objective-see / ReiKey

Malware and other applications may install persistent keyboard "event taps" to intercept your keystrokes. ReiKey can scan, detect, and monitor for such taps!
GNU General Public License v3.0
326 stars 36 forks source link

gamecontrollerd (/usr/libexec/gamecontrollerd) triggers ReiKey #14

Open h-spiess opened 3 years ago

h-spiess commented 3 years ago

Hey,

First of all, thank you for all your nice work on MacOS security. I really appreciate that.

Since updating to the newest version of MacOS 11.3, ReiKey (v.1.4.1) complains about gamecontrollerd (/usr/libexec/gamecontrollerd). After googling it seems that gamecontrollerd is from the OS itself and should probably be ignored if the setting "Ignore Apple Programs" is set. Correct me if i'm wrong. For now I disabled alerts manually.

Thanks :)

jawiv commented 3 years ago

Yes. I'm getting gamecontrollerd alerts every minute or so. Takes focus away from whatever program I'm typing in.

marcel-bluestone commented 3 years ago

I experience the same thing and it is really really annoying, as typing this text alone had me regain focus on the window text input-form three times. It seems gamecontrollerd is not considered to be an Apple process.

proton1k commented 3 years ago

I've encountered the same issue. I found that gamecontrollerd for many users was never launched prior update of MacOS to Big Sur. I wonder how it might be related. I also have doubts regarding the Game Controller daemon lanched here and there just because of Chrome or an Electronjs. Yet here's the tricky question: if it's not really needed and the user never plays games, can it be shut down forever without troubled consequences for the OS?

If gamecontrollerd is passively listening to the keyboard tapping and might pass it to some 3rd-party app, imagine it's a web browser with a 3rd-party Javascript loaded, can a script request the information from this daemon or not?

egrueter-dev commented 2 years ago

I am having usr/libexec/relatived come up as a keylogger with passive listening permissions. Is this malware?

utkonos commented 2 years ago

In the ReiKey preferences, there is a setting Ignore Apple Programs. For me, this has removed gamecontrollerd from the listing when a scan is performed. I have not seen the annoying alert either since I make this change to preferences.

prefs