Jump to content

MantisTek GK2's Keyboard has built-in Keylogger

goodtofufriday
Quote

Multiple online user reports claim that the MantisTek GK2 mechanical keyboard's configuration software is sending data to an Alibaba server. One of the reports even includes an analysis of the software’s traffic, which seems to include typed keys.

 

The MantisTek GK2 is a cheap RGB mechanical keyboard from China that costs half as much (or less) as the mechanical keyboards from better known companies. Multiple gadgets that come from China seem to have either poor security or privacy issues caused by collecting user data without consumers' explicit permission. The MantisTek GK2 seems to be one of those products.

 

The main issue seems to be caused by the keyboard’s “Cloud Driver,” which sends information to IP addresses tied to Alibaba servers. Alibaba sells cloud services, so the data isn’t necessarily being sent to Alibaba, the company, but to someone else using an Alibaba server.

90tYFSr.png

Ya672cP.jpg

 

Source Article: http://www.tomshardware.com/news/mantistek-gk2-collects-typed-keys,35850.html

 

While the source article recommends steps to stop the keylogger, I believe you should just throw the thing away. Don't continue to use a product that uses such practices. I can't even comment that this is hard to believe as if you ever think you are saving money, well you are wrong. That monetary savings to you comes at a cost from somewhere else. In this case your private data. 

Be careful with no name brand devices, especially from china. Plain and simple.

CPU: Amd 7800X3D | GPU: AMD 7900XTX

Link to comment
Share on other sites

Link to post
Share on other sites

Why would anyone install a "Cloud Driver"? Keyboards don't need an internet connection. xD 

CPU: Intel Core i7-5820K | Motherboard: AsRock X99 Extreme4 | Graphics Card: Gigabyte GTX 1080 G1 Gaming | RAM: 16GB G.Skill Ripjaws4 2133MHz | Storage: 1 x Samsung 860 EVO 1TB | 1 x WD Green 2TB | 1 x WD Blue 500GB | PSU: Corsair RM750x | Case: Phanteks Enthoo Pro (White) | Cooling: Arctic Freezer i32

 

Mice: Logitech G Pro X Superlight (main), Logitech G Pro Wireless, Razer Viper Ultimate, Zowie S1 Divina Blue, Zowie FK1-B Divina Blue, Logitech G Pro (3366 sensor), Glorious Model O, Razer Viper Mini, Logitech G305, Logitech G502, Logitech G402

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, PCGuy_5960 said:

Why would anyone install a "Cloud Driver"? Keyboards don't need an internet connection. xD 

Sure they can use an internet connection, for "stuff and things" that are "important".

a Moo Floof connoisseur and curator.

:x@handymanshandle x @pinksnowbirdie || Jake x Brendan :x
Youtube Audio Normalization
 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Mooshi said:

Not everyone can afford a branded mech keyboard so this really sucks people are this scummy.

To a point, I wonder if membrane is better than knock off mechanical switches.

a Moo Floof connoisseur and curator.

:x@handymanshandle x @pinksnowbirdie || Jake x Brendan :x
Youtube Audio Normalization
 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

At least now you know why it was so cheap. They be selling your info. 

CPU: Ryzen 9 5900 Cooler: EVGA CLC280 Motherboard: Gigabyte B550i Pro AX RAM: Kingston Hyper X 32GB 3200mhz

Storage: WD 750 SE 500GB, WD 730 SE 1TB GPU: EVGA RTX 3070 Ti PSU: Corsair SF750 Case: Streacom DA2

Monitor: LG 27GL83B Mouse: Razer Basilisk V2 Keyboard: G.Skill KM780 Cherry MX Red Speakers: Mackie CR5BT

 

MiniPC - Sold for $100 Profit

Spoiler

CPU: Intel i3 4160 Cooler: Integrated Motherboard: Integrated

RAM: G.Skill RipJaws 16GB DDR3 Storage: Transcend MSA370 128GB GPU: Intel 4400 Graphics

PSU: Integrated Case: Shuttle XPC Slim

Monitor: LG 29WK500 Mouse: G.Skill MX780 Keyboard: G.Skill KM780 Cherry MX Red

 

