What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem - The Citizen Lab

Researchers take a look at the analytics and first-party tracking ecosystem of WeChat Mini Programs.

The Citizen Lab
WireWatch: Measuring the Security of Proprietary Network Encryption in the Global Android Ecosystem - The Citizen Lab

New paper co-authored by researchers at the Citizen Lab and Princeton University explores the network security of Android apps.

The Citizen Lab
Network Security Issues in RedNote - The Citizen Lab

Our first network security analysis of the popular Chinese social media platform, RedNote, revealed numerous issues with the Android and iOS versions of the app. Most notably, we found that both the Android and iOS versions of RedNote fetch viewed images and videos without any encryption, which enables network eavesdroppers to learn exactly what content users are browsing. We also found a vulnerability in the Android version that enables network attackers to learn the contents of files on users’ devices. We disclosed the vulnerability issues to RedNote, and its vendors NEXTDATA, and MobTech, but did not receive a response from any party. This report underscores the importance of using well-supported encryption implementations, such as transport layer security (TLS). We recommend that users who are highly concerned about network surveillance from any party refrain from using RedNote until these security issues are resolved.

The Citizen Lab
【我們繼續聊天?】繁體中文摘要 - The Citizen Lab

微信有超過十億每月活躍使用者,我們分析了微信使用的主要網路協定 MMTLS 的安全和隱私特性,並發佈了首篇公開的研究報告。

The Citizen Lab
【我们继续聊天?】常问问题 - The Citizen Lab

微信是一款具有多种功能的应用程序。之前,我们研究了小程序的隐私问题及其监视以及审查文本和图像消息。本研究重点研究微信的网络加密协议及其安全性。

The Citizen Lab
Should We Chat, Too? FAQ - The Citizen Lab

Research FAQ for the full report "Should We Chat, Too? Security Analysis of WeChat’s MMTLS Encryption Protocol"

The Citizen Lab
【我們繼續聊天?】常見問題 - The Citizen Lab

微信是一個具有許多功能的應用程式。之前我們研究過圍繞小程式的隱私問題,以及微信對文字和圖片訊息的監視及審查。在這項研究中,我們主要關注微信的網路加密協定及其安全性。

The Citizen Lab
Should We Chat, Too? Security Analysis of WeChat’s MMTLS Encryption Protocol - The Citizen Lab

This report performs the first public analysis of MMTLS, the main network protocol used by WeChat, an app with over one billion users. The report finds that MMTLS is a modified version of TLS, however some of the modifications have introduced cryptographic weaknesses.

The Citizen Lab
敲敲打打:一系列雲端輸入法漏洞允許網路攻擊者監看輸入內容(摘要) - The Citizen Lab

重要:我們建議所有使用者立即更新他們所使用的輸入法軟體以及作業系統。並建議高風險使用者停止使用任何輸入法提供的雲端建議功能,改為使用完全離線的輸入法,以避免資料外洩。

The Citizen Lab
Chinese Keyboard App Vulnerabilities Explained - The Citizen Lab

We analyzed third-party keyboard apps Tencent QQ, Baidu, and iFlytek, on the Android, iOS, and Windows platforms. Along with Tencent Sogou, they comprise over 95% of the market share for third-party keyboard apps in China. This is an FAQ for the full report titled "The not-so-silent type: Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers."

The Citizen Lab