Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.

  • Paige (she/her)
    link
    English
    11911 months ago

    It probably doesn’t though. Obviously it’s closed source making it harder to tell what’s actually happening, but there’s nothing stopping security analysts from looking at network usage and such. I would imagine that Google doesn’t install a keylogger on every Android phone, not out of the goodness of their hearts, but because they don’t want the bad publicity and lawsuits when it would inevitably be discovered.

    • voxel
      link
      fedilink
      English
      46
      edit-2
      11 months ago

      they do collect usage stats by default though.
      which include typed sentences passed through their ai model and words usage counts.
      it can all be turned off and gboard seems to respect these options. it doesn’t access online services unless requested with these options off.

      • Avid Amoeba
        link
        fedilink
        English
        7
        edit-2
        11 months ago

        If you mean by “collect usage stats” train their AI model on-device and send the training result to Google, then yes. If you mean that the actual words get sent to Google’s servers, then no. There was a study shared recently that looked into this. Only metadata about what’s typed is sent. That’s not nothing of course, but it’s not what Tencent does at all.

        E: Found it.

      • Paige (she/her)
        link
        English
        1
        edit-2
        11 months ago

        Thank you for this. This is much more reasonable of a privacy critique than falsely claiming Google is using a keylogger. I heard Grammarly was doing something similar and deleted my account. I’m changed the settings, but will continue using Gboard because I like the combined emojis.