Live data from Hacker News

“Please do not make it public” (Tencent’s Sogou Input Method)

citizenlab.ca

31–40 of 43 posts

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#31

> In this report, we analyze Tencent’s Sogou Input Method, the most popular Chinese input method with over 455 million monthly active users and versions of the app for multiple platforms, including Windows, Android, and iOS. Sogou Input Method accounts for 70% of Chinese input method users, with products by iFlytek and Baidu taking second and third place, respectively. This part is surprising to me. Are the Chinese i…

It is a lot better now, but the Chinese keyboard used to be so not-as-good on iOS that Baidu's official help for people (and even for a while an advertisement on their home page!) suggested they jailbreak their phone to get a better keyboard.

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#32
I'm not a huge fan of the blog title - the clear intent of the title is to make it sound like they didn't want any public disclosure, but my reading is that the first response incorrectly considered it low priority, and then after Tencent realized it was a real issue they quickly said "whoops, please don't disclose this as we need to fix it".

It seems like this could be in part mitigated by making sure their server is not an oracle (though obviously fixing the primitives is also important, but older/non-updatable clients could exist).

I would guess the traffic all over TLS on iOS due to "App Transport Security" requiring https by default - it's not a huge leap to turn it off, but it's controlled by the App's Info.plist so is trivially indexable. Also probably more work than just adding 's' to the protocol (at least from the PoV of the individual dev working on the code).

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#33

> In this report, we analyze Tencent’s Sogou Input Method, the most popular Chinese input method with over 455 million monthly active users and versions of the app for multiple platforms, including Windows, Android, and iOS. Sogou Input Method accounts for 70% of Chinese input method users, with products by iFlytek and Baidu taking second and third place, respectively. This part is surprising to me. Are the Chinese i…

phone native pinyin->character input seems fine now? Google keyboard and iphone's keyboard for pinyin->characters works fine. If you're using normal mandarin.

Windows OS pinyin->character input.... I don't know if I've ever seen someone use something other than Sogou lol, so honestly I can't say how good or bad windows native is at this now.

It's a hard problem, because of the 1:many fanout for any given pinyin input. "bao" can mean like 40 different things - bread thing, weak (?), hug, violence (?), treasured-one (think like "my precious", like a pet name for a baby?), etc etc. Sogou had a big leg up for a long time because it figured out the correct words from context much better than other alternatives, requiring fewer manual selections.

(semi-related note, google's voice->text still fails pretty hard for regional mandarin. For example it really doesn't like the hard Rs at the end of words in far northeastern mandarin. It can't seem to figure out that "baoERRRR" is actually just "bao". That problem doesn't exist for pinyin->characters though)

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#34

> In this report, we analyze Tencent’s Sogou Input Method, the most popular Chinese input method with over 455 million monthly active users and versions of the app for multiple platforms, including Windows, Android, and iOS. Sogou Input Method accounts for 70% of Chinese input method users, with products by iFlytek and Baidu taking second and third place, respectively. This part is surprising to me. Are the Chinese i…

Haven't used sogou since like 2009 but back then it not only was ace at contextual prediction but also had colloquialisms built in

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#35

> In this report, we analyze Tencent’s Sogou Input Method, the most popular Chinese input method with over 455 million monthly active users and versions of the app for multiple platforms, including Windows, Android, and iOS. Sogou Input Method accounts for 70% of Chinese input method users, with products by iFlytek and Baidu taking second and third place, respectively. This part is surprising to me. Are the Chinese i…

> I'm surprised that Microsoft, Apple et al provide such a sub-par service in China that over 450 million people were bothered enough to install a third-party keyboard.

American companies man. They really don't care. So much stuff just breaks or does the bare minimum if you're using any kind of IME, or if you're not using UTF8, or even if you're not using ASCII. There seems to just be a general cultural incomprehension that there's any other way of writing on computers. (It's not even limited to companies - there's a whole bunch of Linux stuff with the same problem, e.g. Snap/FlatPak just break everything and don't care)

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#36

Earlier quoted context omitted.

