Connect with us

NEWS

Immurok Fakes a Keyboard to Unlock Mac and Linux

Immurok stays on Bluetooth by posing as a keyboard, then a local fingerprint match drives PAM, sudo, and AI-agent approval on Mac and Linux.

Published

on

Immurok is a $59 wireless fingerprint key that stays on Bluetooth by advertising itself as a keyboard, then unlocks Mac, Linux, and Windows after a local match. The sensor never sends a print. The computer still gets a PAM yes, a Credential Provider ticket, or a password typed from the Keychain.

That split is the whole product. Apple welded Touch ID to its own keyboard. Linux still treats sudo as a password prompt. Coding agents now want both. Super Dog’s desk cube sits in that gap and sells the workaround as hardware.

Pretending to Be a Keyboard Keeps the Radio Alive

The finished unit is a wireless fingerprint key for Mac and Linux in a CNC aluminum body, 44 × 44 × 14.2 mm and about 40 g, with a 110 mAh cell charged over USB-C. Standby draw is about 50 µA, and the company claims a month or more of normal use per charge. The radio is a WCH CH592 RISC-V Bluetooth LE microcontroller, the CH592F, a QingKe V4C part running at 60 MHz with 448 KB of application flash, 26 KB of SRAM, and Bluetooth LE 5.4 in a QFN28 package.

It shows up as a HID keyboard. That profile is the keep-alive, not the vault. macOS and Linux cling to HID keyboards, so a battery gadget that looks like one stays paired without a daemon hammering the radio. Pairing, match events, and challenge-response run on a second, private GATT service with random 128-bit UUIDs.

The host is the policy engine; the device is the proof.

immurok security model, May 28, 2026

A match is not a bare OK byte. The device emits a signed notification, opcode 0x21, a page id, and an 8-byte truncated HMAC-SHA256 tag over the shared pairing key. The app recomputes the tag and drops anything that does not match. On reconnect it also sends an 8-byte nonce and expects the same HMAC back, so a radio that only copies the name fails closed.

The application firmware is public. The BLE link layer is not. WCH ships that stack as the binary library libCH59xBLE.a, which is the usual trade on this chip family: you can read the auth logic, and you cannot read the radio.

Touch ID Stops at Apple’s Own Keyboard

Apple’s compact Magic Keyboard with Touch ID for $149 is the first-party answer for a Mac mini, a Mac Studio, or a closed-lid MacBook. It needs Apple silicon, and it is the keyboard. A mechanical board, a third-party layout, or a Linux tower never gets that sensor. Touch ID is fused to the Secure Enclave, so nobody else can ship a compatible reader.

Linux is not kinder. fprintd and libfprint can drive a laptop’s built-in reader when the vendor is on the supported list, which many Goodix and Synaptics parts are not. They do nothing for a desktop that never had a reader, and they do not follow you to a second machine. sudo, polkit, SSH, and Git signing stay on passwords unless someone wires a new authenticator into PAM.

Immurok’s pitch is that gap, priced under the Apple keyboard and unbound from it. The companion apps are public on GitHub under Apache 2.0, including the macOS and Linux PAM modules and the Windows Credential Provider. Firmware, hardware, and OTA tooling are source-available under Business Source License 1.1, with a change date of March 5, 2030, when they convert to Apache 2.0. Until then the reserved right is selling competing hardware.

What a Touch Unlocks on Mac, Linux, and Windows

On macOS the lock screen cannot take a third-party PAM module, so the companion app types the login password from the Keychain after it verifies a signed match. Linux uses PAM for both sudo and the lock screen, with no host-stored password. Windows uses a Credential Provider on the logon screen. Cold boot still wants the account password on all three, the same way Touch ID does after a restart.

