Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.

350 points

I live in China and this software is cancerous not just in the encryption failure, it also nestles into a computer like a trojan. Creates 2 fallback installations and will reinstall itself after removal if you reboot in between, unless you get rid of all 3 installations at once, where they are deliberately trying to obfuscate the uninstall button (triple confirmation, swapping the confirm/cancel buttons and button background colors, etc.).

It’s a nasty piece of crap that come preloaded on any phone (android, at least) and Windows-PC here.

permalink
report
reply
72 points

It’s time to switch to Linux!

permalink
report
parent
reply
119 points

I mean the CCP is aiming to have people use Kylin? If the government and the entire populace starts using Linux instead we’ll just see the same BS on Linux instead. It’s not an OS/platform issue, but an issue of bad actors.

permalink
report
parent
reply
15 points

On the plus side maybe then it’ll finally be the year of the Linux desktop.

monkeys paw curls

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
44 points

Don’t worry, there is also a Linux version.

permalink
report
parent
reply
15 points

Oof

permalink
report
parent
reply
19 points

Then they’ll install the Linux version. People here are so indoctrinated, they like it.

permalink
report
parent
reply
29 points

Do people generally try to circumvent it? Are they too scared to uninstall it? Or do they just not care?

permalink
report
parent
reply
57 points

Worse. They think it’s useful.

permalink
report
parent
reply
23 points
*

Why? Useful for safety and security of the society?

Edit: Why downvotes? I’m trying to put myself in their shoes, it’s not how I view it lol

permalink
report
parent
reply
2 points
*

My guess is that it might either be more accurate in predictions or some additional convenience factors that makes typing this logographic language much easier and faster lol.

Or people are also simply used to it since it’s everywhere.

permalink
report
parent
reply
6 points

Be careful jumping the firewall.

permalink
report
parent
reply
17 points

Sure. Foreigners aren’t really sanctioned though, that’s more of a risk for the locals. But even then usually only if they want to get someone disappeared and don’t have anything substantial against them.

permalink
report
parent
reply
260 points

Alright China shills, you can stop changing the subject to how Google and the US are the “same”.

The troops advanced into central parts of Beijing on the city’s major thoroughfares in the early morning hours of 4 June and engaged in bloody clashes with demonstrators attempting to block them, in which many people – demonstrators, bystanders, and soldiers – were killed. Estimates of the death toll vary from several hundred to several thousand, with thousands more wounded.[15][16][17][18][19][20]

https://en.m.wikipedia.org/wiki/1989_Tiananmen_Square_protests_and_massacre

If you lived in China you’d likely not know about this, since people who talk about it go to prison.

Yeah the US is exactly like this so let’s not talk about the Chinese government being awful to their citizens /s

permalink
report
reply
96 points

Simple solution is to block lemmygrad and hexbear in your app. That cuts down quite a few tankies and mainlaind Taiwan shills.

permalink
report
parent
reply
45 points

Imagine being in Taiwan and having full access to information about China and the west and still shilling for China. Those types of people should be looking for a dominatrix, not a political philosophy…

permalink
report
parent
reply
51 points

I think they might be using “mainland Taiwan” as a way of saying China - Taiwan is an island which China thinks is “theirs” for some reason.

permalink
report
parent
reply
4 points

There’s a bunch of Taiwanese people who would welcome Chinese rule. I don’t know why… The CPC sucks my balls

permalink
report
parent
reply
1 point

Imagine being in Taiwan and having full access to information about China and the west and still shilling for China. Those types of people should be looking for a dominatrix, not a political philosophy…

That’s kind of the history of humanity regarding religion. To some degree when the religious prophets were alive it make sense, but hundreds of years later it’s a story book (or oral tradition) and people still strive for the authority.

