Newsletter Archives

  • Remember the HP Synaptics keylogger that was pulled last week? HP says it wasn’t a keylogger

    You can make up your own mind, of course, but last week I posted a reference to Catalin Cimpanu’s report of a massive replacement of HP Synaptics drivers.

    HP now says:

    Synaptics is aware of articles that were published where it was purported that there was a “keylogger” in our touchpad drivers. This is inaccurate. Our debug tool was mischaracterized in the articles as “keylogger”…

    Using a standardized risk scoring system, the Common Vulnerability Scoring System (CVSS), this debug tool scores approximately 2 out of 10, and is classified as a low risk. In today’s heightened sensitivity to security and privacy, Synaptics will take the precautionary steps of defeaturing the debug tool for production drivers to further prevent the tool from being used in an unintended and malicious way.

    I’m of the opinion (in my usual snarky way) that anything that walks like a duck and quacks like a duck certainly has ducklike qualities.