THE THREE UNLOCK PATHS

Platform Screen unlock sudo or admin Password on the host
macOS 13.0 or later App types the login password from Keychain after a signed match PAM module Yes, Keychain only, never over BLE
Linux (Ubuntu, Fedora, Arch, Debian) PAM, same path as sudo PAM and polkit No stored password
Windows 10 and 11 Credential Provider Credential Provider Not a Keychain-style stash in the public docs

The macOS app needs Accessibility permission because that lock-screen path is simulated typing. The login secret never crosses Bluetooth; the radio only carries the signed proof that page N matched. Linux skips the stash entirely. If Bluetooth is off or the gadget is dead, sudo and the lock screen fall back to the normal password field, which is the difference between a convenience key and a lockout.

Firmware 1.7 and later can bind two computers at once. A dedicated switch fingerprint moves the radio between them, which is the dual-host path for a desk that has a Mac and a Linux box. SSH private keys, up to 32 ECDSA P-256 pairs, stay on the device and are signed there. TOTP holds 128 seeds. An API vault holds 50 strings, released only under an active fingerprint cooldown.

Agents Get a Physical Veto or the Command Dies

The same signed touch is now a gate for coding agents. Wrap a command with imk run --agent -- and the companion app pops an overlay with the verbatim line, not a summary. One approved finger opens a 5-minute sudo pre-auth and satisfies SSH signing and secret reads for that subprocess only. Secrets are injected into the child environment at exec time, so they are not supposed to land in the agent’s transcript or on disk.

WHAT ONE AGENT TOUCH APPROVES

  • The overlay: The HUD shows the exact command plus any imk:// URIs, with no paraphrase.
  • The window: One match covers sudo, SSH signing, and vault reads for that single subprocess, with a 5-minute sudo pre-auth.
  • The kill: Dismiss the overlay, or wait 30 seconds, and the subprocess gets SIGTERM and the agent exits 77 (EX_NOPERM).
  • The fallback: There is no silent drop back to a typed password for the wrapped command. No touch means no privileged action.

That last rule is the part that matches the moment. A standing sudo credential is hard to take back once an agent has it. A finger on the desk is a veto you can refuse, and a command you can read before it runs. The stronger the agent, the more that physical release is doing real work, because the alternative is pasting your password into a tool that will happily reuse it.

It is also a weaker secret in another sense. A password can stay in someone’s head. A finger on a gadget on the desk can be pressed. In places where police can compel a biometric unlock, this class of key does not give you the same refusal path as a memorized phrase. Immurok does not claim otherwise. It claims the host decides policy and the device only proves a touch.

The Sensor Matches On-Chip, and the Case Wipes Itself

Scanning is an R559S capacitive module, 508 DPI, 8.0 × 8.0 mm, match in under 500 ms, talking UART at 57600 baud. Templates live in the sensor’s own flash. The CH592F only hears page N matched, or no match. The module can hold 29 templates; the product exposes 5 auth slots plus one host-switch slot. Enrollment merges 12 captures. Vendor figures are a false-acceptance rate under 0.001% and a false-rejection rate under 1%.

ON THE DESK

  • Match path: R559S on-chip compare, MCU never sees an image or template.
  • Pairing: ECDH over NIST P-256, then HKDF-SHA256; scalar multiply takes about 2 seconds on this chip, and a 30-second button window aborts if you walk away.
  • OTA: AES-128-CTR image plus HMAC-SHA256, dual A/B slots, unofficial firmware discarded before it boots.
  • Cooldown: Signing, deletion, and factory reset need a fresh biometric proof with a 10-second cooldown.

Those on-chip matching and signed GATT events only help if the threshold is pinned. An early build left the sensor score at the module’s lax default and skipped a second check in firmware, which let unenrolled fingers pass now and then. Firmware 1.3.14 sets the score in the build and re-validates the match index before it signs. That is the honest version of “local match”: it is as strict as the firmware that wraps the vendor blob.

