Live data from Hacker News

Virtual Keyboard Developer Leaked 31M Client Records

mackeepersecurity.com

41–50 of 77 posts

Re: Virtual Keyboard Developer Leaked 31M Client Records

#41
post #34

Earlier quoted context omitted.

Thanks for the recommendation! It does seem good. Bummer that it has a giant search bar at the top of the keyboard, which is an enormous waste of space on an iPhone SE. If you don't give it full access, the same space is used to constantly beg for full access to turn on the search bar, and accidentally touching that will pull you out of your app over to the Gboard app, which gives you a button to open the Settings ap…

On Android, this search bar can be disabled. Maybe it's the same on iOS.

Doesn't look like it. The "Search" section in their settings has options to disable Predictive search, enable Contacts search, turn on location access, Clear Gboard search history, or Reset Google Usage ID. No way to disable the whole bar.

EDIT - the search prompt actually only pops up if you bump the G button at the left side, otherwise the bar is text predictions once you start typing. Maybe I'll give this a shot.

Android version definitely lets you disable the G button. It's listed right next to the "Predictive search" setting, so I'm fairly sure this can not be disabled on iOS. https://www.ghacks.net/2016/12/19/remove-g-button-android-ke...

Re: Virtual Keyboard Developer Leaked 31M Client Records

#42

> Summary of what the database contained: > Phone number, > full name of the owner, > IMEI number > links and the information associated with the social media profiles (birthdate, title, emails etc.) What's wrong with their users? Why would a keyboard app need this information? At least I would not install an app requiring those permissions. And I allow the Android phone to connect to the Internet only via my firewal…

You do realize that probably 99.9% users don't go to lengths such as firewalls to secure their data. People are not that tech savvy in general. Even among all my tech friends, no one uses VPNs or firewalls.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#43
This little comment about Mongo really bothers me... I disagree that it's a flaw. It's obviously the fault of the tech team for not securing the DB

"One flaw is that the default settings of a MongoDB database would allow anyone with an internet connection to browse the databases, download them, or even worst case scenario to even delete the data stored on them"

Re: Virtual Keyboard Developer Leaked 31M Client Records

#44
post #43

This little comment about Mongo really bothers me... I disagree that it's a flaw. It's obviously the fault of the tech team for not securing the DB "One flaw is that the default settings of a MongoDB database would allow anyone with an internet connection to browse the databases, download them, or even worst case scenario to even delete the data stored on them"

Insecure by default is flawed by default.

Unless a product requires certification to use it can’t rely on expert knowledge to provide safety.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#45

I am old enough to remember that keyloggers used to be a stealthy install. Now users install them willingly, giving it full permissions. What an amazing future we live in.

I wanted a little USB dongle that would turn any keyboard into a Dvorak keyboard so I could make pair programming easier on our group (3 Dvorak typists out of 8 people).

I found some, but I realized the hardware was basically a keylogger with a little extra code. Made me too uncomfortable to suggest it to my coworkers.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#46

Earlier quoted context omitted.

Yeah, well I remember when I had to punch drivers in via the front panel before I could even use my keyboard.

On the good side, those drivers didn't have Internet connection capability.

Or so you thought.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#48

Earlier quoted context omitted.

In the past, a keyboard was a physical thing with keypresses that were just keypresses. You could pick out what physical keyboard you wanted based on some preference, but it was up to the OS to determine input events from the keyboard. It's a whole different ballgame now. Aside from the spacing/layout/etc. preferences from a soft keyboard, they function differently. Samsung's default keyboard is by far the worst thin…

Yeah, well I remember when I had to punch drivers in via the front panel before I could even use my keyboard.

I wrote a Flakey Keyboard Simulator for the Apple ][ to annoy my brother.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#49

Can someone clarify whether 'Full Access' allows logging of keystrokes on the standard keyboard by these developers? Or doe they just get to see which Rick and Morty gifs I search for when I switch to their board?

Full Access grants the 3rd party keyboard access to what the user type or paste, but just for the 3rd party keyboard, not the system or other 3rd party keyboards. The 3rd party keyboard can send the data to the internet. Source/Disclaimer: I'm writing an iOS extension Keyboard

Re: Virtual Keyboard Developer Leaked 31M Client Records

#50
post #7
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

This is why I'm a believer in this type of regulation - you have two options: 1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some sma…

GDPR is effectively forcing companies into #1 (at least those who operate in Europe with some minimum # of employees)
Post reply on HN