Researchers say Conexant audio driver, found on 24+ HP laptops, logs all keystrokes and stores them in an unencrypted file
Dan Goodin / Ars Technica :
Context & Ripple Effects
The finding lands in a stretch where researchers keep pulling apart what ships preinstalled on consumer PCs rather than attacking them head-on: a year earlier, popular wireless keyboards from HP and others were shown transmitting without any encryption at all, and KeySweeper had already demonstrated how cheaply keystrokes can be harvested from off-the-shelf hardware. What is different here is that the logging came from inside the machine — a Conexant audio driver bundled with the laptops themselves.
First-order effects
- Owners of more than two dozen HP laptop models have a plaintext record of everything typed sitting on their disks, readable by any malware or local user that gains file access; HP's response, covered separately as its admission the keylogging code should not have been included, is patches for 2016 models now and 2015 models days later.
Second-order effects
- Component suppliers like Conexant face scrutiny over debug and diagnostics code left active in production drivers, forcing OEMs such as HP to audit what their silicon and peripheral vendors bundle into factory images.
Third-order effects
- The episode fits a run of vendor-installed software as the softest entry point — from Dell's SupportAssist BIOSConnect remote-code flaws across 129 models to insecure kernel drivers spanning dozens of Windows vendors — pushing PC makers toward formal review and attestation of preinstalled firmware and drivers rather than treating them as trusted by default.
The trend: Preinstalled OEM and vendor-supplied software is emerging as one of the most reliable attack surfaces on consumer PCs, repeatedly turning the supply chain itself into the vulnerability.