Technology Almost Every Chinese Keyboard App Has a Security Flaw...

-

Almost Every Chinese Keyboard App Has a Security Flaw That Reveals What Users Type

Almost Every Chinese Keyboard App Has a Security Flaw That Reveals What Users Type

An anonymous reader quotes a report from MIT Technology Review: Almost all keyboard apps used by Chinese people around the world share a security loophole that makes it possible to spy on what users are typing. The vulnerability, which allows the keystroke data that these apps send to the cloud to be intercepted, has existed for years and could have been exploited by cybercriminals and state surveillance groups, according to researchers at the Citizen Lab, a technology and security research lab affiliated with the University of Toronto.

These apps help users type Chinese characters more efficiently and are ubiquitous on devices used by Chinese people. The four most popular apps — built by major internet companies like Baidu, Tencent, and iFlytek — basically account for all the typing methods that Chinese people use. Researchers also looked into the keyboard apps that come preinstalled on Android phones sold in China. What they discovered was shocking. Almost every third-party app and every Android phone with preinstalled keyboards failed to protect users by properly encrypting the content they typed. A smartphone made by Huawei was the only device where no such security vulnerability was found.

In August 2023, the same researchers found that Sogou, one of the most popular keyboard apps, did not use Transport Layer Security (TLS) when transmitting keystroke data to its cloud server for better typing predictions. Without TLS, a widely adopted international cryptographic protocol that protects users from a known encryption loophole, keystrokes can be collected and then decrypted by third parties. Even though Sogou fixed the issue after it was made public last year, some Sogou keyboards preinstalled on phones are not updated to the latest version, so they are still subject to eavesdropping. […] After the researchers got in contact with companies that developed these keyboard apps, the majority of the loopholes were fixed. But a few companies have been unresponsive, and the vulnerability still exists in some apps and phones, including QQ Pinyin and Baidu, as well as in any keyboard app that hasn’t been updated to the latest version.

Read more of this story at Slashdot.

News for nerds, stuff that matters
Source : https://it.slashdot.org/story/24/04/24/2337208/almost-every-chinese-keyboard-app-has-a-security-flaw-that-reveals-what-users-type?utm_source=rss1.0mainlinkanon&utm_medium=feed

Latest news

More than half of the Fortune 100 uses Apple’s Vision Pro headset

Spatial computing in the industrial metaverse appears to be paying off for the company that Steve Jobs...

Every Cool Thing Announced for Star Wars Day 2024: From Funko to Limited-Edition Loungefly – CNET

Every Cool Thing Announced for Star Wars Day 2024: From Funko to Limited-Edition Loungefly -...

Despite Recalls, Air Fryers Are Safe if You Follow These Basic Safety Rules – CNET

Despite Recalls, Air Fryers Are Safe if You Follow These Basic Safety Rules - CNET Recalls...

Therapy Out of Reach? 4 Ways to Improve Your Mental Health for Free – CNET

Therapy Out of Reach? 4 Ways to Improve Your Mental Health for Free - CNET There...

Are You Applying Enough Sunscreen? A Dermatologist Weighs In – CNET

Are You Applying Enough Sunscreen? A Dermatologist Weighs In - CNET You need to wear more...

The Maze Runner Movies are Running Towards a Reboot

The Maze Runner Movies are Running Towards a Reboot It’s now been five years since Disney bought 20th Century Fox,...
Advertisement

Must read

Advertisement

You might also likeRELATED
Recommended to you