Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just to avoid any misunderstandings, from the article: "There's no indication the driver package uploads or otherwise distributes any of the logged information."

The software writes all key presses to a debug logfile on your own machine (which is overwritten on each reboot), it doesn't send them anywhere. This is bad enough, especially given that the file apparently is readable by any user on that machine. But it's not really a malicious spying tool, it's "only" really sloppy programming.



>"There's no indication the driver package uploads or otherwise distributes any of the logged information."

i remember how PM team (not just a team of typical poor technically clueless PMs, mind you, it was the "product management" team including actual PMs, project leads, lead architects, managers, etc.) waived security bug because it was only starting "notepad.exe" and thus was really harmless. Not joking, true story.


we will probably find the uploader on some sloppy coding for some unrelated piece such as intel management engine firmware. or some crash reporter that sends all debug files in some dir, etc.

deniability all the way, baby.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: