Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim
- Reference: 1714109597
- News link: https://www.theregister.co.uk/2024/04/26/pinyin_keyboard_security_risks/
- Source link:
As the Lab’s [1]findings [PDF] explain, “There is no way to fit the tens of thousands of Chinese characters that exist onto a single keyboard.”
Computers set for use by Chinese language speakers therefore employ “Input Method Editor” (IME) software , the most popular of which use the Pinyin scheme that makes it possible to represent the sounds of Mandarin using the Latin alphabet. Smartphones intended for use by Chinese speakers often include Pinyin keyboard apps, and they’re also available in app stores.
[2]
But mapping the Latin alphabet to Chinese characters is not easy, so some Pinyin apps upload keystrokes to the cloud for processing. Apple and Google don't use this technique.
[3]
[4]
According to Citizen Lab, Baidu’s Pinyin app uses weak encryption so users’ keystrokes are vulnerable to interception by an eavesdropper who can therefore read all input. Apps from Samsung, Xiaomi, OPPO, Honor and iFlytek use crypto that has already been compromised by a working exploit that allows active and passive eavesdroppers to intercept keystrokes. Baidu’s Pinyin app for Windows has the same problem.
Apps from Tencent, Xiaomi, OPPO and Vivo have crypto issues that allow an active eavesdropper to intercept keystrokes.
[5]
IME apps are tailored to different devices, and some versions of IME apps have vulnerabilities that are only present on certain machines.
[6]Think tank report labels NSO, Lazarus as 'cyber mercenaries'
[7]If Britain is so bothered by China, why do these .gov.uk sites use Chinese ad brokers?
[8]Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes
[9]Tencent set to slurp Sogou, China's second largest search engine, and snaffle its super-popular text editor
Citizen Lab reported its findings to the relevant companies, with mixed results.
“All companies except Baidu, Vivo, and Xiaomi responded to our disclosures,” the Lab’s report states. Baidu did fix the most serious issues the researchers found but didn’t fix them all.
Tencent promised to fix its wares by April 1st but appears not to have done so at the time of publication – perhaps because it considers one if its insecure app to have reached end-of-life.
Even if apps are updated to address the flaws Citizen lab found, the org worries that difficulties updating software mean the problems will persist. Honor devices, for example, don’t offer a facility to update keyboard apps. Updating Samsung’s apps requires creation of an account. The Lab’s researchers also found some app updates are geoblocked.
[10]
“The scope of these severe vulnerabilities cannot be understated,” the report concludes, because the keyboard apps Citizen Lab studied enjoy over 95 percent market share in China, and the handset-makers that pre-installed vulnerable software collectively own half the market.
By Citizen Lab’s reckoning, about 780 million people were therefore at risk of smartphone surveillance.
It gets worse: the Lab last year found similar problems with a popular input app called Sogou, leading to an “estimate that close to one billion users are affected by this class of vulnerabilities.”
At this point, readers might reach the conclusion that China’s government would not mind access to its citizens’ smartphones.
Citizen Lab suggests that hypothesis is weak – because Beijing doesn’t need backdoors as it already collects keystroke data, wouldn’t like the idea of third parties doing likewise, and constantly urges improved software security.
The Lab attributes the issues to a reluctance to use proven ciphers, perhaps out of fear they’ve been compromised by western powers.
The research suggests many actions that could be taken across the smartphone ecosystem – developers, manufacturers, and app stores – to make this kind of vulnerability history.
For now, however, it has more practical advice: update your Pinyin apps, ASAP. ®
Get our [11]Tech Resources
[1] https://tspace.library.utoronto.ca/bitstream/1807/138305/1/CitizenLabReport%23175--keyboardvuln.pdf
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zit7Q5WeqLjHrIPjPok2-wAAAA0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zit7Q5WeqLjHrIPjPok2-wAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zit7Q5WeqLjHrIPjPok2-wAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zit7Q5WeqLjHrIPjPok2-wAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/12/13/cyber_mercenary_orf_report/
[7] https://www.theregister.com/2024/04/24/ads_on_gov_uk_websites/
[8] https://www.theregister.com/2024/04/24/spies_cisco_firewall/
[9] https://www.theregister.com/2020/07/28/tencent_sogou_buyout/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zit7Q5WeqLjHrIPjPok2-wAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re: No mention of Apple?
I expect some US iPhone users use the pinyin-based keyboard, which if processed in the cloud in China….
Re: No mention of Apple?
"Apple and Google don't use this technique." - from the article.
Re: No mention of Apple?
In case it wasn't present in the article when you posted your comment: "some Pinyin apps upload keystrokes to the cloud for processing. Apple and Google don't use this technique."
Why arent these xiaomi hackers helping xiamomi with their shitty new car ?
You say security issue, governments say feature
Ahh yes, the 82MB Mouse Driver; or the 227MB keyboard driver using 5% of CPU. Is it not obvious why we cannot have nice things?
Downvote presumably by some nob writing spyware into their crap drivers.
'flaws'
Okay, yeah, sure, that is a totally accidental 'flaw'.
No mention of Apple?
iOS has a pinyin-based keyboard built in. Apple sometimes sells phones in China.