Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Mechanical keyboard maker accused of keylogging as customers examine software

Add as a preferred source on Google

Jump on Amazon to perform a search for mechanical keyboards and the cheapest solutions you find are sold by manufacturers you likely don’t know. MantisTek is one of these lesser-known keyboard makers and is now under fire for allegedly tracking the typed keys of those who own its GK2 mechanical keyboard, aka keylogging. This alleged tracking is done through the included software, which sends information to a server maintained by the Alibaba Group.

Typically, the software can be used to customize the keyboard’s RGB illumination, lighting effects, and macro assignments. But a few owners are reporting that the software sends data to an IP address owned by Alibaba. A post stemming out of Asia provides a few more detailed bits, reporting that MantisTek’s “cloud driver” is the responsible component sending data to a specific address: 47.90.52.88.

Recommended Videos

If you enter that address in a browser, a Chinese login page appears along with a link to Browse Happy. The page translates to “Cloud mouse platform background management system,” and is maintained by Shenzhen Cytec Technology Co., Ltd., which may or may not be a rechargeable battery maker located in Shenzhen, China (Cytec doesn’t appear in a web search, but Cytac does).

According to the report, the keyboard’s software sends keypress statistics to two destinations at that IP address: “/cms/json/putkeyusedata.php” and “/cms/json/putuserevent.php.” An analysis shows that all information is crossing the internet in plain text, meaning its unencrypted and exposed to anyone snooping on your internet connection. That means hackers — in addition to MantisTek — can grab anything you type, including email addresses, bank account numbers, and login credentials.

The best defense against MantisTek’s alleged keystroke snooping is to not use the GK2’s included software. Based on the product information, you can adjust the illumination and lighting effects manually on the keyboard using a combination of keys. You can do the same when recording macros.

But if you wish for the software to remain installed, then block CMS.exe in your firewall to prevent the software from sending and receiving information over the internet. To do this in Windows 10, type “Windows Firewall” into Cortana’s search field on the taskbar, click on “Windows Defender Firewall with Advanced Security.” After that, add a new Inbound and Outbound rule for CMS.exe.

Mechanical keyboards with virtually no security issues (that we know of) are typically manufactured by high-profile companies such as Razer, Corsair, Logitech, Roccat, Microsoft, Cooler Master, Thermaltake, and a few others. But even with these products, installing software should only be necessary if you want access to the keyboard’s core features. The less software you install, the happier your PC will be.

To be clear, Alibaba isn’t collecting information from owners of the MantisTek GK2 mechanical keyboard. The company provides cloud services, aka Alibaba Cloud, including an elastic compute service, a virtual private cloud, an analytic database, and anti-DDOS services. The “cloud driver” may be silently collecting information for analytic purposes rather than intentionally collecting sensitive information

Still, keylogging is unacceptable no matter the root intention.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Avec’s new AI feature makes sure you never miss a deadline again
One swipe is all it takes for Avec to remember your email deadlines now
avec-email-app-never-forget-anything-feature

We have all been there. A deadline gets buried somewhere in a long email thread, life gets busy, and suddenly you are apologizing for a missed follow-up you completely forgot about. Avec, the AI powered email app built around swipe gestures and voice dictation, just rolled out a fix for this problem, and it might be the app's smartest addition yet.

https://twitter.com/jnnnthnn/status/2090104762251497908?s=46

Read more
My Mac never tells me where my internet goes, so I found an app that does
Computer, Electronics, Laptop

I’ve been using a Mac for a long time, and over the years, I’ve gotten pretty good at figuring out what’s going wrong when something feels off. Most of the time, I start in the Settings app. I poke around, change a few things, and usually find whatever is causing the problem. Storage is a good example. I recently noticed my Mac slowing down, opened the Storage section, and immediately got a clear breakdown of what was taking up space. One cleanup later, I had freed up some much-needed storage, and everything felt normal again. I’ve done something similar when trying to figure out battery drain or unusually high CPU usage. macOS gives you plenty of places to look when you know something isn’t quite right.

There’s one thing it doesn’t make nearly as obvious, though: where all your internet data is actually going. I only started thinking about this because my internet had been acting strangely for the past few days. Things felt slower than usual, and I couldn’t figure out why. My connection seemed fine, and I wasn’t downloading anything massive, so what was eating up all that bandwidth? Turns out, quite a few apps on my Mac were using the internet in the background, and I had no idea. I probably wouldn’t have figured that out either if I hadn’t come across a Mac app that showed me exactly what was happening behind the scenes. And that’s where things got interesting.

Read more
Researchers expose a worryingly simple trick to make AI bots go rogue and skip safety
average-users-break-past-ai-safety-gemini-chatgpt

If you ask an AI agent to hack an account, it will most certainly refuse, but researchers at EPFL just proved there is an easier way in, and it involves patience rather than technical skill. Their new study shows that breaking a harmful goal into small, harmless-sounding requests can trick AI agents into completing tasks they would normally reject outright (via TechXplore).

It echoes the recent 'Bioshocking' exploit in which AI browsers were manipulated into treating credential theft as part of a harmless game.

Read more