Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.

  • godless@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    I live in China and this software is cancerous not just in the encryption failure, it also nestles into a computer like a trojan. Creates 2 fallback installations and will reinstall itself after removal if you reboot in between, unless you get rid of all 3 installations at once, where they are deliberately trying to obfuscate the uninstall button (triple confirmation, swapping the confirm/cancel buttons and button background colors, etc.).

    It’s a nasty piece of crap that come preloaded on any phone (android, at least) and Windows-PC here.

      • Dojan@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        I mean the CCP is aiming to have people use Kylin? If the government and the entire populace starts using Linux instead we’ll just see the same BS on Linux instead. It’s not an OS/platform issue, but an issue of bad actors.

    • Anamana@feddit.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      Do people generally try to circumvent it? Are they too scared to uninstall it? Or do they just not care?

        • Anamana@feddit.de
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          1 year ago

          Why? Useful for safety and security of the society?

          Edit: Why downvotes? I’m trying to put myself in their shoes, it’s not how I view it lol

  • nomadjoanne@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    1 year ago

    Didn’t swiftpad or whatever its called send every key pressed to Microsoft?

    Not a China shill. China is horrible. Microsoft less so as they don’t commit genocide in slow motion. But still, I think this sort of thing is more common than we think.

    Use FOSS.

    • dx1@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      What are the best FOSS options for Android keyboard apps? I’ve been struggling with this lately.

      • sic_1@feddit.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 year ago

        Seconded. I use Gboard because it has the same functionality but I have to sandbox it and restrict all internet access via firewall. I still don’t trust it and would prefer a FOSS alternative with the same functionality.

          • sic_1@feddit.de
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 year ago

            You can sandbox an app using Shelter. You can block the internet access of that app using NetGuard. Both apps are available on F-Droid and easy to setup. No special OS needed but I strongly recommend GrapheneOS to avoid backdoors.

              • sic_1@feddit.de
                link
                fedilink
                English
                arrow-up
                0
                ·
                1 year ago

                Glad to help. Consider dropping the NetGuard dev some coin, he’s doing incredible work. He also develops FairEmail which imho is the best IMAP email app in existence.

  • Cam@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    1 year ago

    Never use a closed source keyboard app. It can read what you send for messages, websites you go to, search engine queries.