Wireless keyboards easily cracked


We first covered breaking the commodity 27MHz radios used in wireless keyboards, mice, and presenters when [Luis Miras] gave a talk at Black Hat. Since then, the people at Dreamlab have managed to crack the encryption on Microsoft's Wireless Optical Desktop 1000 and 2000 products (and possibly more). Analyzing the protocol they found out that meta keys like shift and ALT are transmitted in cleartext. The "encryption" used on each regular keystroke involves XORing the key against a random one byte value determined during the initial sync with the receiver. So, if you sniff the handshake, you can decrypt the keystrokes. You really don't have to though; there are only 256 possible encryption keys. Using a dictionary file you can check all possible keys and determine the correct one after only receiving 20-50 keystrokes. Their demo video shows them sniffing keystrokes from three different keyboards at the same time. Someone could potentially build a wireless keylogger that picks up every keystrokes from every keyboard in an office. You can read more about the attack in the whitepaper(pdf).

[via Midnight Research Labs]

Recent Posts

Reader Comments

(Page 1)
Next 20 Comments

hack a day serves up a fresh hack each day, every day from around the web and a special how-to hack each week.

send us your hacks

have a hack you'd like to see here? tell us about it

Hacks
aibo hacks (1)
cellphones hacks (43)
cons (30)
contests (18)
daily (3)
digital cameras hacks (48)
downloads hacks (8)
gameboy hacks (28)
google hacks (5)
gps hacks (28)
HackIt (13)
handhelds hacks (50)
home entertainment hacks (107)
home hacks (9)
how-to (9)
ipod hacks (73)
laptops hacks (37)
laser hacks (27)
macs hacks (35)
misc hacks (603)
news (12)
pcs hacks (126)
peripherals hacks (129)
playstation hacks (44)
podcasts (8)
portable audio hacks (41)
portable video hacks (24)
robots hacks (71)
tablet pcs hacks (3)
tivo hacks (6)
tool-hacks (4)
transportation hacks (66)
wii hacks (12)
wireless hacks (74)
xbox hacks (45)

resources

rss newsfeeds

Powered by Blogsmith