Større sikkerhedsfejl afsløre tastetryk på næsten 1 milliard kinesisk pinyin tastatur app-brugere, borger lab finder
A keyboard is supposed to sit on your phone. In China, eight of the nine most popular pinyin keyboards were sending what you typed across the network in a form a stranger could read. Citizen Lab at the University of Toronto published the findings on April 23, 2024, under the title “The not-so-silent type.” Researchers Jeffrey Knockel, Mona Wang, and Zoë Reichert estimated nearly a billion users were exposed.
The vulnerable apps came from Baidu, Honor, iFlytek, OPPO, Samsung, Tencent’s QQ Pinyin, Vivo, and Xiaomi. Huawei was the only one the lab did not find leaking. The report built on Citizen Lab’s August 2023 work on Tencent’s Sogou Input Method. Together those products cover more than 95 percent of China’s third-party keyboard market.
Kineserne har titusinder af karakterer. De fleste mennesker skriver pinyin - latinske bogstaver for mandarin lyde - og lad en Input Metode Editor gætte de rigtige tegn. For at gøre disse gæt, de store tastaturer sende tastetryk til en sky. Det er der, krypteringen mislykkedes. Citizen Lab advares at en passiv eavesdropper på netværket kunne gendanne den indtastede tekst uden at sende en enkelt pakke tilbage til offeret.
- Tencent QQ Pinyin: en CBC padding- oracle angreb, der kunne afsløre indtastet indhold.
- Baidu IME (Windows): en brudt protokol, der lader trafikken dekrypteres.
- iFlytek IME (Android): kryptering for svag til at skjule input.
- Samsung Tastatur (Android): tastetryk data sendt uden kryptering overhovedet.
- Xiaomi, OPPO, Vivo, ære: fabrikstastaturer bygget på Baidu, iFlytek eller Sogou, arver de samme huller.
Homegrown-koder, gamle vaner, nemme at udnytte
The researchers said the bugs were easy to find and easy to use. They did not treat them as deliberate government backdoors. Beijing already has other ways to collect this data, and Chinese regulators have spent years telling vendors to harden software. The more boring explanation is worse: many of these IMEs were written in the 2000s, before TLS was default, and some Chinese developers still refuse Western crypto standards over fears of planted backdoors — then ship homemade ciphers that fall over. Dual_EC_DRBG is the cautionary tale they cited. The result is the same either way: passwords, messages, and searches sitting in the clear for anyone on the path.
As of April 1, 2024, Citizen Lab still had working exploits against Honor and QQ Pinyin. Baidu had patched the worst of it and left other items open. Vivo and Xiaomi never answered the disclosure. The lab told QQ Pinyin users to switch keyboards and Honor owners to disable the preinstalled Baidu IME. It also asked app stores to stop geoblocking security updates.
Det Forenede Kongeriges svar på den samme klasse af billige, utætte apparater er en statut, ikke et forskningspapir. AEGIS Alliance dækkede PSTI Act, der er forbudt gætbare standard adgangskoder på smarte gadgets Samme uge denne rapport landede. For mere om overvågning, lækager, og som faktisk læser din trafik, se vores Hacker News skrivebord og den ældre fil på Wikileaks 'spion filer Rusland-losseplads.










Ja, bare købe æble, de allerede stjæle alle dine data, skære anti alt undtagen USA lort