1827

Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.

(page 3) 50 comments
sorted by: hot top controversial new old
[-] GnuLinuxDude@lemmy.ml 10 points 1 year ago

What's the deal with Android "keyboards"? Why is it just an app that you can install? And why can it have more functionality/permissions from the OS beyond just being a local keyboard? As an iOS user this is very bizarre and foreign to me.

I feel like every time the topic of Android keyboards (again, why is this a thing?) comes up it's some kind of big spyware thing. Seems like most every app on Android and iOS is spyware anyway, of course.

[-] jao@lemy.lol 8 points 1 year ago

Unlike iOS pretty much every part of the Android OS is replaceable. There is technically no "unified" version of Android, each Android phone manufacturer has their own unique spin on it, and since its open source, or at least most of it is, anyone can make their own version. For example: Lineage OS, /e/OS, and Graphene OS.

[-] SpaceCowboy@lemmy.ca 7 points 1 year ago

As someone that hasn't drank that Apple flavoured Kool-aid, I can't understand why people thinking the inabality to use a device you own in the way you want to is considered a feature.

load more comments (1 replies)
[-] hitmyspot@aussie.zone 6 points 1 year ago

All aspects of android (pretty much) are customisable. It's not the os that is the problem, but the developers who program on all this telemetry.

There keyboards on android are much more useful than what's available on iOS. There is a similar issue with launchers. They, by their nature, need more access to other apps and more permissions. In most cases, that means more features, but meta and Microsoft have launchers too...

I use android and iOS. I find both good but the customisable nature of android is what drove me away from iOS.

[-] paysrenttobirds@sh.itjust.works 6 points 1 year ago

For an aac user, it can be super helpful to be able to install a custom communication system as a keyboard as then they can use it with all the other apps. The keyboard apps have the same disclosures as all the others and you should avoid giving it the ability to export data with access to the Internet. Really any app can do this while you're in it and ask those name brand apps you bank with or whatever are made by third parties and could be logging anything to anywhere if no one bothered to check.

That said, I am unhappy with how android play store has never allowed you to filter apps by permission and has made it harder and harder to even see what permissions an app will request or "require". The permissions system is so good, should be made more fine-grained but instead they seem focused on "data safety statements" that are just cya for the platform as far as I can tell.

You need something that can watch/report your Internet traffic around the clock and selectively "fail" dns lookups you don't like or something. I think iPhone does have something like this built in?

load more comments (1 replies)
load more comments (3 replies)
[-] sndrtj@feddit.nl 10 points 1 year ago

So when the Chinese do it it's scary, but when the Americans do it it's just "established practice"?

[-] BoostWillis@lemmy.world 10 points 1 year ago

Naomi Wu has literally been talking about pwnd Chinese IMEs for years in her sidechannel critiques of Signal.

[-] qwertyWarlord@lemmy.world 8 points 1 year ago

Imagine willingly installing a keylogger, lol

[-] gnuhaut@lemmy.ml 8 points 1 year ago

Can you point to where it says that in the report? It actually says:

an IME will commonly reach out over the network to a cloud-based service for suggestions if suitable suggestions are not available in the input method’s local database.

So it doesn't send "every key typed".

[-] redcalcium@lemmy.institute 6 points 1 year ago

Until you realized what sequence of letters most commonly not have any suggestion. That's right, when you type your password.

load more comments (2 replies)
load more comments
view more: ‹ prev next ›
this post was submitted on 10 Aug 2023
1827 points (100.0% liked)

Technology

60042 readers
2232 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS