
Our computer’s hardware – the circuits, chips, disks, memory, cables, and connectors – is something we rarely think about when it comes to considering our privacy.
We would be wise to.
While it’s not as easily compromised, since it requires physical access, hackers know we take our hardware for granted. When it comes to getting at our information, hardware represents another way in. Fortunately, hardware attacks aren’t nearly as common as software-based threats, but they can happen.

Hardware hacks
It’s rare, but your hardware can be compromised too. Never type anything private on a public computer. Skip public USB charging spots and bring your own wall charger. Tap to pay when you can, and use card machines you know and trust. Develop simple habits to keep yourself safe.
Hardware keyloggers
A keylogger is usually a form of malware that resides on your computer, intercepting and recording all your keystrokes (and other activity). It then sends them off to some malicious third party. Type in your username and password, and the keylogger intercepts and records them.
Keyloggers can also be present in hardware. A device inserted between your keyboard and computer can do exactly the same thing: record all keystrokes for transmission or later collection by that same malicious party.
Hardware keyloggers are less common because they require physical access to the machine on which they’re installed. Once installed, however, they’re nearly impossible for the average computer user to detect. It doesn’t matter what anti-malware tools are running, what operating system is installed, clean-installed, or booted from; the keylogger remains in place, recording your data.
There are two simple guidelines:
- Never use a public computer for anything in any way sensitive. Hardware keyloggers are most commonly found on public computers.
- Remember, “If it’s not physically secure, it’s not secure”. If your computer is in a public or highly trafficked place, it’s possible someone could add a hardware keylogger when you’re not around.
Most people don’t need to worry about hardware keyloggers. As I said, they’re rare, mostly because installation requires physical access to the machine.
But they definitely exist.
Help keep it going by becoming a Patron.
Public charging
This is, to me, a fascinating form of compromise.
You’re on a trip, and your mobile phone’s battery is running low. You find a convenient charging station where you can plug in and top off the battery before you board your plane.
Unfortunately, that connection might provide more than power. The connection can include malicious hardware secretly placed there by a hacker. That hardware could use the USB data connection to look through your phone or even put malware on it.
It’s not common, but it can happen.
Fortunately, the solutions are simple.
- Never use a public USB connection for anything. You simply don’t know what you’re connecting to.
- Bring and use your wall charger instead. Assuming you can find a wall outlet, this is a safe way to recharge your device.
- If you must, get and use a “data blocker”, a small adapter that sits between your cable and the charger and blocks any attempt to connect to your data.
Additionally, most modern phones no longer automatically connect to data when plugged in, only power. You usually have to respond to a prompt or make a selection on the device to do more than charge. Needless to say, don’t do that.
Always be careful what you connect your device to, be it your mobile phone, tablet, or laptop.
UEFI/BIOS infection
Technically, this is software, but it’s an update to your hardware: the BIOS in your computer. It’s nearly unnoticeable, and most antivirus programs can’t detect it. You can reformat your machine completely, and the malware will still be there. The only solution, when this happens, is to re-flash (reset the contents of) your computer’s UEFI/BIOS.
If you think your UEFI/BIOS has been infected, it probably has not. Once folks hear about this possibility, they’re very quick to jump to it as a conclusion when malware reappears after a clean rebuild of their machine. What happens much more frequently is simply that they reinstalled the same malicious software they had before.1
Card reader skimmers
While not directly related to the technology you own, this relates to technology you use. Unlike UEFI/BIOS infections, this appears to be somewhat common.
There are malicious devices that can be added to cash machines and credit card machines that read (or “skim”) the information off the card you insert or swipe. When these devices are paired with cameras that record the PIN you type to access your money, the thieves then have enough information to clone your card and access it themselves.
Security researcher Brian Krebs has apparently gotten into the habit of tugging on the card insertion point to make sure it’s not one of these fake devices.
My advice? Tug if you like, but instead:
- Use tap-to-pay if at all possible. It’s not vulnerable to skimming.
- Use only devices in very public places.
- Use only devices you’re personally already familiar with.
- Use them only at stores you already trust.
Or, if possible, pay a real person at the counter. I’m sure they’d love to see you.
Do this
I know it seems like something else to worry about, but it doesn’t really have to be that bad. Just give thought to the ways that hardware can be compromised, and develop habits that don’t put you in risky situations. It really is as simple as that.
Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.
Footnotes & References
1: Seriously. I’ve yet to see this actually happen to anyone who’s come to me claiming it has.



“Cash Machine Skimmers” – Gas pumps can be skimmed too.
Yeah, actually it applies to any device into which you can insert your card.
In articles I’ve read, skimmers are more common on gas station card readers because the security is tighter at banks. Also, I could imagine a higher yield at a gas station as probably more debit/credit cards being used per hour at a gas pump.
“In articles I’ve read, skimmers are more common on gas station card readers because the security is tighter at banks.” – And perhaps too because people are less aware of the problem and so are less vigilant. I seem to remember reading that there are ~50 ATM attacks per year per 1,000 ATMs – which is an alarmingly high number.
I’ve been tugging/checking the slot of every ATM for years after I heard that crooks will attach a device to ATMs to read your card … exactly as you described. And the news report said these devices were found in even the most public of places. So I think I would take Brian Krebs’ advice seriously, not just limit myself to public places because they are also vulnerable.
With regard to public charging stations, will a “charging only” USB cable work to avoid data theft?
It should yes.