abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfiltergenderglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalityweb

Esta página no está disponible en Español y está siendo mostrada en English

Artículo

9 ago 2023

Autor:
Jeffrey Knockel, Zoë Reichert, and Mona Wang, Citizen Lab

450 million users exposed to privacy risk due to encryption issues with Tencent product

"'Please do not make it public': Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping", 9 August 2023

...In this report, we analyze Tencent’s Sogou Input Method, the most popular Chinese input method with over 455 million monthly active users and versions of the app for multiple platforms, including Windows, Android, and iOS. Sogou Input Method accounts for 70% of Chinese input method users, with products by iFlytek and Baidu taking second and third place, respectively...

...We analyzed Sogou Input Method on three operating system platforms, finding that the app has troubling vulnerabilities in its custom-designed encryption system which render sensitive data such as the keystrokes that users type decipherable to network eavesdroppers. The vulnerabilities which we discovered are not limited to Chinese writers in China, as market research estimates concerning visitation to the app’s website put United States users as comprising over 3.3% of visits, Taiwan as nearly 1.8%, and Japan as over 1.5%...

...We found that the Windows and Android versions of Sogou Input Method contain vulnerabilities in this encryption system, including a vulnerability to a CBC padding oracle attack, which allow network eavesdroppers to recover the plaintext of encrypted network transmissions, revealing sensitive information including what users have typed...

...On 25 June, we received the following response via the Tencent Security Response Centre (TSRC) portal: “Thank you for your interest in Tencent security. There is no low or low security risk for this issue. We look forward to your next more exciting report.” Eighteen hours later, we received the following response via the TSRC portal: “Sorry, my previous reply was wrong, we are dealing with this vulnerability, please do not make it public, thank you very much for your report.”...

...Over the last eight years we have dedicated immense effort analyzing, documenting, and responsibly disclosing vulnerabilities concerning the insecure transmission of sensitive data in Chinese-developed apps. While we have had some success in coordinating with developers to resolve these issues, the ecosystem remains problematic, as here we are, again, reporting on how an unimaginably popular Chinese-developed app fails to adopt even simple best practices to secure the sensitive data which it transmits...

Información de privacidad

Este sitio usa cookies y otras tecnologías de almacenamiento web. Puede configurar sus preferencias de privacidad más adelante. Los cambios se aplicarán de inmediato.

Para más información sobre el uso que hacemos del almacenamiento web, por favor consulte nuestra Política de Cookies y Uso de Datos

Strictly necessary storage

ON
OFF

Necessary storage enables core site functionality. This site cannot function without it, so it can only be disabled by changing settings in your browser.

Cookies analíticas

ON
OFF

Cuando accede a nuestro sitio web, utilizamos Google Analytics para recopilar información sobre su visita. La aceptación de esta cookie nos permitirá conocer más detalles sobre su visita y mejorar la forma en que mostramos la información. Toda la información analítica es anónima y no la utilizamos para identificarle. Google proporciona un complemento de inhabilitación de Google Analytics para todos los navegadores populares.

Cookies promocionales

ON
OFF

Compartimos noticias y actualizaciones sobre empresas y derechos humanos a través de plataformas de terceros, incluidas las redes sociales y los motores de búsqueda. Estas cookies nos ayudan a comprender el rendimiento de estas promociones.

Sus preferencias de privacidad en este sitio

Este sitio usa cookies y otras tecnologías de almacenamiento web para mejorar su experiencia, mas allá de la funcionalidad básica necesaria.