Moneycontrol PRO
Check Credit Score
Check Credit Score
HomeNewsTechnology

Hundreds of HP laptops were found to be recording what people type

The keylogger was accidentally identified when security researcher Michael Myng was trying to control the keyboard backlight on an HP laptop while using the Synaptics Touchpad software.

December 13, 2017 / 05:48 PM IST
Three Greenpeace activists wearing bio-hazard suits, hold old laptops and wear face masks depicting Hewlett-Packard (HP) Chief Executive Officer Mark Hurd during a protest outside the computer company's China headquarters in Beijing June 25, 2009. Greenpeace  was protesting at what they say is the company's backdown on using toxic substances in their computer products.        REUTERS/David Gray       (CHINA CONFLICT ENVIRONMENT IMAGES OF THE DAY BUSINESS) - GM1E56P0WJQ01

Three Greenpeace activists wearing bio-hazard suits, hold old laptops and wear face masks depicting Hewlett-Packard (HP) Chief Executive Officer Mark Hurd during a protest outside the computer company's China headquarters in Beijing June 25, 2009. Greenpeace was protesting at what they say is the company's backdown on using toxic substances in their computer products. REUTERS/David Gray (CHINA CONFLICT ENVIRONMENT IMAGES OF THE DAY BUSINESS) - GM1E56P0WJQ01

Hewlett Packard has released a fix for a problem in its laptops that made it possible to record everything users typed.

The privacy issue that was first discovered by a security researcher Michael Myng who identified the keylogger found that it was in laptops’ touchpad drivers.

According to HP, more than 460 laptop models have been affected by this “potential security vulnerability”.  The keylogger is believed to affect 475 models of HP laptop, including Elitebook, ProBook, ZBook, Envy and Pavilion, among others.

They keylogger is preinstalled on laptops in the HP Elitebook, HP ProBook, HP Pavilion and HP Envy ranges, among others.

The keylogger is used by the Synaptics TouchPad software, which controls the touchpad user interface, and was designed to help monitor and repair any bugs it may contain.

Keylogger is a kind of software that captures a person’s keystrokes on a keyboard or pinpad. They recognise the keys pressed and capture that information, usually with the intention of sending it on to a person wanting to harvest the details.

The American technology company has published a complete list of affected devices, dating back to 2012.

HP has also created a website that lets users check if their laptop is hacked.

HP has provided a patch for the issue for the US and has advised its customers to act upon it as soon as possible.

As per Michael Myng, the fix for the issue will also be available to download and install from Windows Update.

Although the keylogger is disabled by default, hackers can still activate the software to record the user's keystrokes- this could include passwords, personal information and banking details.

The problem was accidentally discovered when he was trying to control the keyboard backlight on an HP laptop while using the Synaptics Touchpad software.

HP acknowledged in its notes that the patch could lead to “loss of confidentiality” for the affected customers, but that neither Synaptics nor HP had access to customer data as a result.

By stirring the details of every keystroke made in unencrypted plain text files, hackers or third parties could access everything users have ever written.

In a blog post by ModZero, the firm said: “There is no evidence that this keylogger has been intentionally implemented.”

“Obviously, it is the negligence of the developers which makes the software no less harmful,” added Modzero.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

first published: Dec 13, 2017 05:44 pm

Discover the latest business news, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347