Hacker News new | ask | show | jobs
by acqq 3115 days ago
The previous one in the audio(!) drivers was as bad as it could have been:

https://www.bleepingcomputer.com/news/security/keylogger-fou...

"writes all keystrokes to a local file at:

C:\users\public\MicTray.log"

Note: Public folder! All keystrokes. Discovered May 2017, preinstalled on 28 HP laptop models. Other hardware that uses this driver may also be affected.

Edit, to the other commenters in other threads: please don't mix them, there are two "keyloggers." The one in the audio(!) driver was always on, recording by default to the publicly accessible file, as seen here.

The one in the new news is a code in the keyboard driver that can be turned on (and here it's important to know if the switch is publicly accessible) but isn't on by default. Depending on how that one is turned on and where the result is logged, it can be not worthy to worry too much. But these details also matter.

1 comments

Unlike this one, it even looks like the audio driver exploit is on by default. Much stranger. Guess HP developers aren't very clean with their release process.