Budget Rig 1 - Sold For $750 Profit

Spoiler

CPU: Intel i5 7600k Cooler: CryOrig H7 Motherboard: MSI Z270 M5

RAM: Crucial LPX 16GB DDR4 Storage: Intel S3510 800GB GPU: Nvidia GTX 980

PSU: Corsair CX650M Case: EVGA DG73

Monitor: LG 29WK500 Mouse: G.Skill MX780 Keyboard: G.Skill KM780 Cherry MX Red

 

OG Gaming Rig - Gone

Spoiler

 

CPU: Intel i5 4690k Cooler: Corsair H100i V2 Motherboard: MSI Z97i AC ITX

RAM: Crucial Ballistix 16GB DDR3 Storage: Kingston Fury 240GB GPU: Asus Strix GTX 970

PSU: Thermaltake TR2 Case: Phanteks Enthoo Evolv ITX

Monitor: Dell P2214H x2 Mouse: Logitech MX Master Keyboard: G.Skill KM780 Cherry MX Red

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, dizmo said:

At least now you know why it was so cheap. They be selling your info. 

And if you're in China or a country with censorship laws like China... You better not dare write anything dear leader(s) might not appreciate.

a Moo Floof connoisseur and curator.

:x@handymanshandle x @pinksnowbirdie || Jake x Brendan :x
Youtube Audio Normalization
 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, dizmo said:

At least now you know why it was so cheap. They be selling your info. 

Why sell it when you are literally giving them your bank login and password

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, PCGuy_5960 said:

Why would anyone install a "Cloud Driver"?

why? for the same reason people install a flashlight app on their phone that needs permission to access the internet ... 

 

... and your contacts of course

Link to comment
Share on other sites

Link to post
Share on other sites

That's just really bad like oh wow. 

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

55 minutes ago, PCGuy_5960 said:

Why would anyone install a "Cloud Driver"? Keyboards don't need an internet connection. xD 

To be fair even Razer has a "Cloud Driver" (Synapse). Cloud backed configuration has been a primary selling point for a while now.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, wcreek said:

Damnit China, why you selling us keyboards that'll spy on us that aint cool.

 

1 hour ago, Mooshi said:

Not everyone can afford a branded mech keyboard so this really sucks people are this scummy.

 

1 hour ago, wcreek said:

To a point, I wonder if membrane is better than knock off mechanical switches.

For anyone looking for a cheap mech keyboard, look at the Eagletec kg010. It's 40 bucks and it feels exactly like genuine mx blues. Oh yeah. And it doesn't spy on you, that's cool too.

i7 2600k @ 5GHz 1.49v - EVGA GTX 1070 ACX 3.0 - 16GB DDR3 2000MHz Corsair Vengence

Asus p8z77-v lk - 480GB Samsung 870 EVO w/ W10 LTSC - 2x1TB HDD storage - 240GB SATA SSD w/ W7 - EVGA 650w 80+G G2

3x 1080p 60hz Viewsonic LCDs, 1 glorious Dell CRT running at anywhere from 60hz to 120hz

Model M w/ Soarer's adapter - Logitch g502 - Audio-Techinca M20X - Cambridge SoundWorks speakers w/ woofer

 

Link to comment
Share on other sites

Link to post
Share on other sites

Going to repeat my post on reddit:

 

This article is an example of terrible tech journalism. There is no keylogger, and they didn't even read the source; they just made things up based on a picture they didn't understand.

 

The data is the number of times each key has been pressed, and it's only sent once per session (whenever the software is restarted), presumably as an online heatmap backup. There's no malicious keylogger; the only bad thing going on here is that the heatmaps aren't encrypted.

 

Unfortunately, nobody on reddit and nobody at the news outlets (Tom's Hardware, DigitalTrends, Techpowerup) appears to have fully read the original post this all is based on. The author even says there isn't a keylogger a few posts later.

 

The person all these articles are citing as the source has written a follow-up on reddit here.

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, Nimrodor said:

Going to repeat my post on reddit:

 

This article is an example of terrible tech journalism. There is no keylogger, and they didn't even read the source; they just made things up based on a picture they didn't understand.

