Jeffrey, Mona, and co-author Zoë Reichert first raised the alarm about possible surveillance with their 2023 report, which revealed how #Sogou's encryption could be exploited to decrypt what people were typing in real time. #DefCon32

Full report here: https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/

“Please do not make it public”: Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping - The Citizen Lab

In this report, we analyze the Windows, Android, and iOS versions of Tencent’s Sogou Input Method, the most popular Chinese-language input method in China. Our analysis found serious vulnerabilities in the app’s custom encryption system and how it encrypts sensitive data. These vulnerabilities could allow a network eavesdropper to decrypt sensitive communications sent by the app, including revealing all keystrokes being typed by the user. Following our disclosure of these vulnerabilities, Sogou released updated versions of the app that identified all of the issues we disclosed.

The Citizen Lab

Stellt euch vor, #Threema hätte ihr Update der Verschlüsselung nicht ausrollen dürfen oder #Sogou nicht auf TLS upgraden dürfen 🥶

Welche Horrorszenarien fallen euch sonst noch ein?
https://www.heise.de/news/Britische-Regierung-strebt-Befugnis-zur-Blockade-von-Sicherheitsupdates-an-9285877.html

Britische Regierung strebt Befugnis zur Blockade von Sicherheitsupdates an

WhatsApp & Co. sollen das Innenministerium über geplante Änderungen an ihren Diensten informieren, die sich negativ auf Ermittlungsbefugnisse auswirken könnten.

heise online
#Vulnerability in #Tencent’s #Sogou #Chinese #Keyboard Can Leak Text Input in Real-Time
#Security researchers at #CitizenLab discovered a number of cryptographic #vulnerabilities in Sogou Input Method keyboard made by Tencent, the most popular input method in #China. The vulnerabilities allow adversaries with a privileged network position (such as an ISP or anyone with access to upstream routers) to read the text a user inputs on a device in real-time as it's being typed.
https://www.eff.org/deeplinks/2023/08/vulnerability-tencents-sogou-chinese-keyboard-can-leak-text-input-real-time
Vulnerability in Tencent’s Sogou Chinese Keyboard Can Leak Text Input in Real-Time

Security researchers at Citizen Lab discovered a number of cryptographic vulnerabilities in the Sogou Input Method keyboard software made by Tencent, the most popular input method in China. These vulnerabilities allow adversaries with a privileged network position (such as an ISP or anyone with...

Electronic Frontier Foundation

“Five days after Tencent (Shenzhen) admits to the IME vulnerability, the Chinese person (in Shenzhen) who originally publicized it suddenly gets dragged in by the cops and forced offline.”

“NONE of them could read English to see my account does not even make China look bad, it was all Baidu fucking translate and demands why I was talking about Signal and the keyboard”

@signalapp cannot stop…#Sogou from recording keystrokes” https://assemblag.es/@hugo/110902332690849610

Hugo (@[email protected])

good read, if you too were wondering what happened to the amazing @RealSexyCyborg. https://www.hackingbutlegal.com/p/naomi-wu-and-the-silence-that-speaks-volumes

Assemblag.es
Popular Chinese-language service Sogou exposed to ‘eavesdropper,’ report says
Network transmissions by a Chinese technology company used by more than 455 million people a month were exposed to a “network eavesdropper” that captured keystrokes in real time, according to a report released Wednesday.
https://therecord.media/sogou-input-method-vulnerability-eavesdropper-citizen-lab #NetworkEavesdropper #vulnerability #keystroke #Sogou #InputMethod #chinese
Popular Chinese-language service Sogou exposed to ‘eavesdropper,’ report says

Sogou Input Method, software for typing Chinese characters on computers or mobile devices, was found to have “troubling vulnerabilities," according to Citizen Lab.

“Please do not make it public”: Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping - The Citizen Lab

In this report, we analyze the Windows, Android, and iOS versions of Tencent’s Sogou Input Method, the most popular Chinese-language input method in China. Our analysis found serious vulnerabilities in the app’s custom encryption system and how it encrypts sensitive data. These vulnerabilities could allow a network eavesdropper to decrypt sensitive communications sent by the app, including revealing all keystrokes being typed by the user. Following our disclosure of these vulnerabilities, Sogou released updated versions of the app that identified all of the issues we disclosed.

The Citizen Lab

The vulnerabilities in EncryptWall allow network eavesdroppers to extract the text content and access sensitive data.

#cybersecurity #Sogou #privacy #data

https://cybersec84.wordpress.com/2023/08/10/popular-chinese-language-app-sogou-input-method-vulnerable-to-keystroke-logging/

Popular Chinese Language App Sogou Input Method Vulnerable to Keystroke Logging

A Chinese language input app called Sogou Input Method, which is widely used on Windows and Android devices, has been discovered to have serious security flaws that could potentially expose users&#…

CyberSec84 | Cybersecurity news.
To search for something within #MainlandChina or on China-based websites, you'll need to use a China-based #SearchEngine. Because Google is banned in #China due to #censorship, the top search engines to use are #Baidu and #Sogou #langtwt
https://www.baidu.com
https://sogou.com
百度一下,你就知道

全球领先的中文搜索引擎、致力于让网民更便捷地获取信息,找到所求。百度超过千亿的中文网页数据库,可以瞬间找到相关的搜索结果。

Китай намерен избавиться от информационного хаоса в своих мобильных браузерах #Китай, #браузер, #Huawei, #Xiaomi, #Oppo, #Sogou https://www.securitylab.ru/news/513409.php https://twitter.com/SecurityLabnews/status/1321086760194027529/photo/1
Китай намерен избавиться от информационного хаоса в своих мобильных браузерах

Масштабная проверка будет сосредоточена на браузерах от Huawei, Alibaba Group, Xiaomi Corp, Qihoo 360, Oppo и Sogou.

En Chine, Sogou crée des voix plus naturelles pour les livres audio grâce à l'intelligence artificielle

Après les présentateurs télé et même un juge virtuel, le moteur de recherche chinois Sogou va proposer des avatars d’auteurs de romans pour les livres audio, en partenariat avec Zhangyue Technology.