We haven’t really had that many teachers like Carl Sagan who describe the history and our favoring of authority - inability to question them. It’s pretty weird, as they often aren’t attractive or good speakers, but you see people just accept almost anything they say. I mean in the USA I witnessed so many people who would trust Rush Limbaugh and Alex Jones kind of blindly, and there is some mechanism at play that humanity in total seems to keep engaging.

permalink
report
parent
reply
6 points

A must have on apps to be able to block/filter instances

permalink
report
parent
reply
6 points

Been using lemmy for a few days and I am already feeling the need to do just that.

permalink
report
parent
reply
2 points

How so? I’ve been using since the API blackout and not seen any content from either instance.

permalink
report
parent
reply
1 point

mainland Taiwan

You must mean West Taiwan. Sadly they refuse to acknowledge the authority of Taiwans government.

permalink
report
parent
reply
17 points

No one is saying Google massacred protestors, but if you’re gonna be against keyboard apps spying on you it should be irrelevant who they’re spying for. Criticizing shitty things American companies do doesn’t make you a China shill and calling everyone who does it a China shill is intellectually dishonest.

permalink
report
parent
reply
-10 points

claiming that the dozen people in this thread falsely equating what China is doing to the things that happen in the US – ignoring that they are very different, and ONLY considering that they are moving attention away from the posted article – is not so much “intellectually dishonest” as it is an intentional lie with a goal. Good bye.

permalink
report
parent
reply
8 points

Kinda funny how your own username partially contradicts your argument.

permalink
report
parent
reply
7 points
*

I mean, ill always say that China is worse than the US. But you can find plenty of examples of the US doing awful things to its people too.

Like the MOVE bombing https://en.wikipedia.org/wiki/1985_MOVE_bombing

or The Tusla Massacre that involved law enforcement bombing black neighbourhoods https://en.wikipedia.org/wiki/Tulsa_race_massacre

Or any of the countless of times cops perpetrated mass violence against black people during the civil war era and cracked down harshly on protests.

Or when the did the same to anti-war protestors during the vietnam war.

Or the numerous times they experimented on their own citezens such as MK ultra, The Tuskegee Syphilis Experiment, or any of the dozens upon dozens of radiation experimentation, like when almost 1000 pregnant mothers were injected with radioactive iron, causing many miscarriages and cancers(and thats not the only time they injected pregnant mothers with radioctive material to see if it fucked up the baby), or when inserting radium rods up the nostrils of school children and then observing how their health declined, or when they dosed hundreds of inuit with radioactive iodine to see its affects on the thyroid.

Like I dont think this makes China’s atrocities any more excusable, but the reverse is true to. The US really isnt much better than China.

permalink
report
parent
reply
25 points

The US really isnt much better than China.

The world ain’t just good or bad and there’s various degrees of “bad”. The fact that many US people can even talk about this stuff makes them already just ever so slightly better for many outsiders. This is how it is, neither country is “good” but they align more with western ideals than an authoritarian state which for many of us is bad by default…which it is of course. :)

permalink
report
parent
reply
3 points

Don’t forget operation sea spray! Next time you laugh at someone talking about chemtrails remember the us government actually did chemtrails!

permalink
report
parent
reply
2 points
*

As bad as those two linked incidents were, they weren’t exactly government sanctioned. Police sanctioned, sure, and the government should do more to reign that shit in, but comparing them to Tiennamen is disingenuous at best.

The Chinese government hates letting its citizens have a voice.

permalink
report
parent
reply
6 points

I gave plenty of other examples that were government sanctioned, and the treatment of black people during civil rights was government sanctioned. And going back further you have slavery and the genocide of natives that were government sanctioned. Ofc its not a 1:1 parallel with tiennamen.

permalink
report
parent
reply
-11 points

Imagine thinking China is worse than the US when the US killed something like a million Iraqis, and that’s just one of the many war the US was waging in the last 30 years while China checks notes attacked nobody in that timeframe.

permalink
report
parent
reply
7 points

I think the distinction between China and the US is how they directly treat their own citizens. Arguments could be made that they’re both equally shitty in that regard, but in different ways.

