In this report, we analyze the Windows, Android, and iOS versions of Tencent’s Sogou Input Method, the most popular Chinese-language input method in China. Our analysis found serious vulnerabilities in the app’s custom encryption system and how it encrypts sensitive data. These vulnerabilities could allow a network eavesdropper to decrypt sensitive communications sent by the app, including revealing all keystrokes being typed by the user. Following our disclosure of these vulnerabilities, Sogou released updated versions of the app that identified all of the issues we disclosed.
Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.
It probably doesn’t though. Obviously it’s closed source making it harder to tell what’s actually happening, but there’s nothing stopping security analysts from looking at network usage and such. I would imagine that Google doesn’t install a keylogger on every Android phone, not out of the goodness of their hearts, but because they don’t want the bad publicity and lawsuits when it would inevitably be discovered.
they do collect usage stats by default though.
which include typed sentences passed through their ai model and words usage counts.
it can all be turned off and gboard seems to respect these options. it doesn’t access online services unless requested with these options off.
If you mean by “collect usage stats” train their AI model on-device and send the training result to Google, then yes. If you mean that the actual words get sent to Google’s servers, then no. There was a study shared recently that looked into this. Only metadata about what’s typed is sent. That’s not nothing of course, but it’s not what Tencent does at all.
Thank you for this. This is much more reasonable of a privacy critique than falsely claiming Google is using a keylogger. I heard Grammarly was doing something similar and deleted my account. I’m changed the settings, but will continue using Gboard because I like the combined emojis.
I mean he’s not wrong, but also not really the same thing.
Gboard does send a substantial amount of data about the things you typed to google. It is supposedly anonymous, but they do this to get anylitics, and they use this data to improve the suggestions given to you.
There has been at least one article where someone intercepted the data leaving from Gboard and found it’s either unencrypted or just hashed into something like base64. This was a while back so things hopefully changed.
While google does try not to phone home users passwords, how can you tell what is and isent private?
Even if i had it, do you honestly think i would waste my life to be completely forgotten and left to rot for disclosing it like Snowden. Yep, no one will ever reveal anything after that shit show.
Man, Snowden wasted his entire life to tell you USA literally spy on everything you do and when caught their answer was : yeah, so what you gonna do about it, maybe you should do the same.
Did you read it ? Can you share the part with relevant info. I tried to read it but it kept going abouts how Gboard and the Microsoft keyboard both gather huge amount of data and yet that both are opaque and you can’t know what data is sent to the server backend.
Google doesn’t sell to data brokers. Not yet at least. They have a competitive advantage they will lose if they sold their data (our data) to third parties, especially third party resellers. If/when they begin circling the drain, that may change.
The people here acting like their Gboard doesn’t do the same is so funny.
Edit : never used nor installed tiktok.
It probably doesn’t though. Obviously it’s closed source making it harder to tell what’s actually happening, but there’s nothing stopping security analysts from looking at network usage and such. I would imagine that Google doesn’t install a keylogger on every Android phone, not out of the goodness of their hearts, but because they don’t want the bad publicity and lawsuits when it would inevitably be discovered.
they do collect usage stats by default though.
which include typed sentences passed through their ai model and words usage counts.
it can all be turned off and gboard seems to respect these options. it doesn’t access online services unless requested with these options off.
If you mean by “collect usage stats” train their AI model on-device and send the training result to Google, then yes. If you mean that the actual words get sent to Google’s servers, then no. There was a study shared recently that looked into this. Only metadata about what’s typed is sent. That’s not nothing of course, but it’s not what Tencent does at all.
E: Found it.
Thank you for this. This is much more reasonable of a privacy critique than falsely claiming Google is using a keylogger. I heard Grammarly was doing something similar and deleted my account. I’m changed the settings, but will continue using Gboard because I like the combined emojis.
If you have any evidence that it does, it would be big news. Please share.
I mean he’s not wrong, but also not really the same thing. Gboard does send a substantial amount of data about the things you typed to google. It is supposedly anonymous, but they do this to get anylitics, and they use this data to improve the suggestions given to you.
There has been at least one article where someone intercepted the data leaving from Gboard and found it’s either unencrypted or just hashed into something like base64. This was a while back so things hopefully changed.
While google does try not to phone home users passwords, how can you tell what is and isent private?
Info
Even if i had it, do you honestly think i would waste my life to be completely forgotten and left to rot for disclosing it like Snowden. Yep, no one will ever reveal anything after that shit show.
ok.gif
https://media.tenor.com/NP4p6NFHd00AAAAM/richard-simmons-sure-jan.gif
The big issue is Google isn’t owned by the state.
I mean… Does It change anything? They are owned by a board of directors that want profits over anything else
Of course it change, at least the authorities have to buy from companies with public money instead of getting for free.
Man, Snowden wasted his entire life to tell you USA literally spy on everything you do and when caught their answer was : yeah, so what you gonna do about it, maybe you should do the same.
Instead they are about to be their own state.
Btw, companies are absolutistic by default.
no they are just compelled by the state and secret courts which is totally different obviously
They are the state at this point. So same thing.
No one is acting. It doesn’t do the same. There you have it.
Did you read it ? Can you share the part with relevant info. I tried to read it but it kept going abouts how Gboard and the Microsoft keyboard both gather huge amount of data and yet that both are opaque and you can’t know what data is sent to the server backend.
Also, ever heard of 5,9 and 14 eyes ?
Oh shit, Google is sending my stuff to China?
It depends. Ever heard of databrokers ?
Google doesn’t sell to data brokers. Not yet at least. They have a competitive advantage they will lose if they sold their data (our data) to third parties, especially third party resellers. If/when they begin circling the drain, that may change.
Total false take, don’t just say your suspicions like they are facts.