हैकर न्यूज़अंतर्राष्ट्रीय समाचारNews

Eight of Nine Chinese Pinyin Keyboards Let Eavesdroppers Read What Nearly a Billion People Typed

The keyboard on a phone sold in China is not a piece of glass with letters on it. It is a cloud service. On April 23, 2024, Citizen Lab at the University of Toronto published Report No. 175, “The not-so-silent type,” by Jeffrey Knockel, Mona Wang, and Zoë Reichert. They had pulled cloud-based pinyin keyboards from nine vendors between August and November 2023: Baidu, Honor, Huawei, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi. Eight of the nine had at least one app in which a passive eavesdropper on the network could recover everything a person typed. Huawei was the exception in the versions they tested. Combined with the lab’s August 2023 findings on Tencent’s Sogou Input Method, the researchers estimated that up to a billion users sat inside the blast radius. That figure is an estimate of exposure, not a head count of people whose chats were confirmed stolen.

Chinese has tens of thousands of characters. Most people type pinyin, Latin letters for Mandarin sounds, and an input method editor guesses the characters. The guess is better if a server sees what you have typed so far, so the big keyboards ship keystrokes to a cloud. That hop is the entire attack. Citizen Lab’s report and the plain-language FAQ that came with it said an internet provider, a VPN operator, or another user on the same Wi-Fi could read the traffic without installing anything on the phone and without sending a packet back. Knockel told MIT Technology Review the lab went looking because Sogou had been so easy. “Because we had so much luck looking at this one, we figured maybe this generalizes to the others, and they suffer from the same kinds of problems for the same reason that the one did,” he said, “and as it turns out, we were unfortunately right.”

What Each Vendor Actually Shipped

The failures were not one bug copied nine times. They were a family of bad habits.

  • Tencent QQ Pinyin. Android 8.6.3 and Windows 6.6.6304.400 talked to cloud servers in the same family as Sogou and inherited the same CBC padding-oracle flaw. A padding oracle lets an attacker turn a “decrypt this” error into the original text. Tencent told researchers it aimed to move EncryptWall requests to HTTPS by the end of the first quarter of 2024, except for end-of-life products. Sogou was updated. QQ Pinyin, which had not received an update since 2020 and was still offered for download, was not.
  • Baidu IME. The Windows app used a homemade protocol, BAIDUv3.1, that Citizen Lab could decrypt. The design generated an “AES” key in a way that amounted to a hardcoded secret, then sometimes ran a modified AES with extra permutations or a missing round. Security through obscurity, written down. Android and iOS builds had their own broken variants. Baidu’s cloud hosts in the report included UDP endpoints at baidu.com.
  • iFlytek on Android. Encryption too weak to hide what was typed. iFlytek later fixed the issues the lab reported.
  • Samsung Keyboard on Android. In the tested build, keystroke data went out with no encryption at all. Samsung later fixed its own keyboard. Bundled Baidu software on Samsung devices was a separate problem.
  • Xiaomi, OPPO, Vivo, and Honor. Factory keyboards built on Sogou, Baidu, or iFlytek, so the hole shipped in the box. Honor’s default was a Baidu build. Honor told Citizen Lab to take the disclosure to Baidu, which the lab had already done.

Jedidiah Crandall, a computer scientist at Arizona State University who was not an author of the report, put the consequence in one line for IEEE Spectrum: “Whatever Chinese-language users of your app might have typed into it has been exposed for years.” Passwords, chat, search boxes, payment fields. The keyboard does not know which of those is a secret. It only knows characters.

Not a Backdoor. A Cipher From the 2000s.

Citizen Lab did not call these deliberate government backdoors. Beijing has other ways to collect this data, and Chinese regulators have spent years telling vendors to harden software. The duller explanation is the one that should worry anyone who types on a phone. Many of these input methods were written before TLS was the default. Some developers still refuse widely used Western cryptographic standards because of a real history of standards that were poisoned. Dual_EC_DRBG, the random-number generator later shown to contain a backdoor, is the example the researchers cite. The substitute was worse: a homemade cipher that falls over in a student lab. The Five Eyes intelligence alliance has previously exploited similar holes in Chinese apps. Citizen Lab said it was possible the same class of bug had already been used for mass collection of keystrokes. That is a possibility the report states, not a claim that a named agency was sitting on these particular servers.

The disclosure scorecard, measured again as of April 1, 2024, and restated when the work was published at the ACM Conference on Computer and Communications Security in October 2024, is more precise than “the companies patched it.” iFlytek, OPPO, and Samsung moved vulnerable paths toward TLS and fixed what the lab could exploit. Vivo, Xiaomi, and Baidu did not answer the disclosure emails, but later testing showed Vivo and Xiaomi had updated. Baidu fixed the worst of the Windows flaw and then switched to a different proprietary protocol instead of TLS. Citizen Lab said it no longer had a full working decrypt against those updated Baidu apps, and it also said the remaining cryptography was still weak enough that people should not trust it. The two products the lab could still exploit on that date were Honor’s preinstalled Baidu keyboard and Tencent’s QQ Pinyin.

Baidu later told some reporters that the Honor-customized build had been fixed in September 2023 and pushed out with operating-system updates. Citizen Lab’s April 1, 2024, retest still had a working exploit against Honor’s default keyboard. Both statements can be printed. They cannot both describe the same phone if that phone never received the update. Geoblocked app stores are how that happens. A security fix that is withheld from the country where the keyboard is the default is not a fix. It is a press release. Citizen Lab asked stores to stop geoblocking security updates. The lab has not published a 2025 or 2026 retest of these nine vendors, so the April 2024 scorecard is the last laboratory snapshot, not a certificate that every phone in a drawer has been patched.

Knockel and Wang walked through the same attacks on the DEF CON 32 stage in Las Vegas on August 11, 2024, in a talk whose title dropped the politeness: breaking network crypto in almost every popular Chinese keyboard app. The recording is the version of the paper a person can watch. It does not change the April 1 scorecard. It does make the attack less abstract. A padding oracle and a hardcoded key are not theoretical once someone decrypts a sentence live.

DEF CON 32 - Breaking network crypto in popular Chinese keyboard apps - Jeffrey Knockel, Mona Wang

The practical advice from the FAQ is short. QQ Pinyin users should switch keyboards. Honor owners should turn off the preinstalled Baidu input method and use something else. Anyone still on a Sogou, Baidu, or iFlytek keyboard, including the copy that came with the phone, should update the app and the operating system and then assume the old traffic is already gone. Cloud prediction is a product feature. It is also a decision to put every sentence on a wire. The same week Citizen Lab published, The AEGIS Alliance covered the United Kingdom’s Product Security and Telecommunications Infrastructure Act, which banned guessable default passwords on cheap connected gadgets. A statute can ban a default password. It cannot retrofit a cipher that was never TLS. For the surveillance files that sit next to this one, see The AEGIS Alliance’s हैकर न्यूज़ desk, the WikiLeaks Spy Files Russia dump, and the later report on Google tearing down a shadow network that had been using phones’ internet connections.

Jeffrey Childers
पत्रकार, संपादक, साइबर सुरक्षा और कंप्यूटर विज्ञान विशेषज्ञ, सोशल मीडिया प्रबंधन, छत ठेकेदार।

संबंधित लेख

One Comment

Back to top button
हमारे समाचार और समाचार पत्रों के लिए साइनअप करें!

न्यूज़लेटर फॉर्म

सूची
बंद लिंक