Physical theft is treated as its own case. A device that already holds a shared key refuses new BLE bonds, so a thief cannot pair it to another machine without a wipe. A spring contact on the latest board, hardware version 6, trips when the case opens. Firmware writes a case_opened marker first, then erases the pairing key, the on-device keystore, BLE bonds, and every template. If power dies mid-erase, boot sees the marker and finishes the wipe before anything else. A high-voltage strike on the sensor, the glitch used on some cheap fingerprint locks, takes the same erase path. That tamper response was validated in June 2026. A 10-second button hold is the intentional factory reset, and it is not reversible.

Ubuntu Testing Tripped Over Pairing and PAM

A week-long test of a pre-release unit on Ubuntu 26.04 found the core paths work after you fight the client. Windows and macOS ship graphical apps. Linux was a Rust daemon, a CLI, and a terminal UI, built from source, with no distro packages and about 200 crates to compile. make check-deps listed missing pieces. That is fine for someone who already lives in a toolchain, and it is a lot of friction for a gadget sold as a replacement for typing sudo.

Pairing exposed two states the UI did not explain. The tester had to connect the device in Ubuntu’s Bluetooth panel first, then run Immurok’s own pairing and press the button. Connected over Bluetooth is not paired inside the app. Enrollment into slot zero asked for 12 captures and behaved. Adding another finger correctly required an already enrolled finger to approve, which the screen did not always say.

sudo failed until a race was patched. At session start the daemon asked the device for status with a 5-second timeout, while a Python notification helper took about 5.2 seconds to claim D-Bus, leaving the daemon in NO_STATUS for the rest of the session. Raising the limit to 15 seconds made sudo apt update accept a touch. The project later shipped that fix. After the patch, a locked Ubuntu session opened on a touch. The display-manager login after a cold boot did not, by design. Battery on the Linux TUI went from 84% to 78% in roughly a week, a 6-point drop that is friendly to the month-long claim and too short to prove it.

SSH was the cleanest extra. The device generated an ECDSA P-256 key, exported the public half, and signed a login to a Raspberry Pi after a touch. Existing host keys stayed as fallback, so servers that did not have the new public key kept working. Import only accepted ECDSA P-256, so Ed25519 and RSA keys could not move over. TOTP for GitHub released a code after a touch and verified. Dual-host showed up in the TUI after a firmware update and was not fully proven across two machines in that test.

Kickstarter Closes September 22 at $59

The assembled Silver Edition is $59 on Kickstarter and $69 at retail, a $10 cut, with no subscription and no account. Super Dog opened the Kickstarter campaign ending September 22, 2026, at 9:59 AM EDT. The page showed $335,610 pledged by 4,126 backers against a $2,364 goal. Estimated delivery is November 2026. A 50-unit pilot is already built; the campaign is paying for mass production, not a first prototype. Early-bird tiers had sold out. Shipping, VAT, and duty sit on top of the pledge.

THE BUILD CALENDAR

  1. May 28, 2026: Security model posted, including the HID keep-alive and the macOS typing fallback.
  2. June 2026: Tamper-switch revision validated on the production board.
  3. July 3, 2026: Public write-up of the CH592F and R559S build for Mac and Linux terminals.
  4. August 18, 2026: Kickstarter opens. Super Dog, posting as @immurok_dev, wrote, “We’re live! The immurok Kickstarter campaign has officially launched.”
  5. September 12, 2026: Week-long Ubuntu 26.04 test of a pre-release unit, with the sudo race already patched upstream.
  6. September 22, 2026: Campaign ends.
  7. November 2026: Estimated delivery to backers.
  8. March 5, 2030: Firmware and hardware license converts to Apache 2.0.

The $149 Apple keyboard still owns Touch ID on Apple silicon, and it will keep owning Apple Pay and the Secure Enclave. Immurok is not that. It is a signed radio and a PAM module that exist because desktop Unix never grew a first-class biometric, and because a closed-lid Mac with someone else’s keyboard has nowhere to put a finger. The campaign is still open through September 22, 2026, while Linux packaging and the first-login gap remain unfinished work for the November units.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending