Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

how do I validate my keyboard initially? how do I validate my mouse initially?

something would need special treatment that would be an attack surface.



You can't validate your keyboard. But you can confirm that you keyboard is a keyboard and not a storage device or network interface or whatever. And that your webcam is also not a keyboard.

It's a defense against the OMG cable which attacks you when you connect known-good items. If Logitech or Apple peripherals are counterfeited it will provide less benefit.


I think what he meant was, how do you accept the keyboard prompt if this is the initial keyboard connected to the system? Same goes for mouse. A bit of a chicken and egg problem, unless you blindly accept the first keyboard plugged into the system, which defeats the point.


Showing a PIN on the screen, to type in, helps a long way. But what if I replace the USB cable for your keyboard? (Or replace the whole keyboard, but that's more noticeable.) Most people would just re-authenticate their keyboard immediately, because this stuff sucks enough that we don't even blink when we need to redo a Bluetooth pairing because the planets changed their alignment again.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: