Live data from Hacker News

Virtual Keyboard Developer Leaked 31M Client Records

mackeepersecurity.com

21–30 of 77 posts

Re: Virtual Keyboard Developer Leaked 31M Client Records

#21

I am old enough to remember that keyloggers used to be a stealthy install. Now users install them willingly, giving it full permissions. What an amazing future we live in.

In the past, a keyboard was a physical thing with keypresses that were just keypresses. You could pick out what physical keyboard you wanted based on some preference, but it was up to the OS to determine input events from the keyboard. It's a whole different ballgame now.

Aside from the spacing/layout/etc. preferences from a soft keyboard, they function differently. Samsung's default keyboard is by far the worst thing to work with from a development standpoint. I've never had an issue working with any other soft keyboard, but the way Samsung handles certain input events is orthogonal to other major keyboards.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#22
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

Past data is useful for building a personalized typing and autocorrect model from the get go. That's the key conviency vs. security/privacy concerns tradeoff for many if these keyboards.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#23
post #15

Earlier quoted context omitted.

Yep, it's not everything, but "full access" gets a scary name because when you give your keyboard a network connection it can easily log and send off all of your passwords. Very few things on iOS have that level of access.

iOS doesn't allow custom keyboard to be used for password inputs. Any input element which masks the users input will only open with the iOS stock keyboard.

Oh, that's a good policy. Wasn't aware since I use the stock keyboard everywhere.

I tried some alternate ones for swype style typing, but frankly they were all worse than the stock Google keyboard from my days on Android so I gave up on it and learned to type with my thumbs again.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#24
post #15

Earlier quoted context omitted.

iOS doesn't allow custom keyboard to be used for password inputs. Any input element which masks the users input will only open with the iOS stock keyboard.

Oh, that's a good policy. Wasn't aware since I use the stock keyboard everywhere. I tried some alternate ones for swype style typing, but frankly they were all worse than the stock Google keyboard from my days on Android so I gave up on it and learned to type with my thumbs again.

If you haven't tried it, Google's GBoard is now on iOS and is quite good.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#25
> Summary of what the database contained:

> Phone number,

> full name of the owner,

> IMEI number

> links and the information associated with the social media profiles (birthdate, title, emails etc.)

What's wrong with their users? Why would a keyboard app need this information?

At least I would not install an app requiring those permissions. And I allow the Android phone to connect to the Internet only via my firewall (of course Google servers are blocked from the start).

Re: Virtual Keyboard Developer Leaked 31M Client Records

#26
This is an Israeli company. What were they doing with the data before they leaked it? Who were they selling it to?

One of the revelations that came out of the "binary option" fiasco is that it's legal in Israel to scam non-Israelis.[1] Financed by the binary option industry, which is 40% of Israel's financial sector, Israel's organized crime sector has become much larger. They need sucker lists for marketing. Data from phones is a good way to figure out who has spare cash.

Although a recent law change in Israel is expected to shut down the binary option industry next January, the law is very narrow. The scammers are moving to "forex" and initial coin offerings.[2]

[1] https://www.timesofisrael.com/knesset-committee-to-vote-mond... [2] https://www.timesofisrael.com/cryptocurrencies-may-be-the-ne...

Re: Virtual Keyboard Developer Leaked 31M Client Records

#27
post #17

I wonder from a societal point of view how data is put into the "public" and "private" camp. This is one of hundreds of leaks, and there are many more thousands to come over the next decade. It's to the point where I just assume my contacts, keyboard data, location history, voice searches and more are just public and somebody has access. Apple, Google, Microsoft have shown no interest in wanting to actively prevent t…

Well, privacy is not binary. Nothing is ever fully public or fully private. Something being more or less private just describes how hard it is for someone to get this information. The inertia of this information.

Do they have to drive to your house to find out where they can break in or can they see from Google StreetView? Do they have to collect a whole bunch of phone books to find out your name+number or is it readily available in a dataset online? Can they just access your PC without hindrance or do they need to strap you to a torture rack to get your password out of you?

And just as well, information loses value over time. Either because it's not anymore correct / particularly relevant, or because it's covered up by more accessible information.

Why worry about fingerprinting one user's browser when billions of people don't even clear their cookies? Why sift through a data leak of 10000 people when a data leak with millions of people is just as well available? Why try to steal the identity of that guy who's data got leaked in one data leak, if there's this other guy with cross-referencable entries in 8 data leaks?

As such, it's still always going to be worth something to try to reduce your data footprint. If you're smarter about your data than most other people are, you'll stop being interesting to data brokers, because you're just too much effort.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#28
post #7
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

This is why I'm a believer in this type of regulation - you have two options: 1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some sma…

I think it should be other way: in many countries surveillance is prohibited. The developers who collect those data should be treated the same way. And their software should be treated as a spyware.

UPD: For example, we often hear news about hackers from some Eastern European country that were obtaining personal information in large quantities. Their actions are very similar to what the developers of this keyboard did.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#29
post #10
post #7

Earlier quoted context omitted.

This is why I'm a believer in this type of regulation - you have two options: 1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some sma…

Absolutely. Good regulation is that which effectively disincentivises anti-consumer behavior. Businesses are playing risk/reward games all the time, and regulation should just pile on some huge extra risk in places where it's needed to protect consumers, and the health of the market as a whole.

This risk/reward mechanism works only for large, established companies. There is no real responsibility for a startup. If they make a mistake and are caught, they can shut down the company and start a new one with the same staff.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#30

I am old enough to remember that keyloggers used to be a stealthy install. Now users install them willingly, giving it full permissions. What an amazing future we live in.

In the past, a keyboard was a physical thing with keypresses that were just keypresses. You could pick out what physical keyboard you wanted based on some preference, but it was up to the OS to determine input events from the keyboard. It's a whole different ballgame now. Aside from the spacing/layout/etc. preferences from a soft keyboard, they function differently. Samsung's default keyboard is by far the worst thin…

Yeah, well I remember when I had to punch drivers in via the front panel before I could even use my keyboard.
Post reply on HN