We in Telegram
Add news
March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010
November 2010
December 2010
January 2011
February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024
1 2 3 4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
News Every Day |

Almost every Chinese keyboard app has a security flaw that reveals what users type

Almost all keyboard apps used by Chinese people around the world share a security loophole that makes it possible to spy on what users are typing. 

The vulnerability, which allows the keystroke data that these apps send to the cloud to be intercepted, has existed for years and could have been exploited by cybercriminals and state surveillance groups, according to researchers at the Citizen Lab, a technology and security research lab affiliated with the University of Toronto.

These apps help users type Chinese characters more efficiently and are ubiquitous on devices used by Chinese people. The four most popular apps—built by major internet companies like Baidu, Tencent, and iFlytek—basically account for all the typing methods that Chinese people use. Researchers also looked into the keyboard apps that come preinstalled on Android phones sold in China. 

What they discovered was shocking. Almost every third-party app and every Android phone with preinstalled keyboards failed to protect users by properly encrypting the content they typed. A smartphone made by Huawei was the only device where no such security vulnerability was found.

In August 2023, the same researchers found that Sogou, one of the most popular keyboard apps, did not use Transport Layer Security (TLS) when transmitting keystroke data to its cloud server for better typing predictions. Without TLS, a widely adopted international cryptographic protocol that protects users from a known encryption loophole, keystrokes can be collected and then decrypted by third parties.

“Because we had so much luck looking at this one, we figured maybe this generalizes to the others, and they suffer from the same kinds of problems for the same reason that the one did,” says Jeffrey Knockel, a senior research associate at the Citizen Lab, “and as it turns out, we were unfortunately right.”

Even though Sogou fixed the issue after it was made public last year, some Sogou keyboards preinstalled on phones are not updated to the latest version, so they are still subject to eavesdropping. 

This new finding shows that the vulnerability is far more widespread than previously believed. 

“As someone who also has used these keyboards, this was absolutely horrifying,” says Mona Wang, a PhD student in computer science at Princeton University and a coauthor of the report. 

“The scale of this was really shocking to us,” says Wang. “And also, these are completely different manufacturers making very similar mistakes independently of one another, which is just absolutely shocking as well.”

The massive scale of the problem is compounded by the fact that these vulnerabilities aren’t hard to exploit. “You don’t need huge supercomputers crunching numbers to crack this. You don’t need to collect terabytes of data to crack it,” says Knockel. “If you’re just a person who wants to target another person on your Wi-Fi, you could do that once you understand the vulnerability.” 

The ease of exploiting the vulnerabilities and the huge payoff—knowing everything a person types, potentially including bank account passwords or confidential materials—suggest that it’s likely they have already been taken advantage of by hackers, the researchers say. But there’s no evidence of this, though state hackers working for Western governments targeted a similar loophole in a Chinese browser app in 2011.

Most of the loopholes found in this report are “so far behind modern best practices” that it’s very easy to decrypt what people are typing, says Jedidiah Crandall, an associate professor of security and cryptography at Arizona State University, who was consulted in the writing of this report. Because it doesn’t take much effort to decrypt the messages, this type of loophole can be a great target for large-scale surveillance of massive groups, he says.

After the researchers got in contact with companies that developed these keyboard apps, the majority of the loopholes were fixed. But a few companies have been unresponsive, and the vulnerability still exists in some apps and phones, including QQ Pinyin and Baidu, as well as in any keyboard app that hasn’t been updated to the latest version. Baidu, Tencent, iFlytek, and Samsung did not immediately reply to press inquiries sent by MIT Technology Review.

One potential cause of the loopholes’ ubiquity is that most of these keyboard apps were developed in the 2000s, before the TLS protocol was commonly adopted in software development. Even though the apps have been through numerous rounds of updates since then, inertia could have prevented developers from adopting a safer alternative.

The report points out that language barriers and different tech ecosystems prevent English- and Chinese-speaking security researchers from sharing information that could fix issues like this more quickly. For example, because Google’s Play store is blocked in China, most Chinese apps are not available in Google Play, where Western researchers often go for apps to analyze. 