> Why do they elect to do this? They could be rightly suspicious of a western TLS implementation but discovered the pitfall of writing their own. Could have also been intentional.

> They could be rightly suspicious of a western TLS implementation but discovered the pitfall of writing their own. Could have also been intentional. They could have deployed TLS with some cipher of Chinese origin, not like Chinese companies haven't done this before [0] [0] https://ciphersuite.info/cs/TLS_SM4_GCM_SM3/

If there's a zero day that's been embedded in a protocol by the NSA or actively used by the NSA, I normally wouldn't expect it to come from the actual encryption process itself. It would be something that choosing your own cipher wouldn't fix, because it would be about compromising security on the software level rather than the encryption level. There's a very good reason the PRC won't allow compromised Cisco routers, it wouldn't surprise me if there was similar thinking here, justified or not.

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#37
post #10

Earlier quoted context omitted.

From TFA > While alphabetic keyboards typically provide autocomplete features for more expedient typing, predictive features in Chinese input methods are more crucial when using input methods such as pinyin where hundreds of characters might match an inputted pinyin syllable. For longer strings of syllables, an IME will commonly reach out over the network to a cloud-based service for suggestions if suitable suggestio…

It's impressive that users are ok with this. This is even beyond the (now generally-accepted) analytics and ad targeting, it's literally "we'll send all your keystrokes to a remote server", a literal keylogger.

The privacy environment in the PRC is pretty different to here (I'm in Australia, but speaking for the West in general). In the PRC there is an expectation by everyone (government and citizen) that the government will have access to your data if it wants it and trying to keep that data away from the government is itself criminal. Foreigners are held to a different standard, but the takeaway is that for the vast majority of PRC internet users security from government invasion of privacy is "not a concern"; it's essentially known that it will always be the case, so why be worried about it?

On the consumer privacy side, talking about consumer data safety from companies using it for commercial exploitation, that's where there is allowable space to be protective, and the laws reflect that in the PRC. If Tencent was found to be doing something that was seriously exploitative of user privacy in a way that made enough Chinese very angry, it would be almost certain that Tencent would be breaking some law to do so, and depending on the circumstances you could see anything from mandatory "make it right" directives from the government to the execution of Pony Ma as a result. PRC citizenry expect that if they are seriously harmed, en masse, by a company, the government will make it right.

This is a very different environment and culture from what we have in the West. In general, if I was the victim of significant harm (alongside many other people) by a large corporation, I would not expect justice. The CEO or those who made the decisions that harmed me wouldn't be executed, the company wouldn't be forced to push an update making my device safe to use again or pay a full refund to everyone, etc. As a result, if I care about this issue I'm not really thinking about the consequences for big companies of harming me, I'm just thinking about how to protect myself. What software can I individually use to protect my privacy, what companies should I individually avoid because I know I don't like what they're doing, etc. These are philosophically quite different approaches to privacy concerns - we have a lot more individual freedom in the West if we choose to use it, when it comes to individual net privacy, but the general attitude of PRC is that they don't have to worry about the privacy thing because the government will handle it one way or another.

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#38
post #6
post #4

What is the significance of the headline? It seems like the editors are trying to play into popular stereotypes for clicks, because reading through the disclosure log, it seems like a straightforward process marred by some minor email/communication issues. No real attempt at "suppression/censorship", as the headline implies. What am I missing?

Yes, what could be wrong with some keyboard input addon that sends every keypress to Tencent, and on top of that, in a manner trivial for a passive eavesdropper to decode? We used to call these things "keyloggers".

The severity of the vulnerability has nothing to do with this sensationalized headline.

Re: “Please do not make it public” (Tencent’s Sogou Input Method)

#39
post #9

> “Please do not make it public” (Tencent’s Sogou Input Method) (citizenlab.ca) Ok, so they didn't make it public and the development team fixed the bugs. Maybe I am missing some new trend where the headline in these disclosures _has_ to come from the communication with the company. Kind of like vulnerabilities need custom websites with logos and cool made up names? > Even with the reported vulnerabilities now resolv…

[dead]
Post reply on HN