 

The data is the number of times each key has been pressed, and it's only sent once per session (whenever the software is restarted), presumably as an online heatmap backup. There's no malicious keylogger; the only bad thing going on here is that the heatmaps aren't encrypted.

 

Unfortunately, nobody on reddit and nobody at the news outlets (Tom's Hardware, DigitalTrends, Techpowerup) appears to have fully read the original post this all is based on. The author even says there isn't a keylogger a few posts later.

 

The person all these articles are citing as the source has written a follow-up on reddit here.

Let's say that's correct.

 

It's still wrong.

 

You could potentially reconstruct some data using that info. It's also sent unencrypted, which is terrible. And finally, and most importantly, there was no consent. They didn't ask to collect and send that data.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

If you're going to buy a cheap off brand mechanical keyboard, buy one without one of those fancy software included. I know mine doesn't have one and it only cost $30.

Link to comment
Share on other sites

Link to post
Share on other sites

When China does it: it's wrong and you should kill yourself

When MS does it: it's telemetry and you're just being a tinfoil hat guy

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, suicidalfranco said:

When China does it: it's wrong and you should kill yourself

When MS does it: it's telemetry and you're just being a tinfoil hat guy

There is a difference - Microsoft at least let's you know it's happening, when you go through the setup of Windows 10.

 

Plus just because one company does it, doesn't make it okay for another.

 

Furthermore, telemetry for an OS makes sense in a diagnostic sense. People I think are most caught off guard because a Keyboard should be a simple device with no online component at all.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, dalekphalm said:

People I think are most caught off guard because a Keyboard should be a simple device with no online component at all.

*cough razer synapse *cough

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, suicidalfranco said:

*cough razer synapse *cough

Sure but at least that serves a function of backing up your config.

 

In either case, many people would no doubt be uncomfortable even with Razer Synapse.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

There is a new article on the the site "thehackernews.com" that people have found MantisTek GK2 Mechanical Gaming Keyboards recording the key strokes of the user (also known as a key-logger) and sending it to a server hosted by the "Alibaba Group" located in China.

Capture.JPG.1edb18da4b7e68e10dd5608eeeb12528.JPG

Full article below. 

https://thehackernews.com/2017/11/mantistek-keyboard-keylogger.html

Link to comment
Share on other sites

Link to post
Share on other sites

One more reason to be suspicious of cheap versions of products from unknown brands.

 

Actually there's a far more serious issue here than the fact some random keyboard has a keylogger.  It was sending it to Alibaba!?  Does that not mean this was their idea and they're running it?  This story shouldn't be "keyboard X has a keylogger", it should be "alibaba spies on customers by selling them malware infested products"

 

Edit: oh, maybe not.  This was missing from the OP above :P

Quote

  Alibaba sells cloud services, so the data isn’t necessarily being sent to Alibaba, the company, but to someone else using an Alibaba server.

 

This would be a good topic for WAN show actually since Linus has done cheap keyboard roundups/recommendations in the past

Edited by Ryan_Vickers

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Yeah it would be and I didn't even know that but i'm glad personally i have stuck with my old trusty Mac keyboard. lol

Link to comment
Share on other sites

Link to post
Share on other sites

"It's OK because you can turn it off, by blocking it in a firewall"

"It's probably somewhere in the TOS so all the blame is on you. This is perfectly acceptable"

"I don't care that they know what I press on my keyboard, I am not an interesting person so they don't care about me anyway"

"It doesn't collect any personal information so you should not worry about it"

"Why does anyone care unless you're typing something illegal?"

"It's just telemetry data about how you use their keyboard. Nothing important."

"Just don't use a keyboard if you don't like it"

"Google and Facebook already knows what you type anyway"

 

Did I miss anything?

Seriously though, fuck this company. Even if it's "just how often you press a key", that's still too much. The way I look at it, sending data, any data at all, from my computer is a privilege that developers should earn. Can't justify to me why some data is leaving my computer? Then it has no business leaving my computer.

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, mynameisjuan said:

Why sell it when you are literally giving them your bank login and password

if there was a line in regards to data collection that woukd be just over it. 

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×