Sometimes all it takes is a little additional effort. After two emails about the issue to iFlytek were met with silence, the Citizen Lab researchers changed the email title to Chinese and added a one-line summary in Chinese to the English text. Just three days later, they received an email from iFlytek, saying that the problem had been resolved.

Москва

Диетолог Макиша: витамин К в ряде случаев может привести к образованию тромбов

5 Things To Remember When A Friendship Ends

5 Things EVERY Ripped Guy Does (COPY THESE)

13 Crops You'd Be INSANE Not To Plant in May

Online Alarm Clock for efficient time management

Ria.city






Read also

Report: Darvin Ham’s firing ‘not a LeBron James issue’

'The Idea of You' director Michael Showalter explains why he changed the book's controversial ending

Kawamitsu and Toyoshima pick up title wins at Korakuen Hall

News, articles, comments, with a minute-by-minute update, now on Today24.pro

News Every Day

Online Alarm Clock for efficient time management

Today24.pro — latest news 24/7. You can add your news instantly now — here


News Every Day

13 Crops You'd Be INSANE Not To Plant in May



Sports today


Новости тенниса
Даниил Медведев

Медведев сыграет с Бубликом в Мадриде 



Спорт в России и мире
Москва

Источник 360.ru: в районе Чертаново Южное в Москве загорелся ангар



All sports news today





Sports in Russia today

Москва

В поселке Калининец состоялся этап Чемпионата и Первенства Москвы и МО по кроссу «Кубок Kramar Motorsport»


Новости России

Game News

Бета-тест Figment 2: Creed Valley на iOS открыли для 100 человек


Russian.city


Москва

Кремль: Рахмон приглашен в Москву на празднование Дня Победы


Губернаторы России
Казахстан

Тверская область: ввозили хлопок из Казахстана, саженцы из Германии


Продвижение новых песен с высоким результатом

Участники фестиваля антифашисткой песни «Гитары в строю!» записали манифест

Магнитная буря 2 мая может спровоцировать северное сияние в Москве

Шор заявил о проверках без оснований пассажиров из России в аэропорту Кишинева


Цирковая артистка Бурятии Аригма Цыремпилова - девочка-каучук (Россия, Культура, Театр и Дети)

Deep Purple представили первую композицию из нового альбома

Linkin Park воссоединяются и едут в тур. Место Честера Беннингтона займет неизвестная вокалистка

Культура России: как прошёл конкурс бурятского языка для детей в Бурятии?


Свентек стала первой полуфиналисткой турнира WTA-1000 в Мадриде

Российский теннисист Рублев вышел в финал турнира «Мастерс» в Мадриде

Соболенко вышла в полуфинал турнира WTA-1000 в Мадриде

Медведев сыграет с Бубликом в Мадриде 



Планетарий: условия для наблюдения Майских Акварид благоприятные, новолуние

Форум Доноров представил результаты первой лаборатории проекта «Музеи и меценаты»

В Москве и Подмосковье ударили первые майские заморозки

Вадим Арутюнов и его книга «Записки странствующего армянина»


Страх Рахмона: Таджикистан получит экономический коллапс и уличные бунты

«Спартак» обыграл «Динамо» 2:0 в полуфинале Пути регионов Кубка России

"Балтика" сыграет со "Спартаком" в финале Пути регионов Кубка России

Фонд «Восход» инвестировал в российский проект SaaS-платформы на основе ИИ Syntelly


Президент Таджикистана поедет в Москву на Парад Победы

Забег по пересеченной местности «Лига героев» прошел в Одинцове

«Я восстанавливаюсь!»: Куклачев обратился к своим поклонникам

Предправления «Зенита» ответил поговоркой на вопрос про бюджет



Путин в России и мире






Персональные новости Russian.city
Концерт

Концерт «Пасхальная радость» пройдет в Музеях Московского Кремля



News Every Day

5 Things EVERY Ripped Guy Does (COPY THESE)




Friends of Today24

Музыкальные новости

Персональные новости