permalink
report
parent
reply
4 points

Yeah right, let me ask the Uyghurs how they’re doing real quick

permalink
report
parent
reply
-1 points

But those were brown people so they dont count - Americans probably.

permalink
report
parent
reply
-11 points

Shills gonna shill

permalink
report
parent
reply
34 points

I tend to lean into accepting that ‘the US government has done some pretty horrific shit too’ camp, but I don’t do it as a way to shill for China, because fuck that authoritarian place. But it is dumb not to recognize massacres like Kent State, Tulsa, or the systematic genocides of First Nations peoples.

Tiananmen Square really isn’t the best example to use as an example of how China isn’t like the US. There’s plenty of much more insidious dystopian shit happening in China every day to use than that.

permalink
report
parent
reply
-2 points

Do you even know what the word shill means?

Like wtf do you think I’m trying to sell?

permalink
report
parent
reply
-13 points
*
Deleted by creator
permalink
report
parent
reply
1 point

Oh no, you insulted a genocidal dictator that I would fucking celebrate like it was fucking mardi gras if he was hung by his own intestines. However will I recover from this devastation.

permalink
report
parent
reply
2 points

Sir this is a Wendy’s

Or more specifically, a thread about a phone keyboard.

But it is true that Google and Microsoft phone home with your key strokes. That’s how they develop their predictive typing and autocorrect.

permalink
report
parent
reply
0 points

If you can’t see the fundamental intertwining of Google (or any other fortune 500 company) and the US State, then you should really start looking harder. Lobbyists, revolving door membership, corruption, tax writeoffs, corporate power being used to influence day-to-day life, really, US companies’ control over the US state is pretty similar to the Chinese State’s control over Chinese Companies. I just don’t think corporations should be in charge like y’all seem to.

permalink
report
parent
reply
10 points

I think it’s weird how so many of you want to stop talking about China and shift focus to the US.

permalink
report
parent
reply
2 points
*

It actually makes sense that Americans should talk a lot more about the shitty state of things in the US rather than the propaganda about China used to distract them.

It also makes sense that Chinese should talk a lot more about the shitty state of things in China rather than the propaganda about the US used to distract them.

That just leaves everybody else, looking at both countries and people in them doing the equivalent of measuring the length of turds and fighting for which one is the shortest, pointedly ignoring it’s all shit.

permalink
report
parent
reply
-4 points

yeah I really do, because the average annual US foreign conflict is worse than the wildest liberal exaggeration of the worst thing China has ever done

permalink
report
parent
reply
-1 points
Removed by mod
permalink
report
parent
reply
-2 points
Removed by mod
permalink
report
parent
reply
1 point

The sources are… A bunch of tankie newsletters, a Medium article, and official Chinese reports? LOL talk about bias.

permalink
report
parent
reply
-9 points
*
Removed by mod
permalink
report
parent
reply
-9 points
*

That’s false equivalence.

China killing protesters and silencing dissidents does not make it OK for Google or anyone else to spy on you.

permalink
report
parent
reply
31 points
*

yeah no shit. The point is that they aren’t equivalent, trying to make them so is a destructive distraction

permalink
report
parent
reply
2 points

This thread is about an app that spies on you, it is absolutely relevant to want to talk about other apps that do the same thing.

The “yH bUt ChInA iS EvIl” rhetoric is an irrelevant distraction from the topic at hand.

permalink
report
parent
reply
14 points

That’s not what is being pointed. In China, you don’t have freedom of information. They are authoritarian, borderline totalitarian. Yeah, Google spy and the US spy on us but to say America/Google is just as bad is the false equivalence.

permalink
report
parent
reply
3 points

I’m not saying that America/Google is just as bad. I’m saying that in a thread discussing apps that spy on you, that talking about non-Chinese apps that also hoard your data is absolutely relevant and shouldn’t be trumped or silenced by a “yh, but China is evil tho” type comment.

permalink
report
parent
reply
-15 points

The troops advanced into central parts of Beijing on the city’s major thoroughfares in the early morning hours of 4 June and engaged in bloody clashes with demonstrators attempting to block them, in which many people – demonstrators, bystanders, and soldiers – were killed.

