Author Topic: Work sprung a doozy on me the other day...  (Read 6933 times)

0 Members and 1 Guest are viewing this topic.

Offline katushkin

  • Too Keycool for School
  • * Elevated Elder
  • Posts: 3667
  • Location: Birmingham - Not Alabama
  • Just the guy
Re: Work sprung a doozy on me the other day...
« Reply #50 on: Fri, 25 April 2014, 17:51:06 »
I'm pretty lucky that I work on our control bridge and I'm left alone most of the time. We all plug our phones into our thin clients, and my boss who owns the data centre has seen my blue and white keyboard and doesn't really care. I think the fact that we only have thin clients is why nobody has said anything to me.
Can we get them to build the Alps ten feet higher and get Cherry to pay for it?
Katushkin's Clearout | Twitter | Steam | Instagram| Discord - katushkin

Offline dorkvader

  • Posts: 6288
  • Location: Boston area
  • all about the "hack" in "geekhack"
Re: Work sprung a doozy on me the other day...
« Reply #51 on: Fri, 25 April 2014, 18:57:51 »
Seriously, never known anyone develop a computer problem on their machine from connecting a keyboard or mouse. Its just never happened. Certainly not from a reputable company.
I have a few years' experience with diagnosing computers, and I've seen a few that have done this. The company was "Apple" for both devices, not sure if I'd call them reputable though.

---
@nubbinator: pull the ergo card and use it for all it's worth. Fortunately I'm on good terms with the information systems guys at my company, and they let me use whatever KB I want.

Offline smknjoe

  • Posts: 862
  • Location: Tejas
  • I like tactile, clicky, switches.
Re: Work sprung a doozy on me the other day...
« Reply #52 on: Fri, 25 April 2014, 19:25:29 »
Sorry Nub, but this is the world we live in now. Especially if your company is in the healthcare sector. There is a reason they implemented this policy and part of is to be in compliance probably.

Plugging a USB keyboard into a computer is not the same as plugging a USB memory drive. Not the same thing at all.

Seriously, never known anyone develop a computer problem on their machine from connecting a keyboard or mouse. Its just never happened. Certainly not from a reputable company.

I'd go down the ergonomics route if they persist. Denying people the tools they need to do a job and its a recipe for an industrial tribunal.



Never say never. Security breaches happen with HIDs (Human Interface Device) every day. Did you click on his link here?

Ive posted this before but this is the reason why
http://www.theregister.co.uk/2011/06/27/mission_impossible_mouse_attack/

That example is a moded mouse, but it's really a USB "flash" device that looks like a regular USB keyboard to the PC and therefore the PC treats it as such. No AV or firewall software scans keyboards for Malware. These devices can be programmed for all sorts of things like setting up a reverse ssh tunnel to a server that allows full remote access to your  PC and entire network potentially.

Nub, it looks like your company is taking security seriously. Which is good. Like everyone else said, talk to your IT/HR people and see what they can do for you. Maybe if they purchase the board you choose and inspect it they will be okay with it?
« Last Edit: Fri, 25 April 2014, 19:46:40 by smknjoe »
SSKs for everyone!

Offline Techno Trousers

  • Posts: 908
  • ʘ_ಠ
Re: Work sprung a doozy on me the other day...
« Reply #53 on: Fri, 25 April 2014, 19:28:56 »
This is probably what they are really trying to prevent. Many of us here have used a Teensy to modernize a model F, so an adversary could extend that Teensy programming to do nefarious stuff.

http://www.offensive-security.com/offsec/advanced-teensy-penetration-testing-payloads/

Then again, if a company isn't already preventing physical access to the workstation USB ports, then this rule doesn't make sense. It would be WAY easier to just use a payload on a USB stick, rather than going to all the trouble of modding your own keyboard or mouse.


Offline smknjoe

  • Posts: 862
  • Location: Tejas
  • I like tactile, clicky, switches.
Re: Work sprung a doozy on me the other day...
« Reply #54 on: Fri, 25 April 2014, 19:31:12 »
That's exactly what they used in the link Lanx posted. There are many different iterations of course. They come as USB "flash" drives but sticking it into a mouse or keyboard is a good diversion if you are in a workplace that doesn't allow USB flash drives.
« Last Edit: Fri, 25 April 2014, 19:34:36 by smknjoe »
SSKs for everyone!

