Live data from Hacker News

Virtual Keyboard Developer Leaked 31M Client Records

mackeepersecurity.com

51–60 of 77 posts

Re: Virtual Keyboard Developer Leaked 31M Client Records

#51
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

Could it be made illegal to store personal information of users? Or even just restricted to particular industries? How many services do you use that even need it?

Re: Virtual Keyboard Developer Leaked 31M Client Records

#52
post #44
post #43

This little comment about Mongo really bothers me... I disagree that it's a flaw. It's obviously the fault of the tech team for not securing the DB "One flaw is that the default settings of a MongoDB database would allow anyone with an internet connection to browse the databases, download them, or even worst case scenario to even delete the data stored on them"

Insecure by default is flawed by default. Unless a product requires certification to use it can’t rely on expert knowledge to provide safety.

If you don't bother to read the manual for a piece of software upon which your business depends, that's your own fault.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#53
post #51
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

Could it be made illegal to store personal information of users? Or even just restricted to particular industries? How many services do you use that even need it?

[deleted]

Re: Virtual Keyboard Developer Leaked 31M Client Records

#54
There need to be a limit on telemetry, eg what data programs collects about you. This is not something new though, but hard drive space is getting cheaper so it's possible to store even more data. All this data is a gold mine for marketing, knowing what you search for, what you have on your hard drive, all your friends, and social contacts.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#55
post #51
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

Could it be made illegal to store personal information of users? Or even just restricted to particular industries? How many services do you use that even need it?

Sure could. If I'm not mistaken, Europe does that to some extend.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#56
post #7

Earlier quoted context omitted.

This is why I'm a believer in this type of regulation - you have two options: 1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some sma…

GDPR is effectively forcing companies into #1 (at least those who operate in Europe with some minimum # of employees)

Also those that have European customers!

Re: Virtual Keyboard Developer Leaked 31M Client Records

#57
post #2

Note: This story was co-published with ZDNet. I know "MacKeeper" is not a brand loved by all, but I chose to link the version from the MacKeeper Security blog rather than ZDNet, because of how the latter blasts users with an autoplay video: http://www.zdnet.com/article/popular-virtual-keyboard-leaks-...

> I know "MacKeeper" is not a brand loved by all

And the understatement of the year award goes to...

Re: Virtual Keyboard Developer Leaked 31M Client Records

#58
That's scary. It also made me think of a certain online only grammar checking service that sounds like it could be registered in Libya, where everything you type is sent to their service. Madness - in my mind, at least; their site says nothing about how they protect their customers' data.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#60

These guys write Mac malware for a living and use nefarious tactics to fool users into installing it, while making it really hard to uninstall. I've seen it on the Mac of many less technically inclined people. Things like: “your Mac has been infected, click here” while the user is downloading some torrent or watching porn. Faking the system's dialog boxes, using chatbots “is your Mac slow?”, etc. I'm amazed Apple ha…

> I don't know how these people sleep at night.

Are you talking about Apple management or the malware developers?

Post reply on HN