Popular wireless keyboards from HP, Toshiba, GE, others don't use encryption, can easily be snooped on and exploited to send malicious text to linked device
Andy Greenberg / Wired :
Context & Ripple Effects
This is the second act in the wireless-keyboard problem: back in 2015, the KeySweeper USB charger showed that some Microsoft wireless keyboards could be sniffed and decrypted for about $10 of parts, implying their radio protocol was at best weakly protected. Andy Greenberg's new reporting widens the aperture — keyboards from HP, Toshiba, GE and other mainstream brands aren't weakly encrypted, they're not encrypted at all.
The finding lands alongside a broader run of radio-link failures in everyday hardware: researchers had already pulled laptop crypto keys out of processor emissions with a sub-$300 device, and later found immobilizer flaws in Toyota, Hyundai and Kia keys. Keyboards are just the input layer of the same pattern.
First-order effects
- Anyone typing on an affected HP, Toshiba or GE wireless keyboard within radio range is exposed to both passive keystroke capture and active injection — an attacker can type malicious text into the linked device, not just read it.
- The named vendors face immediate pressure to issue firmware fixes, pull unencrypted models from shelves, or quietly discontinue them, since unlike a software bug there is no patch path for a dongle that never encrypted in the first place.
Second-order effects
- Vendors whose keyboards do encrypt the radio link gain a concrete enterprise selling point, as corporate buyers who never specified encryption on peripherals start adding it to procurement requirements after this class of demo.
- Security tooling shifts toward the desk: the same cheap-hardware playbook behind KeySweeper applies to any unencrypted keyboard protocol, making RF monitoring and dongle audits a plausible add-on to physical-security sweeps.
Third-order effects
- If the pattern holds across keyboards, locks and car keys, 'no encryption on the radio link' becomes a recognized defect category for low-cost embedded hardware rather than an exotic research result — pushing regulators and standards bodies toward baseline encryption requirements for consumer RF devices.
- Keyboard makers converge on encrypted proprietary protocols or standard authenticated links as table stakes, squeezing out the cheapest unencrypted designs and consolidating the peripheral market around vendors willing to pay for silicon with crypto built in.
The trend: Consumer devices with radio links — keyboards, locks, car fobs — keep shipping without real encryption, and each new demonstration pushes unauthenticated wireless hardware closer to being treated as a defect class rather than a design choice.