Researcher Michael Myng aka "ZwClose" was trying to solve the problem of friend's keyboard while discovering keylogger software. Software is off by default.
After Myng contacted HP about the program, we immediately released the patch and removed it.
"Keylogger is a very dangerous software," said Lamar Bailey, director of security research and development at Tripwire.
"It's like looking over your shoulders while you are typing," told TechNewsWorld. "Keyloggers can capture passwords that you can use to access financial accounts, record personal communications, or record your own code under development.
Keylogger is an important weapon of cyber attack weapons, notes Chris Morales, director of security analytics at Vectra Networks.
"We collect user credentials and other confidential information and are frequently used in the coordination phase of targeted attacks to compromise user accounts at a later time," he told TechNewsWorld.
"Keyboard loggers may be very difficult to spot on consumer AV," Morales added.
Rather than using a malicious payload that could be identified by a security product, a clever attacker could turn on the built-in keyboard logger feature and use it, Mr. David Pickett (AppRiver's security Analyst)
"This will help to avoid the traditional detection method that a security product might have been able to detect," he told TechNewsWorld.
Because it is as dangerous as a keylogger, over 460 HP laptop model software seems to have no malicious intent behind it.
"Keynogger seems to be part of the driver of Synaptics Touchpad," says Frederik Mennes, Vasco Data Security's senior market and security strategy manager.
"This was used for debugging purposes by the company providing a touchpad," he told TechNewsWorld.
Vectra 's Morales said the keylogger tool should have been removed from the software before it was finalized.
"In this case, it is unlikely to be a consciously malicious act, but it is another example of poor control of QA for the risk of digital supply chain."
According to AppRiver's Picket, third party driver quality control checks seemed not enough to reveal the remaining invalid keylogger from the software development stage.
"While key logging data was developing software for the purpose of troubleshooting and debugging, it is extremely convenient as security concerns are raised once it is distributed.
Although the code on the laptop is not a malicious code, it could be exploited by a bad actor, Joseph Carson, director of Thycotic's global strategic alliance points out.
"When code is injected by hackers without knowledge of HP, it will be a major disaster," he told TechNewsWorld.
If the code given to HP by the supplier is not carefully checked before it is sent to the system producing the product it will get even worse.
"If so, I would be very worried about the other code undergoing the same software development lifecycle," Carson said.
Keyloggers can pose a serious threat to consumers, but Basego's Mene suggests that in the case of HP keyloggers the threat is not important.
"Keyloggers are disabled by default and the risk to consumers and business users is considerably lower, as administrators need to have access to the device," he said.
Mr. Carson of Tychotics said, "I do not think that cybercriminals should be concerned about the possibility of misuse of code with administrator's permission." If so, consumers are already having big problems and the system is likely to be totally compromised.
Nonetheless, he said it would be desirable for consumers to ensure system updates and reduce opportunities for misuse.