Live data from Hacker News

Virtual Keyboard Developer Leaked 31M Client Records

mackeepersecurity.com

11–20 of 77 posts

Re: Virtual Keyboard Developer Leaked 31M Client Records

#11
post #9
post #6

Earlier quoted context omitted.

I thought most keyboards at least ask for Full Access, though may not necessarily mandate it: https://techcrunch.com/2014/10/04/everything-you-need-to-kno... I was never sure what "Full Access" meant, other than keyboard data (including keystroke recording if the dev wanted it) going forward. But surely it doesn't mean everything , as in access to keyboard-non-related data (user photos, etc).?

The documentation for that is here: https://developer.apple.com/library/content/documentation/Ge... The gist of it is that requesting "full access" allows them to access the internet and some other bits automatically, but they need to ask for further permissions for photos, location, contacts, etc.

Yep, it's not everything, but "full access" gets a scary name because when you give your keyboard a network connection it can easily log and send off all of your passwords. Very few things on iOS have that level of access.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#12
post #8
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

"all keyboard data". for a keyboard app? seems right on point. why wouldn't it want it?

With the basic permissions the keyboard can only type, it has no capability to send the keystrokes out to the internet or store them where they could be sent.

If you don't trust the keyboard developer to not be an idiot with your keystrokes, better to not give that access.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#13
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

What past data is being stored?

Is this simply frequently typed emoji/words?

Re: Virtual Keyboard Developer Leaked 31M Client Records

#14
post #8
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

"all keyboard data". for a keyboard app? seems right on point. why wouldn't it want it?

Security is one reason. You need to be able to put absolute trust in the developer of the keyboard.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#15
post #9

Earlier quoted context omitted.

The documentation for that is here: https://developer.apple.com/library/content/documentation/Ge... The gist of it is that requesting "full access" allows them to access the internet and some other bits automatically, but they need to ask for further permissions for photos, location, contacts, etc.

Yep, it's not everything, but "full access" gets a scary name because when you give your keyboard a network connection it can easily log and send off all of your passwords. Very few things on iOS have that level of access.

iOS doesn't allow custom keyboard to be used for password inputs. Any input element which masks the users input will only open with the iOS stock keyboard.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#17
I wonder from a societal point of view how data is put into the "public" and "private" camp. This is one of hundreds of leaks, and there are many more thousands to come over the next decade. It's to the point where I just assume my contacts, keyboard data, location history, voice searches and more are just public and somebody has access.

Apple, Google, Microsoft have shown no interest in wanting to actively prevent these apps from being on the app store [1], [2], try spotting the fakes.

And the fact that there is no legislation against this behaviour, and there's no real way to punish leaks like this in a purely objective way.

Welcome to the 21st century I guess?

[1]: https://fnd.io/#/us/search?mediaType=ios&term=whatsapp

[2]: https://play.google.com/store/search?q=whatsapp%20messenger&...

Re: Virtual Keyboard Developer Leaked 31M Client Records

#19

I'm still mostly just wondering why the hell a company that does shady advertising and pushes adware is doing security write-ups.

"Researchers were able to access the data and details of 31,293,959 users"

Welll... i wonder whether they kept all that data?

Post reply on HN