iBankCoin
Wake up. Break the cycle. Teach your children.
Joined Oct 24, 2016
1,140 Blog Posts

UPDATE: HP Issues Patch For Factory Installed Keylogger

HP has issued a patch for the recently reported keylogger installed on various laptops, after Swiss security firm Modzero reported the software last Thursday in the Conexant HD audio driver package found on dozens of HP laptop models.

The driver stored every keystroke in an unencrypted text file on the user’s hard drive, which included passwords, visited websites, and any other sensitive information – all vulnerable to malware or anyone with local access.

In a statement, the company said “HP is committed to the security and privacy of its customers and we are aware of the keylogger issue on select HP PCs. HP has no access to customer data as a result of this issue”

In an after-hours call Thursday, HP vice president Mike Nash said the keylogger was mistakenly added to the driver’s production code and was not meant to be rolled out to end users. The patch is now available on Windows Update and HP.com for affected models.

The keylogger was scheduled to start automatically upon boot, with it’s stated function to detect user input so it could react to shortcut functions such as microphone mute/unmute. The application then logged each keystroke in a text file, which was overwritten upon the next login.

Wither an innocent mistake or something more nefarious, it’s disconcerting to think that a pre-installed factory program would log keystrokes and store them in an unencrypted local file. Good thing there are security firms like Modzero who are actively hunting for such vulnerabilities…

If you enjoy the content at iBankCoin, please follow us on Twitter

2 comments

  1. The Maven

    Amazing that nobody picked it up until now!

    • 1
    • 0
    • 0 Deem this to be "Fake News"
  2. 'merica

    Not many trustworthy computer brands left. Started with Sony about 10 years ago installing rootkits on Windows via music CD’s. Then Lenovo, after turning Chinese, with spyware installed on new laptops. So I went ahead and bought an HP laptop, sigh…

    This particular incident seems intentional. I’m a developer, can’t see any reason why they would ever want to log that data even during the development phase.

    • 1
    • 0
    • 0 Deem this to be "Fake News"

Leave a Reply

Your email address will not be published. Required fields are marked *