In this report, we analyze the Windows, Android, and iOS versions of Tencent’s Sogou Input Method, the most popular Chinese-language input method in China. Our analysis found serious vulnerabilities in the app’s custom encryption system and how it encrypts sensitive data. These vulnerabilities could allow a network eavesdropper to decrypt sensitive communications sent by the app, including revealing all keystrokes being typed by the user. Following our disclosure of these vulnerabilities, Sogou released updated versions of the app that identified all of the issues we disclosed.
Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.
Didn’t swiftpad or whatever its called send every key pressed to Microsoft?
Not a China shill. China is horrible. Microsoft less so as they don’t commit genocide in slow motion. But still, I think this sort of thing is more common than we think.
Seconded. I use Gboard because it has the same functionality but I have to sandbox it and restrict all internet access via firewall. I still don’t trust it and would prefer a FOSS alternative with the same functionality.
You can sandbox an app using Shelter. You can block the internet access of that app using NetGuard. Both apps are available on F-Droid and easy to setup. No special OS needed but I strongly recommend GrapheneOS to avoid backdoors.
Glad to help. Consider dropping the NetGuard dev some coin, he’s doing incredible work. He also develops FairEmail which imho is the best IMAP email app in existence.
Didn’t swiftpad or whatever its called send every key pressed to Microsoft?
Not a China shill. China is horrible. Microsoft less so as they don’t commit genocide in slow motion. But still, I think this sort of thing is more common than we think.
Use FOSS.
What are the best FOSS options for Android keyboard apps? I’ve been struggling with this lately.
Seconded. I use Gboard because it has the same functionality but I have to sandbox it and restrict all internet access via firewall. I still don’t trust it and would prefer a FOSS alternative with the same functionality.
How do you do that?
You can sandbox an app using Shelter. You can block the internet access of that app using NetGuard. Both apps are available on F-Droid and easy to setup. No special OS needed but I strongly recommend GrapheneOS to avoid backdoors.
Thank you vm! NetGuard is awesome. I will test Shelter.
Glad to help. Consider dropping the NetGuard dev some coin, he’s doing incredible work. He also develops FairEmail which imho is the best IMAP email app in existence.