Hacker News new | ask | show | jobs
by VenTatsu 1754 days ago
The cable claims that it's a random 3rd party keyboard when it talks to the Mac, the cable claims it's a random non Apple device when it talks to the keyboard, the keyboard falls back to non-encrypted mode as it's not on a product that supports it.

Man in the middle is hard to prevent when you need to be compatible with incredibly broken insecure legacy protocols.

Apple could maybe go the route that all new Apple keyboards only work with new Macs and iOS devices, but that would mean that they can't work with any existing Apple hardware or third party systems.

2 comments

I guess the MITM attack could be mitigated in the OS by showing an "encrypted keyboard connection" UI indicator of sorts. Assuming the MITM hardware doesn't exploit a vulnerability in the OS to incorrectly show that indicator. ;)
And does Apple care? Unlikely… Preventing MITM cable hacks is not a common use case.