وكشفت العيوب الأمنية الرئيسية عن وجود مفاتيح لحوالي بليون من مستعملي الأجهزة الرئيسية الصينيين، وخلصت مختبرات المواطنين
A keyboard is supposed to sit on your phone. In China, eight of the nine most popular pinyin keyboards were sending what you typed across the network in a form a stranger could read. Citizen Lab at the University of Toronto published the findings on April 23, 2024, under the title “The not-so-silent type.” Researchers Jeffrey Knockel, Mona Wang, and Zoë Reichert estimated nearly a billion users were exposed.
The vulnerable apps came from Baidu, Honor, iFlytek, OPPO, Samsung, Tencent’s QQ Pinyin, Vivo, and Xiaomi. Huawei was the only one the lab did not find leaking. The report built on Citizen Lab’s August 2023 work on Tencent’s Sogou Input Method. Together those products cover more than 95 percent of China’s third-party keyboard market.
الصينيون لديهم عشرات الآلاف من الشخصيات ومعظم الناس يطبعون الدبابيسين - رسائل لاتينية لصوت ماندرين - ويسمحون لمحرر طرق المدخلات أن يُخمّن الشخصيات الصحيحة. لجعل تلك التخمينات لوحات المفاتيح الكبيرة تشحن المفاتيح إلى سحابة هذا هو المكان الذي فشل فيه التشفير مركز المواطن تحذير أن النسيج السلبي على الشبكة يمكن أن يستعيد النص المطبع دون إرسال عبوة واحدة إلى الضحية.
- نقطة البداية: هجوم على الرصيف يمكن أن يكشف المحتوى المطبوع
- Bidu IME (Windows): نظام تقليدي مكسّر يسمح بفك التشفير
- ? التشفير ضعيف جدا لإخفاء المدخلات.
- لوحة مفاتيح سامسونغ (أندرويد): بيانات السرب المرسل بدون تشفير على الإطلاق
- شياومي، أوبو، فيفو، الشرف: لوحات مفاتيح المصنع التي بُنيت على بيدو، أيفليتيك، أو سوجو، ورثت نفس الثقوب.
الشفرة المنزلية، العادات القديمة، الاستغلال السهل
The researchers said the bugs were easy to find and easy to use. They did not treat them as deliberate government backdoors. Beijing already has other ways to collect this data, and Chinese regulators have spent years telling vendors to harden software. The more boring explanation is worse: many of these IMEs were written in the 2000s, before TLS was default, and some Chinese developers still refuse Western crypto standards over fears of planted backdoors — then ship homemade ciphers that fall over. Dual_EC_DRBG is the cautionary tale they cited. The result is the same either way: passwords, messages, and searches sitting in the clear for anyone on the path.
As of April 1, 2024, Citizen Lab still had working exploits against Honor and QQ Pinyin. Baidu had patched the worst of it and left other items open. Vivo and Xiaomi never answered the disclosure. The lab told QQ Pinyin users to switch keyboards and Honor owners to disable the preinstalled Baidu IME. It also asked app stores to stop geoblocking security updates.
جواب المملكة المتحدة لنفس الفئة من الأجهزة الرخيصة والمتسربة هو نظام أساسي وليس ورقة بحث تحالف الأغس غطى PSTI القانون الذي يحظر كلمة سر غير قابلة للتخمين على الأدوات الذكية في نفس الأسبوع هبط هذا التقرير من أجل المزيد من المراقبة، التسرب، ومن يقرأ في الواقع زحام المرور الخاص بك، نرى لدينا أخبار هاكر المكتب والملف القديم ملفات التجسس الخاصة بـ(ويكيليكس).










نعم، فقط يَشتري التفاحَ، هم يَسْرقونَ كُلّ بياناتِكَ، يَصْرفونَ مضادَ كُلّ شيءَ لكن الولايات المتحدة الأمريكيةَ حماقة