Hacker NewsInternational NewsNews

Major Security Flaws Expose Keystrokes of Nearly 1 Billion Chinese Pinyin Keyboard App Users, Citizen Lab Finds

A keyboard is supposed to sit on your phone. In China, eight of the nine most popular pinyin keyboards were sending what you typed across the network in a form a stranger could read. Citizen Lab at the University of Toronto published the findings on April 23, 2024, under the title “The not-so-silent type.” Researchers Jeffrey Knockel, Mona Wang, and Zoë Reichert estimated nearly a billion users were exposed.

The vulnerable apps came from Baidu, Honor, iFlytek, OPPO, Samsung, Tencent’s QQ Pinyin, Vivo, and Xiaomi. Huawei was the only one the lab did not find leaking. The report built on Citizen Lab’s August 2023 work on Tencent’s Sogou Input Method. Together those products cover more than 95 percent of China’s third-party keyboard market.

Chinese has tens of thousands of characters. Most people type pinyin — Latin letters for Mandarin sounds — and let an Input Method Editor guess the right characters. To make those guesses, the big keyboards ship the keystrokes to a cloud. That hop is where the encryption failed. Citizen Lab warned that a passive eavesdropper on the network could recover the typed text without sending a single packet back to the victim.

  • Tencent QQ Pinyin: a CBC padding-oracle attack that could expose typed content.
  • Baidu IME (Windows): a broken custom protocol that let traffic be decrypted.
  • iFlytek IME (Android): encryption too weak to hide input.
  • Samsung Keyboard (Android): keystroke data sent with no encryption at all.
  • Xiaomi, OPPO, Vivo, Honor: factory keyboards built on Baidu, iFlytek, or Sogou, inheriting the same holes.

Homegrown Ciphers, Old Habits, Easy Exploits

The researchers said the bugs were easy to find and easy to use. They did not treat them as deliberate government backdoors. Beijing already has other ways to collect this data, and Chinese regulators have spent years telling vendors to harden software. The more boring explanation is worse: many of these IMEs were written in the 2000s, before TLS was default, and some Chinese developers still refuse Western crypto standards over fears of planted backdoors — then ship homemade ciphers that fall over. Dual_EC_DRBG is the cautionary tale they cited. The result is the same either way: passwords, messages, and searches sitting in the clear for anyone on the path.

As of April 1, 2024, Citizen Lab still had working exploits against Honor and QQ Pinyin. Baidu had patched the worst of it and left other items open. Vivo and Xiaomi never answered the disclosure. The lab told QQ Pinyin users to switch keyboards and Honor owners to disable the preinstalled Baidu IME. It also asked app stores to stop geoblocking security updates.

The United Kingdom’s answer to the same class of cheap, leaky devices is a statute, not a research paper. The AEGIS Alliance covered the PSTI Act that banned guessable default passwords on smart gadgets the same week this report landed. For more on surveillance, leaks, and who actually reads your traffic, see our Hacker News desk and the older file on WikiLeaks’ Spy Files Russia dump.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Articoli Correlati

Un commento

  1. Yeah ,just buy apple,they already steal ALL your data,cut the anti everything but the U.S. crap

Pulsante per tornare all'inizio
Signup for our news and memes newsletters! 

Newsletter Form

Lists
close-link