Here’s a video of an interview with Chai Ling recorded on May 28, 1989 with reporter Philip Cunningham. Chai Ling was arguably the most influential leader of the student protesters at Tiananmen Square. In the interview she openly wishes for the soldiers to massacre the students after her instrumental role in blocking attempts by other activists to move the protest back to campuses, all while refusing to sacrifice herself.

Notable quotes from this interview include:-

“You, the Chinese are not worth my struggle. You are not worth my sacrifice”

“The students keep asking what shall we do next? What can we accomplish? I feel so sad, because how can I tell them what we’re actually hoping for is bloodshed - for the moment when the government has no choice but to brazenly butcher the people?”

“Only when the square is awash with blood will the people of China open their eyes. Only then will they really be united”

“If we allow the [protesters] movement to collapse on its own, then the government will be able to wipe out all the leaders of the movement”

Upon being asked if she will stay in the square herself after urging the students to stay she simply responded, “No, I won’t”.

When the Tiananmen Square incident erupted in violence on June 3rd, Chai Ling escaped from Beijing by train. She was eventually smuggled to Hong Kong via Operation Yellowbird, an MI6/CIA led initiative to extract dissidents who they hoped would form the nucleus of a “Chinese democracy movement in exile”. To my knowledge, no details exist about how and when she made contact with them. She was subsequently invited to study at Princeton on a full scholarship due to her pivotal role in the Tiananmen protests. She studied Politics and International Relations there, eventually picking up an MBA from Harvard. Today, she runs an internet company called Jenzabar that she founded with her husband, the lawyer Robert Maginn, a long time associate of the Republican party, having even served as the chairman of the Massachusetts Republican party between 2011 and 2013. Their company serves more than 1300 higher education institutions worldwide, whom they provide with ERP software.

permalink
report
parent
reply
2 points

Here is an alternative Piped link(s): https://piped.video/5__ESiklA1A

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I’m open-source, check me out at GitHub.

permalink
report
parent
reply
1 point

What even is your point? Does one protester’s desire for violence justify the Chinese government’s violence?

permalink
report
parent
reply
1 point

Straight up disgusting attempt to dismiss what happened at Tienanmen square. Gee I wonder what your opinion on the chinese govt is.

permalink
report
parent
reply
-5 points

I haven’t stated an opinion either way. I’ve simply provided additional context to a historical event you chose to bring up. Why do you feel the need to respond to it in such a kneejerk manner and ascribe my motives? Does the context I’ve provided make you feel uncomfortable in some way?

I have neither dismissed nor denied that a terrible incident happened at Tiananman square on the late hours of June 3rd 1989. I wish for those responsible for plotting and catalysing the incident to face justice for their crimes.

permalink
report
parent
reply
-11 points

You’re just salty that the Western backed color revolution failed in China. You would have loved to cheer the West on in sucking the country dry the same that it did with Russia after they fell for the Western lies. Just compare the life expectency graphs between Russia and China after 1989:

permalink
report
parent
reply
221 points

permalink
report
reply
31 points

This is one of my favorite things about kbin over Reddit. So neat to see gifs in chat.

permalink
report
parent
reply
80 points

They’re viewable on Lemmy too!

permalink
report
parent
reply
21 points
*
Deleted by creator
permalink
report
parent
reply
32 points

Reddit added the same functionality some time ago, I’m a bit sad it’s a thing here too but oh well. People seem to like it. My favourite thing about reddit was it being text-based though

permalink
report
parent
reply

I wish they were smaller, like maximum twice the size of an emoji, maybe bigger for gif type images.

