its customers to remove the keylogger.

The issue affects laptops in the EliteBook, ProBook, Pavilion and Envy ranges, among others. HP has issued a full list (https://support.hp.com/us-en/document/c05827409) of affected devices, dating back to 2012.

'Loss of confidentiality'
Mr Myng discovered the keylogger while inspecting Synaptics Touchpad software, to figure out how to control the keyboard backlight on an HP laptop.

He said the keylogger was disabled by default, but an attacker with access to the computer could have enabled it to record what a user was typing.

According to HP, it was originally built into the Synaptics software to help debug errors.

It acknowledged that could lead to "loss of confidentiality" but it said neither Synaptics nor HP had access to customer data as a result of the flaw.

In May, a similar keylogger was discovered (http://www.zdnet.com/article/keylogger-found-on-several-hp-laptops/) in the audio drivers pre-installed on several HP laptop models.

At the time, the company said the keylogger code had been mistakenly added to the software.
Title: HP laptops found to have hidden keylogger.
Post by: SenseiSteve on December 11, 2017, 01:28:06 PM
Wow, that's awful. Thanks for the heads up. I run my laptops with Malwarebytes daily to be proactive about protection.