Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
HP Privacy Security IT

HP Issues Fix For Keylogger Found On Several Laptop Models (zdnet.com) 72

HP says it has a fix for a flaw that caused a number of its PC models to keep a log of each keystroke a customer was entering. The issue, caused by problematic code in an audio driver, affected PC models from 2015 and 2016. From a report: HP has since rolled out patches to remove the keylogger, which will also delete the log file containing the keystrokes. A spokesperson for HP said in a brief statement: "HP is committed to the security and privacy of its customers and we are aware of the keylogger issue on select HP PCs. HP has no access to customer data as a result of this issue." HP vice-president Mike Nash said on a call after-hours on Thursday that a fix is available on Windows Update and HP.com for newer 2016 and later affected models, with 2015 models receiving patches Friday. He added that the keylogger-type feature was mistakenly added to the driver's production code and was never meant to be rolled out to end-user devices. Nash didn't how many models or customers were affected, but did confirm that some consumer laptops were affected. He also confirmed that a handful of consumer models that come with Conexant drivers are affected.
This discussion has been archived. No new comments can be posted.

HP Issues Fix For Keylogger Found On Several Laptop Models

Comments Filter:
  • by thegreatbob ( 693104 ) on Friday May 12, 2017 @09:03AM (#54405367) Journal
    A fix is all well and good, but an explanation would be a nice touch. I guess people just don't get pissed off about getting the shaft anymore.
    • Re:Fine. (Score:5, Informative)

      by Megane ( 129182 ) on Friday May 12, 2017 @09:12AM (#54405419)

      From what I saw yesterday, the "explanation" is:

      1: mediocre programmer guy wants to check the keystrokes that affect volume control, adds a keylogger to the code for debugging
      2: poor version control, or a total lack thereof, combined with lack of code review, allows "temporary" debugging keylogger code to become part of and remain enabled in main-line production code
      3: someone eventually discovers it and SHTF

      In other words, Hanlon's Razor. [wikipedia.org]

      • Re:Fine. (Score:4, Insightful)

        by anegg ( 1390659 ) on Friday May 12, 2017 @09:41AM (#54405625)
        Words fail me. Whether this was incompetence or a poorly-kept secret, the implications are troublesome. A clear demonstration that even mainstream commercial software can't be trusted in some pretty fundamental ways. Yet we conduct more and more of our personal and professional lives on and through software-controlled systems. The explanation is that it was done accidentally, which implies that it is relatively easy to do and will not be detected by whatever quality assurance processes are in place.
        • Re:Fine. (Score:5, Insightful)

          by 110010001000 ( 697113 ) on Friday May 12, 2017 @10:05AM (#54405755) Homepage Journal
          I'm pretty sure that RMS has been saying this for years. You cannot trust any closed source. You have no idea what is doing. You are trusting unknown people with your data.
          • Not at all. RMS's comments concern a small subset of the issues that cause problems like this. I can't trust closed source, that's a given. Recent history has shown we can't trust open source either.

            Pretty much everyone lacks the means to audit binary releases. In the population of computer users pretty much everyone lacks the technical knowhow and time to audit code even if they had the means to audit the binaries they use.

            A perversion of Linus's law: Many eyes gloss over bugs equally.

          • by Ramze ( 640788 )

            The older I get, and the more crap like this that comes up, the closer I get to agreeing with RMS... especially with the windows 10 shenanigans. I've already got a tweaked Ubuntu Linux PC w/ Cinnamon DE that I'm getting accustomed to using for everything but games (Win10 for that, for now)... still... Until gnome/kde/cinnamon all have wayland and vulkan working properly, I'm not going to use Linux as my main machine.

            One thing to remember, though is even open source software can be nefarious... and even gr

        • by BK425 ( 461939 )

          Absolutely, and we have to stop reacting with words like "fix" "flaw" and "problematic". This was a serious privacy intrusion on a massive scale. Whether it was some guy up to late on a bad schedule set by his boss Dilbert really doesn't matter. HP published the stuff, Connexant wrote it, they should pay some kind of price.

        • A clear demonstration that even mainstream commercial software can't be trusted in some pretty fundamental ways.

          You can skip the "mainstream and commercial" part. Software is created by people, people in general make all sorts of stupid mistakes. Software in general can't be trusted.

          That's not new. It was the case many years ago when we irradiated and killed people with race conditions. It will forever be the case going forward. It will be a problem in large OSes, and it'll be a problem in small apps and drivers.