permalink
report
parent
reply
10 points

If you think that’s a kbin thing, you’ve not used reddit in years, you haven’t looked at anything lemmy, etc.

permalink
report
parent
reply
7 points

You could have gifs on Reddit too

permalink
report
parent
reply
5 points

Through New Reddit, which was objectively awful.

permalink
report
parent
reply
5 points

It’s viewable in Memmy for lemmy as well, also been on Reddit for years just not used much due to the culture there dog piling it all the time.

permalink
report
parent
reply
2 points

How are you seeing gifs in kbin? All I’m seeing is a url link to the gif and have to click the media icon button next to the URL For it to load… is there a setting I need to enable to load pictures/gifs automatically?

permalink
report
parent
reply
1 point

I’m guessing it’s your app. I’m viewing through desktop and it works fine.

permalink
report
parent
reply
2 points

I wish there was a setting to get rid of them in the app I use, hate inline images and gifs

permalink
report
parent
reply
12 points

permalink
report
parent
reply
150 points
*

Didn’t swiftpad or whatever its called send every key pressed to Microsoft?

Not a China shill. China is horrible. Microsoft less so as they don’t commit genocide in slow motion. But still, I think this sort of thing is more common than we think.

Use FOSS.

permalink
report
reply
25 points
*
Deleted by creator
permalink
report
parent
reply
85 points

Just for one thing, Chinese companies are required to have CCP members in their leadership.

permalink
report
parent
reply
24 points

I mean like the FBI buys all that data without a warrant anyways… So st least we pretend its not happening but like were practically looking in a mirror

permalink
report
parent
reply
16 points
*
Deleted by creator
permalink
report
parent
reply
12 points
Removed by mod
permalink
report
parent
reply
0 points
Removed by mod
permalink
report
parent
reply
27 points

I wanted to ask if you were born yesterday but I’ll try to be more educative than sassy.

All companies in China exist purely with the blessing of the political party. No approval, no company. Everything is done by their books.

permalink
report
parent
reply
31 points

And in US is other way around, every political party has blessing of companies.

permalink
report
parent
reply
Removed by mod
permalink
report
parent
reply
-1 points

All companies in China exist purely with the blessing of the political party. No approval, no company. Everything is done by their books.

Damn I wish that was me fr

permalink
report
parent
reply
1 point

Unexamined racism. “Collectivist asians” and denying Asian individuality is very normal in the US/Europe. Malcolm Gladwell can write a book saying Koreans are culturally incapable of flying an airplane and it’s fine. When Asians have human emotions it’s normal to turn it into some special exoticized thing like “saving face”. White people are individuals, Asians are a horde, nothing in Anglo culture prepares or encourages people to think about Chinese people as a billion individuals wandering around doing stuff for the same reasons you do. They’re a singular alien unit, if you go to war with Japan it’s only natural to lock all the Japanese people in a camp. Basically every book and newspaper article you’ve ever read talks about them they’re all wired together like the Borg, unless you put a ton of effort into critical thinking there’s no reason to escape that assumption.

permalink
report
parent
reply
3 points

Except the Chinese government has way more control over their companies than the US government does. In fact, there has been an explicit push recently by the government to increase their control and ownership of companies. It’s also consistent with how most large states operate, especially ones with a history of trying to control ethnically Chinese people outside of their borders.

That isn’t to say that a ton of anti China sentiment isn’t racist; it’s just that one doesn’t need to be racist make such a prediction. It’s true that many people who hate China hate it for the wrong reasons, but that doesn’t mean there aren’t things to take issue with.

permalink
report
parent
reply
21 points

What are the best FOSS options for Android keyboard apps? I’ve been struggling with this lately.

permalink
report
parent
reply
18 points

I use OpenBoard (it’s available on fDroid. Maybe the play store too).

