Hi My Name is Keyboard

No ratings

Presented at Shmoocon 2024 by

Seven years after MouseJack, Marc set out to hack some more peripherals. Gaming-keyboards looked fun but were hilariously bad, so he looked to Apple’s Magic Keyboard for a challenge. One question lead to another, and he was soon reporting unauthenticated Bluetooth keystroke-injection vulnerabilities in macOS, iOS, Android, Linux and Windows, along with link-key-extraction vulnerabilities in popular computers and peripherals. This is a story of trusting your instinct, following the research, and ignoring the part of your brain that says “there is no possible way this will work.” We’ll look at the progression of research and decisions that were made, the vulnerabilities themselves, and the realities of a complex, multi-vendor disclosure. We’ll conclude with tools, demos, and some reflection on what we can learn from this dumpster-fire.