          • by anegg ( 1390659 )

            I'm not disagreeing with you. This case seems particularly egregious from a "flaw" standpoint, however. An accident of programming with a race condition in a critical system that ends up killing people is horrible, but that's a high risk environment for software and the outcome is a lot more screening of software in critical applications (that increases the cost of those applications).

            This was a complex and apparently functional behavior that could be compromising data that was "accidentally" built in a

        • Technically it wasn't done accidentally. It was done deliberately because the programmer was being lazy. The way you're supposed to do it is via

          #ifdef DEBUG
          insert debug code here
          #endif


          Then you can enable/disable all the debug code with a single #define DEBUG statement. But people being lazy, they stick the debug code straight in thinking they'll just remember to comment it out before they ship the end product. Except they forget. QA can't catch this form of laziness because short of reading a
      • In other words, Hanlon's Razor. [wikipedia.org]

        Hanlon's Razor doesn't explain the employees who worked at Mozilla, Cisco, RSA, etc. and weakened products for nation-state interests.

    • by Thud457 ( 234763 )

      HP Issues Fix For Keylogger Found On Several Laptop Models

      More like "HP Issues Fix For Keylogger SECRETLY INSTALLED On Several Laptop Models"

  • I only buy Windows 7 machines for myself and my company, but the first thing I do when I buy them (new or refurbished) is format the drive, install Windows 7, and use the Windows drivers whenever available.
    • Re: (Score:3, Informative)

      by Anonymous Coward

      The driver containing the keylogger was distributed by Windows Update.. Unless you deactivated driver loading from Windows update, your wiped laptop is also affected.

      • Why the fuck would Microsoft be distributing HP's software? I very much doubt it came via Windows Update, but I don't mind being corrected, please send links to anything which states it was via Windows Update.
        • Because it's a service that is offered in an attempt to keep machines with custom hardware up to date.
          • Well I did mention links with some kind of proof - just saying "because" is not proof.
            So I googled that for you...
            https://support.hp.com/us-en/d... [hp.com]
            And if it's the TLDR thing then here is the relevant bit

            Many, including Hewlett-Packard, use the Windows Update tool to distribute their updates.

            • by Khyber ( 864651 )

              "Well I did mention links with some kind of proof"

              Everyone and their fucking mother knows big-brand hardware manufacturers have distributed vendor-specific driver patches through Windows Update since Windows 98 - almost 20 fucking years ago.

              And then you went ahead and looked it up yourself after demanding proof - which you should have done in the first place instead of looking like a child wanting a handout. We're in the age where the summation of mankind's knowledge is almost constantly at our fingertips.

            • Yeah, I know it's true because some of the companies I've done work for use it and I had to look into how it would work, and no, I'm not doing your research for you. Have a good one.
        • by omibus ( 116064 )

          Because it is a driver, and Microsoft writes as few of those as it can.

        • by SeaFox ( 739806 )

          Why the fuck would Microsoft be distributing HP's software?

          Because Joe Sixpack finds himself having to reinstall Windows fairly often to fix issues, and many computers today don't come with proper install discs, or generic ones that don't automate the installation of drivers for the hardware specific to the model of computer. So you end up with "drivers and utilities" CDs that don't make it clear which of their many drivers you need, or you have to go to the manufacturer's site to get the drivers you need -- a process beyond the technical abilities of a large porti

    • I do the same, ESPECIALLY laptops, I don't need a hidden "recovery" partition sucking up space. Although I generally try get the latest drivers from the manufacturer - preferably BEFORE formatting, although that is sometimes not possible. I remember once having to go buy a memory stick and go to an internet cafe to get network drivers (many moons ago) so that I could get my NIC up and running - the stock Windows drivers did not recognize it.
    • by ledow ( 319597 )

      Same, but Windows 8/8.1

      I have precisely three drivers listed in my WDS driver packages.

      One is for an IBM BladeCenter SAS RAID controller that blue-screens with the default Windows one (so all the blades have to start using that driver from the very first boot or they will blue-screen, even if you push updates later).

      Two for gigabit-network cards that aren't covered by plain Windows install disk / WDS installs (purely to kick-start them being able to get out to Windows Update and download a better driver and

  • by Anonymous Coward

    A fully functioning keylogger is a flaw?

  • Is it just me, or is this patch that difficult to find? I know google is my friend, but this is just sad.

  • Sorry, but one of our programmers leaned on his keyboard while eating lunch and wouldn't you know, it caused the driver he was working on to start logging keystrokes and storing them into a file.
  • You mean a fix as in it is no longer detected?
  • ... MP3 rip you!

  • That's great news! now, who's going to jail over this? Nobody? That's fucked up!

Keep up the good work! But please don't ask me to help.

Working...