Over a billion users could be at risk from keyboard logging app security flaw

android, over a billion users could be at risk from keyboard logging app security flaw

Over a billion users could be at risk from keyboard logging app security flaw

Almost a billion mobile users, holding various devices, could have had their communications revealed to malicious third parties, a report from cybersecurity researchers Citizen Lab claims.

It says different device manufacturers have used different keyboard apps which were relaying unencrypted communications, transmitting keystrokes via plaintext, and similar. Tencent QQ Pinyin, Baidu IME, iFlytek IME, Samsung Keyboard on Android, Xiaomi (with keyboard apps from Baidu, iFlytek, and Sogou), OPPO, Vivo, Honor, all of these allowed potential threat actors to decrypt Chinese mobile users’ keystrokes, completely passively, and without the users needing to send any extra network traffic.

The team says it believes the keyboard apps found on these devices were “revealing the contents of users’ keystrokes in transit”.

Keeping private talk private

The only manufacturer whose keyboard app was secure is Huawei, the researchers said. As for Apple and Google, neither app has a feature to transmit keystrokes to cloud servers for cloud-based communications, it was said, which made it impossible to analyze the keyboards for the security of the feature.

“However, we observed that none of the mobile devices that we analyzed included Google’s keyboard, Gboard, preinstalled, either,” the researchers claim.

The researchers disclosed their findings to the manufacturers and say that as of April 1, almost all have addressed their issues. Only Honor and Tencent (QQ Pinyin) still remain a work in progress.

To defend from potential eavesdroppers, users should keep their apps and mobile operating systems updated, and use a keyboard that fully works on the device. Developers, on the other hand, are advised to use well-tested and standard encryption protocols, instead of building their own, potentially vulnerable versions, The Hacker News reports.

“Given the scope of these vulnerabilities, the sensitivity of what users type on their devices, the ease with which these vulnerabilities may have been discovered, and that the Five Eyes have previously exploited similar vulnerabilities in Chinese apps for surveillance, it is possible that such users’ keystrokes may have also been under mass surveillance,” the researchers concluded.

More from TechRadar Pro

    News Related

    OTHER NEWS

    FA confident that Man Utd starlet will pick England over Ghana

    Kobbie Mainoo made his first start for Man Utd at Everton (Photo: Getty) The Football Association are reportedly confident that Manchester United starlet Kobbie Mainoo will choose to represent England ... Read more »

    World Darts Championship draw throws up tricky tests for big names

    Michael Smith will begin the defence of his world title on the opening night (Picture: Getty Images) The 2024 World Darts Championship is less than three weeks away and the ... Read more »

    Pioneering flight to use repurposed cooking oil to cross Atlantic

    For the first time a long haul commercial aircraft is flying across the Atlantic using 100% sustainable aviation fuel (SAF). A long haul commercial flight is flying to the US ... Read more »

    King meets world business and finance figures at Buckingham Palace

    The King has met business and finance leaders from across the world at a Buckingham Palace reception to mark the conclusion of the UK’s Global Investment Summit. Charles was introduced ... Read more »

    What Lou Holtz thinks of Ohio State's loss to Michigan: 'They aren't real happy'

    After Ohio State’s 30-24 loss to Michigan Saturday, many college football fans were wondering where Lou Holtz was. In his postgame interview after the Buckeyes beat Notre Dame 17-14 in ... Read more »

    Darius Slay wouldn't have minded being penalized on controversial no-call

    Darius Slay wouldn’t have minded being penalized on controversial no-call No matter which team you were rooting for on Sunday, we can all agree that the officiating job performed by ... Read more »

    Mac Jones discusses Patriots future after latest benching

    New England Patriots quarterback Mac Jones (10) Quarterback Mac Jones remains committed to finding success with the New England Patriots even though his future is up in the air following ... Read more »
    Top List in the World