[Owasp-Malaysia] KeyScrambler Personal encrypts your keystrokes - Does This Really Work

David Fetter david at fetter.org
Mon Sep 13 13:29:42 EDT 2010


On Tue, Sep 14, 2010 at 12:37:55AM +0800, Harisfazillah Jamel wrote:
> Assalamualaikum and salam sejahtera,
> 
> I found this add-on for Mozilla Firefox that said can defeat Keylogger....
> 
> KeyScrambler Personal encrypts your keystrokes at the kernel driver
> level to protect what you type from keyloggers.
> 
> https://addons.mozilla.org/en-US/firefox/addon/3383/
> 
> Can it really help?

It can help QFX Software make money, so in that sense, it helps
someone.

As far as defending against actual keylogging attacks, it's pretty
helpless against ones that target they keyboard hardware.  I'd say if
your computer is compromised to the point of having keyboard loggers
installed, your chances of keeping anything private on it are
approximately zero.

This is an excellent example of "security as product," which is
fundamentally the wrong way to go about it.  That a giant industry is
premised on this mistake is not a reason to believe that it's not a
mistake.

Cheers,
David.
-- 
David Fetter <david at fetter.org> http://fetter.org/
Phone: +1 415 235 3778  AIM: dfetter666  Yahoo!: dfetter
Skype: davidfetter      XMPP: david.fetter at gmail.com
iCal: webcal://www.tripit.com/feed/ical/people/david74/tripit.ics

Remember to vote!
Consider donating to Postgres: http://www.postgresql.org/about/donate


More information about the Owasp-Malaysia mailing list