On The Insider: Judge Bans Real Housewives Sex Tape
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner , ZDNet (UK)
Posted on ZDNet News: Dec 5, 2007 1:22:00 PM

The protocol for securing some of Microsoft's wireless keyboards has been cracked, opening up the possibility of keystroke logging, according to Swiss security company Dreamlab Technologies.

Researchers from the company have said they are also close to being able to use the hack to control affected computers remotely.

Microsoft's Wireless Optical Desktop 1000 and 2000 keyboards communicate by transmitting radio signals to the sound card in a user's computer. The data stream is encrypted using an exclusion-or (XOR) cipher, which is not strong enough to secure the communication, according to Dreamlab's senior security specialist, Max Moser.

"This is nothing like a crypto-algorithm," Moser told ZDNet UK, a CNET News.com sister site. "An exclusion-or binary is really a simple mathematical idea. You can crack the cipher by hand. You take two values, write both lines and look at the different digits. When either the top or the lower line is 1, you write 1. If both are 0, you write 0. For me, this is just obfuscation (rather than encryption)."

Microsoft's Mark Miller, said the company was investigating Dreamlab's claims. He said Microsoft was unaware of any attacks exploiting the claimed vulnerability or any customer impact.

"We will take steps to determine how customers can protect themselves should we confirm the vulnerability," Miller added.

Dreamlab started its cracking efforts six months ago. It first identified the radio frequency used by the keyboards. The company then used a piece of copper wire to intercept the signal, which is effective to a range of 10 meters, including through walls and floors. However, because the radio frequency is in the citizens' band--that is, it is used by CB radios--Moser said it would be possible to obtain radio equipment that could intercept the transmissions from up to 50 meters away. "Range is not a problem," said the security specialist.

But Moser said that, though he could log keystrokes, he hadn't yet been able to take control of a compromised computer remotely, because there were still some parts of the keyboards' protocol that were unknown to him. Because the protocol is proprietary to Microsoft, meaning the researchers do not have access to the source code, they decided to analyze the data on a binary level, rather than use reverse engineering.

"The real challenge was to understand the keyboard protocol," said Moser. "With 40 bytes per keystroke, it's difficult to understand which (byte) holds the data. From the binary stream, we built the data into meaningful sets and groups."

Moser then wrote a software tool that automatically sifted the data. Moser said he has not publicly released the tool because he does not want it to fall into the wrong hands. He added that he has informed Microsoft of his findings.

Each keyboard transmits its own identifier, so, if two or more keyboards are working in close proximity, the signals don't interfere with each other. While this means users are unlikely to find themselves typing on a neighbor's computer, it also allows intercepted signals to be hacked because each unique identifier can be used as a key.

It takes between 30 and 50 intercepted keystrokes to break the protocol. As exclusion-or is used as a cipher mechanism, even if the user changes the key by reconnecting the keyboard, it is easy to crack the code, said Moser.

Moser said that, to mitigate this possible attack vector, companies could invest in wired or Bluetooth keyboards.

Tom Espiner of ZDNet UK reported from London.

©2007 CNET Networks, Inc. All rights reserved. CNET , CNET.com , and the CNET logo are registered trademarks of CNET Networks, Inc. Used by permission.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 9 Talkback(s)
Sound Card?
Since when do wireless keyboards transmit data through the computer's sound card? All the ones I have used required a USB attached dongle or Bluetooth...... (Read the rest)
Posted by: Too_Busy_To_Be_Here Posted on: 12/07/07 You are currently: a Guest | | Terms of Use
XOR?  John Musbach | 12/05/07
RE: Researchers hack Microsoft wireless keyboards  crackle0 | 12/06/07
Wow, showing that humans can crack other human's creations  Boot_Agnostic | 12/06/07
It shouldn't be any surprise!  dcpacker | 12/06/07
RE: Researchers hack Microsoft wireless keyboards  AtlantaTerry | 12/06/07
FUD against Microsoft  qmlscycrajg | 12/06/07
RE: Researchers hack Microsoft wireless keyboards  taskman | 12/06/07
Academics really are amateur crackers!!  robert_mt_walker@... | 12/06/07
Sound Card?  Too_Busy_To_Be_Here | 12/07/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Introducing SmartPlanet

  • Find thought-provoking progressive ideas on topics that intersect with technology, business and life. Visit Today
  • Technology, perspective, and insights shaping the world
  • Learn innovative and practical skills for your business and your life. SmartPlanet offers 360 degree coverage that you need to feel connected to the information that matters to the world at large. Go to SmartPlanet
advertisement
Click Here