Offline SpAmRaY

  • NOT a Moderator
  • * Certified Spammer
  • Posts: 14667
  • Location: ¯\(°_o)/¯
  • because reasons.......
Re: Work sprung a doozy on me the other day...
« Reply #55 on: Fri, 25 April 2014, 19:43:05 »
Tell them to get you a das or filco, and say you can't work efficiently without it.

Thankfully I have a boss who makes sure I have whatever I need/want (within reason) to better do my job, however I would imagine many places would just show you the door for making too big of a fuss over a mouse and keyboard.


Offline terrpn

  • Alpha Geezer
  • * Exquisite Elder
  • Posts: 992
  • Location: MD/VA
  • - Buy Vintage -
Re: Work sprung a doozy on me the other day...
« Reply #56 on: Fri, 25 April 2014, 22:58:11 »
yep..........did the same thing at my place to, but did not apply to me :cool:

if they will accept Staples as a vendor and you don't have to use ergo...........they do sell matias, cherry, cm, ibm rubber domes that might pass?, keytronic, razer, steelseries and of course logitech
More

Luga G80-1865/MX Reds + Dolch G80-1813/MX Blues + G80-3700HQAUS + DK9008G2 Pro/MX Browns Thick PBT + DK9008G2 Pro/MX Clears Thick PBT +  QFR TKL/Ghetto Greens + Cherry G80-1800/MX Blues + IBM Model M SSK Bolt Modded + IBM Model M + IBM Model F + IBM AT F + Cherry G80-1000 (HAD)/MX Vintage Blacks + Razer BWU/MX Blues + Leading Edge DC2214/Blue Alps + Compaq MX11800/Browns + Chicony 5181/Monterey Blues + Chicony 5161/MX Black Cherry Clone + Focus 2001/White Alps + Chicony 5191/White Futabas + Olivetti ANK27-101 + Dell (Old Logo) AT101/Black Alps + NMB RT8255C+/Black Space Invaders + Unitek K260/Green Alps + Apple M0116/Orange Alps + AEK II M3501/Cream Alps + AEK M0115/Orange Alps + NEC  APC412/Blue Sliders + NEC APC410/Blue Sliders + Omnikey /White Alps + Wang/Yellow Alps (Omrons) + Laser/White SMK + Fame/Blue Aruz + AEK II M3501/Salmon Alps + Zenith ZKB-2R/Green Alps + Wang 724/Orange Alps + DK1087/Green Alps + Zenith ZKB-2/Yellow Alps + Dell Old Logo AT101/Salmon-Pink Alps + Leading Edge AK1012/White SMK's + Magitronic SK-1030/White (Linear) Futaba's + Packard Bell/White (Clicky) Futaba's + Datacomp DFK101/White  Alps + SGI AT101/Dampened White Alps + NMB AQ6RT-72511/Grey Space Invaders (Hi-Tek) + Datacomp/Blue Alps + Phillips 2812/White Space Invaders (Linear) + Dah Yang K251/Vintage MX Blues + Chicony 5161/DS Caps/Vintage MX Blue + Archie-NMB AQ659ZRT-725/Black Space Invader (Tactile) + IBM Model M 71G4644 (RD) Bolt Modded with Soarers Converter + IBM Model M Silver Label 1390131 + Cherry G80-1501/Vintage MX Clears + Focus FK8000/Linear Futabas + Gateway 2000 Anykey Programmable/Maxi-Switch + Dell GY13PVAT101/Dye Sub Caps/Salmon Alps + Chicony 5161/White Alps + AST K0B101/Slider over RD + Qtronix QX-32H + Everex/NMB RT8255CW+ Black Space Invaders-Split Erase + Tandon/NMB AQ659ZRT-101A/Beige Space Invaders + Cherry G80-11903 MNRUS/MX Blacks + Apple IIGS A9M0330/SMK Whites + WYSE PCE/MX Blacks + Chicony 5160AXT/Clicky Futaba + Cherry G80-0528/Vintage MX Blacks + Dell AT101/Linear (Modded) Black Alps+Topre 55g

Offline mougrim

  • Posts: 768
  • Location: Ukraine
Re: Work sprung a doozy on me the other day...
« Reply #57 on: Sat, 26 April 2014, 00:16:56 »
This is probably what they are really trying to prevent. Many of us here have used a Teensy to modernize a model F, so an adversary could extend that Teensy programming to do nefarious stuff.

http://www.offensive-security.com/offsec/advanced-teensy-penetration-testing-payloads/

Then again, if a company isn't already preventing physical access to the workstation USB ports, then this rule doesn't make sense. It would be WAY easier to just use a payload on a USB stick, rather than going to all the trouble of modding your own keyboard or mouse.

