Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Actually, the purpose of the software is to recognize whether a special key has been pressed or released.

I'm doubtful of the utility of software like this. Every driver and application seems to want to keep a persistent background process running, and because of the natural inefficiency of software (this executable is ~2MB --- why it needs to be this big, I'm not certain; from a brief inspection, all it seems to be doing is controlling microphone mute/unmute), results in a huge waste of resources and new computers which appear no more responsive and than older ones.

However, to put the severity of this problem in perspective, from the description this is not like a typical keylogger that sends keystrokes out to some remote server; it only logs locally.

If you regularly make incremental backups of your hard-drive - whether in the cloud or on an external hard-drive – a history of all keystrokes of the last few years could probably be found in your backups.

There's going to be plenty of other sensitive information in your backups, which if you don't want others to read you would use encryption anyway, in which case the point is rather moot.

Any process that is running in the current user-session and therefore able to monitor debug messages, can capture keystrokes made by the user.

...or it could just monitor the keystrokes itself with SetWindowsHookEx() like this process.

Thus, I think the correct reaction to this is more towards the "oops... that wasn't a good idea" than "everybody panic!"



> There's going to be plenty of other sensitive information in your backups, which if you don't want others to read you would use encryption anyway, in which case the point is rather moot.

This is a bit of a strawman. When you're backing things up, you know what you're backing up and chose to do so. Here you'd be backing up things that you didn't want to, or even worse, things you'd never want to be backed up anyway. If someone gets into my backups, maybe they can see some family photos or financial data...but they wouldn't otherwise be able to see all the porn searches I do in incognito mode. With this, they could potentially access that as well.


I think Windows actually has a built in "Backup Computer" feature, which AFAIK is a complete image backup. Alot of the cloud backup products do entire computer too (like Time Machine does for OSX). The convenience factor of a system backup for a non-technical user (someone who struggles with explorer.exe) is pretty great.

That being said, keylogging is just plain horrible and inexcusable. Passwords, searches, private messages, etc. There's no way we should be cutting them slack on this.

The worst part is, it's crapware like this that steers us towards the walled app store model for PCs... and the loss of freedom that accompanies that.

Every time I hear of stuff like this I gain more respect for Stallman.


> Thus, I think the correct reaction to this is more towards the "oops... that wasn't a good idea" than "everybody panic!"

"Oop..."? - Is that what you'd write on the graves of dissidents whose efforts to communicate securely were subverted by a keylogger in an audio driver?

Too much over the top? The HN-compatible version: Actual reverse engineering can be punished by law in most of the first world (through the illegal status of tools that can be used to circumvent access restrictions). Of course, this is close to impossible to prove when all you publish is the security advisory and thus nobody really cares. "Oops..." someone accidentally just made a recording & backup of all the evidence against you :)

There is no "correct" reaction, only individually justified reactions and if you can afford to just say "oops..." you may consider yourself lucky.


"Oop..."? - Is that what you'd write on the graves of dissidents whose efforts to communicate securely were subverted by a keylogger in an audio driver?

A smart dissident wouldn't be using a Windows laptop to write things that could get themselves killed.

It's not a diss on Windows, but rather basic opsec: if you want to be secure, you need to know what every part of your system is doing. Or at least rely on the fact that open source maintainers have examined every part of the system.

One basic protection is to boot into Tails, where an audio driver like this won't have an effect.


Under authoritarianism, one's status as a dissident exists entirely at the whims of the regime. If you're recommending everyone use Tails after the pattern of someone like Stallman, I get your point. Otherwise, you're putting some absurd standard on people who might be otherwise be incredibly courageous but lack technical understanding to a degree that seems like victim-blaming.


It's an observation that if you're using a stock Windows installation to post inflammatory remarks about the regime you live under, you're gonna have a bad time. An audio driver logging your keystrokes is 0.1% of your concern at best.

Of course dissidents are courageous and deserve sympathy. That's not quite the point, though.


Yes, the victims should have known.

I strongly suspect (and hope) that you are just trolling, so in a very short form:

* "It's an observation" that you eat babies. This statement is just as valid as yours. I mean, "it's an observation" (tm). Read: Well, duh, yeah, whatever you say. Come back when you have a point.

* "posting inflammatory remarks" is not activism. Activists have no time for this BS, they do actual political work.

* Spend a few weeks in a developing country before you give advice to people who live there. Here in my house I can get you an apartment for $200/mo (2 bedrooms, hot water, gas, electricity and "internet" inclusive). But be aware: Best phone you can purchase in a 3h-radius runs Android 4; next place to buy a laptop that halfway works as expected with a vanilla linux distro: 6 to 10h driving. Modern hardware costs at least twice as much as in 1st world.

* Before talking, take over responsibility for OPSEC in a place like mine: Nobody within hours that can help someone with a problem with tails but me (well, you, since you just volunteered); next linux-expert? At least a day's travel. Still want to advise for a non win/osx-solution? I'm looking forward to hear why and how this should work.

Too much work? Well, then at least show me that at least half of your friends and family adhere to the standards you expect from unknown people who live in circumstance you obviously have no clue about. Until you do that: You're trolling.

PS: I've been teaching OPSEC to activist since 1996. I'm using Linux since 1997 and FreeBSD since 1999. I happen to know a thing or two about windows as well.


This is just an escalation attack, not one which is remotely exploitable.

You still need access to the machine in order to take advantage of this and by the time you have access to the machine you can run your own keylogger if you'd like. The only increased risk here is the ability to look back into the past.

Which is bad on its own, but let's not exaggerate. This didn't get any dissidents killed. Nor is it likely to.


What about people who encrypt sensitive information locally, then back it up? That's perfectly secure in the common case, as long as you don't accidentally store sensitive information outside of your encrypted containers. But the moment you start backing up comprehensive key logs, anyone with access to the backups can decrypt your stuff.


> There's going to be plenty of other sensitive information in your backups

I have never once backed up the login details for my online banking, or the passwords to my cloud servers, or the passwords to government websites, etc. etc.


> this executable is ~2MB --- why it needs to be this big, I'm not certain

Because writing this in 200 lines against the Win32 API resulting in a 15 kB executable would be far too straightforward. Abstraction is required.


Just wait until people start making services and software-bundled-with-drivers in electron.


Well, this used NW.js: http://www.computerworld.com/article/3018972/security/ransom...

I vaguely recall something that used Electron, but I can't find it. It was 30MB+.


Let's replace that with a tab for users to keep open !

(presses shift-esc, sees this number 91.372K standing next to the hackernews tab. Wonder what that means. Say, the number next to my gmail is like 10 times that. I wonder what that means)


Google search results frequently use 200MB+ on my machine.

It's like the Internet has collectively decided nobody has 2GB of RAM anymore. (Yep.)


Then why use gmail?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: