Hacker News new | ask | show | jobs
by thisrod 3555 days ago
I'm a bit surprised that, in 2016, there is no standard way for a computer to authenticate its keyboard and monitor. Has anyone even thought about how that could be done?
3 comments

HDCP is arguably the standard for authenticating the monitor, but it's not quite intended for this purpose. I'm not aware of a standard for authenticating input devices, but disabling USB HID and relying solely on tamper-evident PS/2 input devices goes a long way.
Even if you can, yous implant a keylogger onto the keyboard, and some malware/implant into the screen you get a full readout of every keystroke and every pixel displayed.

If you are going to prevent physical attacks from adversaries that can circumvent basic protection (e.g. FDE) you have to make sure that every device is as secure because the system is as secure as its weakest link.

If your adversaries are just the random person that might steal your PC then any full disk encryption even a cryptographically insecure one would be sufficient because the people who end up dealing with these devices won't have the knowhow or the resources to attack even bad encryption.

yes but since an application is DRM the hacker groupthink decided that this was a double unplus good thought and so no one should think it lest evil happen.