Heh. I heard of a company which routinely conducts full-body search on employees - all phones, usb-sticks, such must be left at the entrance, and so on...
IBM AT Model F, Vortexgear Race 3, AEKII (Alps Cream Damped), Metoo Zero (modded to Kailh Box Navy)

Offline mouse.the.lucky.dog

  • Posts: 146
Re: Work sprung a doozy on me the other day...
« Reply #58 on: Sat, 26 April 2014, 01:00:46 »
This is probably what they are really trying to prevent. Many of us here have used a Teensy to modernize a model F, so an adversary could extend that Teensy programming to do nefarious stuff.

http://www.offensive-security.com/offsec/advanced-teensy-penetration-testing-payloads/

Then again, if a company isn't already preventing physical access to the workstation USB ports, then this rule doesn't make sense. It would be WAY easier to just use a payload on a USB stick, rather than going to all the trouble of modding your own keyboard or mouse.

Is something like this even possible if you only use ps2?

Offline nubbinator

  • Dabbler Supreme
  • * Maker
  • Thread Starter
  • Posts: 8658
  • Location: Orange County, CA
  • Model M "connoisseur"
Re: Work sprung a doozy on me the other day...
« Reply #59 on: Sat, 26 April 2014, 01:02:12 »

Is something like this even possible if you only use ps2?

That's what I'm wondering.  I'll gladly go PS/2 if I can use a good keyboard and not the **** available to me.

Offline smknjoe

  • Posts: 862
  • Location: Tejas
  • I like tactile, clicky, switches.
Re: Work sprung a doozy on me the other day...
« Reply #60 on: Sat, 26 April 2014, 01:19:56 »
No. That particular type of device only works with USB.

It is possible.

Edit: Well, I was curious about this since I've never actually tried it and it does work with a PS2 adapter, but it requires a reboot of the machine in order to be recognized.

Looks like you are stuck with trying to sweet talk your IT/HR people. Good luck, Nub.
« Last Edit: Sat, 26 April 2014, 02:23:20 by smknjoe »
SSKs for everyone!

Offline mkawa

  •  No Marketplace Access
  • Posts: 6562
  • (ツ)@@@. crankypants
Re: Work sprung a doozy on me the other day...
« Reply #61 on: Sat, 26 April 2014, 20:21:24 »
newegg/cdw/etc are probably on their list of approved providers, so what probably needs to happen is that you need to get the keyboard you want, let's say another rk-9000, approved for use, then have IT source it.

the evoluent handshake mouse is almost certainly already approved because evoluent spent a lot of money convincing the public sector to certify their devices in hipaa situations and used the empirical research that handshake reduces occurrence of work-related RSI significantly to push everything through. so, for the mouse, i'd go with that. IT shouldn't have trouble getting you one, and it's a really comfortable mouse.

the RK-9000 is a newegg house brand keyboard and there is no way they're going to go through the effort to push like evoluent did. that said, it's almost identical to a lot of keyboards that might have been approved.

actually, before you move forward with trying to get an MX-switched keyboard, make sure that unicomp isn't an approved vendor first. afaik unicomp does a fairly large amount of public sector business who have to source their products as replacements for old IBM keyboards.

if they aren't, try looking for anything in the approved list of vendors and p/ns that look like they are deck or TG3 boards. TG3 sells a ton of boards into law enforcement; i think most of us have bought a rebadged police interceptor workstation keyboard from a surplus outlet at some point. the next vendor i'd look at is adesso. they have a long history of supporting macs institutionally with input devices and were die hard alps-style switch customers at one point. they currently have two MX boards in their lineup: http://www.adesso.com/products/product-sort2-16.html

the last vendor that i think might be able to pull this off that i can think of is matias. afaik, prior to the new switch and models, edgar matias sold a lot of keyboards in mac-locked markets as replacements for AEKs and i have no doubt that he can navigate this space if it makes sense to him. that said, i don't know if he's pursuing it with the new line, but they're great boards and he has a bunch of cool ergo models as well. also, his organization also doesn't have the kind of corporate lethargy that some of the bigger companies (logitech, namely) have, as he demonstrates every day on this very forum :).

