I have a keyboard that runs custom, open-source software.
It would be easy to figure that out about me, if you cared. Say if you found a list of employees and contractors.
A sufficiently-motivated attacker could backdoor my firmware with a timer-based exploit (e.g., start your keystroke payload after ten minutes without input events)
and I might well not notice if it was a deft-enough change.
It might not be worth the cost, given that I might well notice it and it might not pay off even if I didn't.
Still - the point is that keyboards are not innocuous, harmless devices that it's a no-brainer to allow.
It would be easy to figure that out about me, if you cared. Say if you found a list of employees and contractors.
A sufficiently-motivated attacker could backdoor my firmware with a timer-based exploit (e.g., start your keystroke payload after ten minutes without input events) and I might well not notice if it was a deft-enough change.
It might not be worth the cost, given that I might well notice it and it might not pay off even if I didn't.
Still - the point is that keyboards are not innocuous, harmless devices that it's a no-brainer to allow.