Domestic cloud input method - only Huawei has no cloud data upload security issues

Researchers from CitizenLab at the University of Toronto in Canada analyzed the cloud input methods of nine manufacturers: Baidu, Honor, Huawei, iFlytek, OPPO, Vivo, Samsung, Tencent, and Xiaomi, and found that eight input method software contained serious vulnerabilities. Allows researchers to completely break encryption methods designed by manufacturers to protect user input. There are also some manufacturers that do not use any encryption method to protect user input content .

▲ Schematic diagram of the BCTR mode encryption scheme used by Baidu IME on Android and iOS

Researchers submitted vulnerability reports to the nine affected developers. Most developers took the problem seriously and responded, patching the vulnerabilities. However, there are still a few input methods that have not patched the vulnerabilities.

Among the applications of nine manufacturers tested, only Huawei's products did not find any security issues related to uploading user input content to the cloud. Each of the other manufacturers has at least one application that contains vulnerabilities, allowing passive network attackers to Monitor the complete content of user input.


Reference link

https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/

https://citizenlab.ca/2024/04/%e6%95%b2%e6%95%b2%e6%89%93%e6%89%93%e4%b8%80%e7%b3%bb%e5%88%97%e4%ba%91%e7%ab%af%e8%be%93%e5%85%a5%e6%b3%95%e6%bc%8f%e6%b4%9e%e4%bd%bf%e7%bd%91%e7%bb%9c%e6%94%bb%e5%87%bb%e8%80%85%e5%be%97-zh-cn/

https://citizenlab.ca/wp-content/uploads/2024/04/CitizenLabReport175-keyboardvuln.pdf

Guess you like

Origin www.oschina.net/news/289288