anyway, the one thing i'd like to emphasize is to _not_ try to split hairs on this one. there's nothing really sensical about most rules in public IT. i'm going to take a wild guess that there's very little keeping someone from sneaking usb keys inside the cases of all their stock of approved keyboards and accomplishing max exfiltration despite the security rubrick, or just like, using their phonecam to take a picture of a sensitive screen.

i have friends who work on projects whose operational security departments have their stuff together, and you have to go way way beyond not letting people bring in usb devices to maintain op sec. at probably the most notable workplace i have friends at, the _last_ line of defense is a building-mounted anti-aircraft battery.
« Last Edit: Sat, 26 April 2014, 20:32:12 by mkawa »

to all the brilliant friends who have left us, and all the students who climb on their shoulders.

Offline dorkvader

  • Posts: 6288
  • Location: Boston area
  • all about the "hack" in "geekhack"
Re: Work sprung a doozy on me the other day...
« Reply #62 on: Sat, 26 April 2014, 20:57:35 »
if they aren't, try looking for anything in the approved list of vendors and p/ns that look like they are deck or TG3 boards. TG3 sells a ton of boards into law enforcement; i think most of us have bought a rebadged police interceptor workstation keyboard from a surplus outlet at some point. the next vendor i'd look at is adesso. they have a long history of supporting macs institutionally with input devices and were die hard alps-style switch customers at one point. they currently have two MX boards in their lineup: http://www.adesso.com/products/product-sort2-16.html
TG3 also make CNC controller KBs though they are really expensive on eBay. I suspect they might have OEM'd some medical KBs as well, but I have no hard proof.

They are also one of my fav oems.

Offline demik

  • Pronounced "demique"
  • Posts: 11159
Re: Work sprung a doozy on me the other day...
« Reply #63 on: Sat, 26 April 2014, 21:10:23 »
Nah time to quit.

still best advice
No, he’s not around. How that sound to ya? Jot it down.

Offline hoggy

  • * Ergonomics Moderator
  • Posts: 1502
  • Location: Isle of Man
Re: Work sprung a doozy on me the other day...
« Reply #64 on: Sun, 27 April 2014, 01:15:55 »
Would you be able to persuade staples to source the keyboard you want? It would probably be easier to do from inside a shop... Say they add x dollars to the price from your vendor as their fee.
GH Ergonomic Guide (in progress)
http://geekhack.org/index.php?topic=54680.0

Offline mougrim

  • Posts: 768
  • Location: Ukraine
Re: Work sprung a doozy on me the other day...
« Reply #65 on: Sun, 27 April 2014, 02:33:57 »
Would you be able to persuade staples to source the keyboard you want? It would probably be easier to do from inside a shop... Say they add x dollars to the price from your vendor as their fee.
Oh, graft way :) It might just work.
IBM AT Model F, Vortexgear Race 3, AEKII (Alps Cream Damped), Metoo Zero (modded to Kailh Box Navy)

Offline jwaz

  • * based mod
  • Posts: 2069
  • #geekhack on freenode
Re: Work sprung a doozy on me the other day...
« Reply #66 on: Sun, 27 April 2014, 03:23:13 »
So I thought this was absolutely ridiculous on behalf of your job but then I saw this:

Teensy attack at ~40:17

Offline tricheboars

  • * Esteemed Elder
  • Posts: 964
  • Location: Denver
  • Keyboards are Important!
Re: Work sprung a doozy on me the other day...
« Reply #67 on: Sun, 27 April 2014, 16:37:17 »
So I thought this was absolutely ridiculous on behalf of your job but then I saw this:

Teensy attack at ~40:17

****. that was nuts.  i would never have thought someone could do that with a teensy.
|  Fundamentalist ErgoDox Zealot  |  HHKB Hybrid

Offline SpAmRaY

  • NOT a Moderator
  • * Certified Spammer
  • Posts: 14667
  • Location: ¯\(°_o)/¯
  • because reasons.......
Re: Work sprung a doozy on me the other day...
« Reply #68 on: Sun, 27 April 2014, 17:03:13 »
So I thought this was absolutely ridiculous on behalf of your job but then I saw this:

Teensy attack at ~40:17

****. that was nuts.  i would never have thought someone could do that with a teensy.

Someone posted it somewhere in this thread but check out the 'peensy'