I don’t know if it’s the best but I like it. If you type in multiple languages you do need to hit a “language switcher” key on the keyboard to switch to the autocorrect for that language. A very minor complaint. Otherwise it’s great.

And it will learn swear words. No more ducking ducks.

permalink
report
parent
reply
9 points

OpenBoard - every other keyboard app is ducking shirt

permalink
report
parent
reply
0 points
*
Deleted by creator
permalink
report
parent
reply
11 points

FlorishBoard

permalink
report
parent
reply
5 points

F-Droid says the app hasn’t been updated in the last 14 months. Is the project still worked on? It says beta on the website.

permalink
report
parent
reply
4 points

Thanks for the recommendation. This comment is typed using a freshly installed florisboard keyboard :)

permalink
report
parent
reply
10 points

Seconded. I use Gboard because it has the same functionality but I have to sandbox it and restrict all internet access via firewall. I still don’t trust it and would prefer a FOSS alternative with the same functionality.

permalink
report
parent
reply
3 points
*

How do you do that?

permalink
report
parent
reply
6 points

I’m partial to thumbkey. It even has a Lemmy community: !thumbkey@lemmy.ml

permalink
report
parent
reply
3 points

Thanks for the heads up. It’s really similar to the keyboard I use.

permalink
report
parent
reply
3 points

OpenBoard with Gesture

permalink
report
parent
reply
2 points

Using FlorisBoard right now, no auto correct but you’ll adapt

permalink
report
parent
reply
17 points

Think you mean SwiftKey which Microsoft just introduced bing AI into that you can’t turn off. I 100 percent assume they now use all your typing data to train their ai too. They won’t even let you use themes without logging in to an account so I again assume they also tie data to accounts.

permalink
report
parent
reply
2 points
*

Yes that’s why I’ve disabled Internet access for my keyboard since I haven’t found a FOSS one with all the features I want. Not that I need them but they’re nice and blocking network access is built in GrapheneOS anyway.

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
parent
reply
-1 points
Removed by mod
permalink
report
parent
reply
109 points

It’s stories like this that don’t surprise me as much as make me ask: How the fuck do you store and process this much data to get anything useful out of it.

permalink
report
reply
64 points

You just save the first 50 digits typed after some email is typed, and you have all the passwords you need!

permalink
report
parent
reply
2 points

This only applies if a username is a email

And if it is then what happens when people actually email someone? Autocorrect during login?

permalink
report
parent
reply
11 points
*

I don’t think they’re saying that method would yield 100% clean data but it would give you all the “necessary” data with the absolute bare minimum storage requirement. At some point people will log into their email and for most people if you have their email password you have the password they use for everything

permalink
report
parent
reply
3 points

They weren’t describing a use case for every single type of situation.

permalink
report
parent
reply
45 points

I could be wrong, and this is a generalization of any country you can name, but my impression is data is stored on everyone so when they decide someday to look you up they already have all the data collected. It’s not really processed until needed.

permalink
report
parent
reply
13 points

And in hopes of it being useful later, when processing power is better.

Hey GovGPT8, please rank the 10 citizens most likely to organize protests if we institute curfews.

permalink
report
parent
reply
2 points

Exaaaactly

permalink
report
parent
reply
4 points
*
Deleted by creator
permalink
report
parent
reply
22 points

And how can autosuggest / autocorrect be so bad with so much training data

permalink
report
parent
reply
7 points

Did you ever see how an average person types? It’s not the amount of data that is the problem. We have too much dumb data!

permalink
report
parent
reply
5 points

The real answer is compute power. At the moment it’s very expensive to run the computations necessary for big LLMs, I’ve heard some companies are even developing specialized chips to run them more efficiently. On the other hand, you probably don’t want your phone’s keyboard app burning out the tiny CPU in it and draining your battery. It’s not worth throwing anything other than a simple model at the problem.

permalink
report
parent
reply
2 points
*
Deleted by creator
permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 10K

    Posts

  • 466K

    Comments