Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.

  • @[email protected]
    link
    fedilink
    English
    1092 years ago

    It’s stories like this that don’t surprise me as much as make me ask: How the fuck do you store and process this much data to get anything useful out of it.

    • toofpic
      link
      fedilink
      English
      642 years ago

      You just save the first 50 digits typed after some email is typed, and you have all the passwords you need!

      • @[email protected]
        link
        fedilink
        English
        42 years ago

        This only applies if a username is a email

        And if it is then what happens when people actually email someone? Autocorrect during login?

        • @[email protected]
          link
          fedilink
          English
          11
          edit-2
          2 years ago

          I don’t think they’re saying that method would yield 100% clean data but it would give you all the “necessary” data with the absolute bare minimum storage requirement. At some point people will log into their email and for most people if you have their email password you have the password they use for everything

          • toofpic
            link
            fedilink
            English
            22 years ago

            Yep, I only reacted to a “new requirement”: save space :)

      • TheEntity
        link
        fedilink
        72 years ago

        Did you ever see how an average person types? It’s not the amount of data that is the problem. We have too much dumb data!

      • @[email protected]
        link
        fedilink
        English
        52 years ago

        The real answer is compute power. At the moment it’s very expensive to run the computations necessary for big LLMs, I’ve heard some companies are even developing specialized chips to run them more efficiently. On the other hand, you probably don’t want your phone’s keyboard app burning out the tiny CPU in it and draining your battery. It’s not worth throwing anything other than a simple model at the problem.

    • @[email protected]
      link
      fedilink
      English
      442 years ago

      I could be wrong, and this is a generalization of any country you can name, but my impression is data is stored on everyone so when they decide someday to look you up they already have all the data collected. It’s not really processed until needed.

    • @[email protected]
      link
      fedilink
      English
      22 years ago

      you just look for users that have power in their governments. Getting a senators username/password would be invaluable to china

    • @[email protected]
      link
      fedilink
      English
      22 years ago

      The article states the software users external endpoints, whether encrypted or not. The CCP already has the ability to obtain all of this information from those endpoints. The article identified poor software design choices that may expose user keyboard data to anybody on the network…

  • @[email protected]
    link
    fedilink
    English
    322 years ago

    This is news? I would have been extremely surprised if it wasnt. This is normal for China, the CCP is eavesdropping on everything

  • @[email protected]
    link
    fedilink
    English
    52 years ago

    Looks like very few people have actually read the article, and that the cancerous anti-China sentiment migrated from reddit to lemmy too.

  • @[email protected]
    link
    fedilink
    English
    392 years ago

    These findings underscore the importance for software developers in China to use well-supported encryption implementations such as TLS instead of attempting to custom design their own.

    lol.

    • JJROKCZ
      link
      fedilink
      English
      112 years ago

      The writer out here acting like this wasn’t an intended feature lol

    • @[email protected]
      link
      fedilink
      English
      12 years ago

      And this is the only point of the article. Idk what all these other comments are on about, but this article is outlining lack of standardized protocols that made the software vulnerable to network eavesdropping.

      This doesn’t point to a big CCP conspiracy, it’s just bad design.

  • @[email protected]
    link
    fedilink
    English
    22 years ago

    Hmm…

    I use AnySoftKeyboard instead of the default android keyboard or the Samsung keyboard just to preemptively avoid these kind of “issues” creeping up in the future.

    Should I still be worried?

    Is there a way to sandbox or scope the software keyboards to never see the network (wired ethernet, Wi-Fi, LTE, 5G or otherwise) on stock Android 13 ?

    Other than:

    Settings > Connections > Data Usage >

    Allowed networks for apps > {app} > Wi-Fi only (and not use Wi-Fi) or Mobile data only (and not use Mobile data)

    and

    Mobile data usage > {app} > Allow background data usage > Disabled

    Moreover, there is no “Network Permissions” setting option from what I can see even within Permission manager > Additional permissions.

  • @[email protected]
    link
    fedilink
    English
    582 years ago

    I don’t get it? Why are they talking in the article about not using the right type of encryption. The problem isn’t the encryption, but the fact that it is sending your keystrokes to the mothership, right?

      • @[email protected]
        link
        fedilink
        English
        12 years ago

        Apparently they’ve been caught up in working on predictions for a good while which has been harder than they expected, so that’s slowed development and releases considerably. So not abandoned by the devs for what its worth.

        • nudny ekscentryk
          link
          fedilink
          English
          22 years ago

          Perhaps. The last update is from June 2022 and the last contribution is 3 months old

    • panCatE
      link
      fedilink
      English
      22 years ago

      I wish the development was active , i been using florisboard since years now

        • panCatE
          link
          fedilink
          English
          12 years ago

          Tbh i started using florisboard coz i found word suggestions on google board very scary , it felt like they been tapping each word typed by me ! Florisboard is nicely customizable , although auto correct would be a nice feature to have !

  • @[email protected]
    link
    fedilink
    English
    32 years ago

    If it’s a app, including fucking tik tok you bunch of morons, that was developed by a Chinese company all of the data on your device is going back to the CCP. It’s just that fucking simple people.

  • reflex
    link
    fedilink
    32
    edit-2
    2 years ago

    Jeremy Clarkson:
    The Chinese are very good at this sort of thing.

  • @[email protected]
    link
    fedilink
    English
    92 years ago

    So when the Chinese do it it’s scary, but when the Americans do it it’s just “established practice”?