Live data from Hacker News

68.3% of people in China use third-party keyboards – many of them use Signal

community.signalusers.org

61–70 of 77 posts

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#61

Earlier quoted context omitted.

She has been ignored for over a year (she tried to get them to discuss the issue in 2019), and all the while people have been getting kidnapped by the Chinese government due to this misunderstanding. I can understand why she would feel upset. I think what set this off was signal responding to questions to some tiny Twitter account after ignoring her for so long.

It is an extreme exageration to say that the Chinese state artitrarily detaining people is due to Signal not working around the IME issue. Let's be clear: the Chinese state detains people all the time, based on many sources of information, probably the least important being interception of keystrokes to Signal in an input method app. They own all the app makers and the app stores. They can push a specific version of…

Of course signal is not the only way people get compromised in China but if the claim in TFA that 70% of Chinese users use a third party IME is correct, it seems reasonable that some of them, thinking their chat is secure, would say something that gets them in trouble. Naomi Wu has claimed this has happened and I have no reason to doubt her.

Yes OWS is small, but a major security vulnerability for a country with over a billion people seems worth addressing, no? Naomi Wu is certainly a big account on Twitter and we can see from TFA that Moxie and OWS are aware of this complaint. The question is what to do about it. If you read TFA you will see that the best suggestion seems to be a warning to users using any third party IME. Seems quite reasonable to me.

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#62

"many of them use Signal" - where is this conclusion come from? They have WeChat. I've never seen any of my Chinese friends using Signal.

When Donald Trump threatened to block WeChat in the US expats and Chinese people alike started to download Signal. https://www.nbcnews.com/tech/security/trump-bans-wechat-some...

That's about Chinese people in the US. The headline explicitly says "people in China".

Note that even for Chinese people in the US (myself included), Signal was in my experience a pretty minor choice when Trump was trying to ban WeChat. Whatsapp, Line, etc were among the favorite alternatives.

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#63

Earlier quoted context omitted.

I would assume that any phone purchased in China is compromised by the CCP.

In what way though? Are you arguing that people should just ignore security vulnerabilities that they are aware of, on the basis that you think there might be some vulnerabilities that they're not aware of?

The linked paper literally just says "(assume the default IME app does not have these problems)" in it without justification.

This thirdparty IME concern seem really more relevant for e.g. Japan being worried about it's citizens using a compromised Baidu IME instead of a more trustworthy preinstalled Japanese one. All IMEs all can be keyloggers and the Chinese government can necessarily access Baidu data, and any smaller Chinese IMEs will be outside the auditing and enforcement jurisdiction of the Japanese government.

If you're inside China using the preinstalled OnePlus IME that "untrustworthy supposition" just already holds to the preinstalled one, and there's little reason to believe at least some of these third party IMEs are more likely to be compromised than the preinstalled one instead of less likely.

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#64
post #58
post #12

Earlier quoted context omitted.

Japanese IMEs operate basically the same way as Chinese ones.

But native OS IMEs in japan are used frequently, while in China they are not? From what I understand hiragana -> kanji conversions are formalized and thus are easy to add by dumping a dictionary, while in chinese since the phonography is informal you need to do more effort to maintain the dictionary, as everyone ends up typing in whatever they thing they think it would be in pinyin or similar AFAIK, along with all th…

The paper cited for the 68.3% figure http://web.cse.ohio-state.edu/~lin.3021/file/SEC15.pdf says that third-party IMEs are also "very popular" in Japan and Korea, though they do not cite any statistics. (Their statistics for China are from 2014. The paper was published in 2015.)

Chinese orthography is just as standardized as Japanese and hanzi/pinyin dictionaries are not harder to maintain than kanji/hiragana ones. Some people have trouble with sound distinctions in Standard Mandarin that don't exist in their speech and enter incorrect pinyin (e.g. z instead of j or zh), but that can be treated as a typo, the same as phonetic misspellings in other languages.

Support for dialectal variations is essentially nonexistent in mainstream IMEs. People who want to use varieties other than Standard Mandarin would have to use shape-based input (including methods that decompose each character into smaller parts, like Cangjie) or send a voice message. (There are projects to create IMEs for other Sinitic languages, like https://hanhngiox.net/ but almost nobody uses them.)

(Do any Japanese IMEs support non-standard dialects or even other Japonic languages?)

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#66

Earlier quoted context omitted.

It is an extreme exageration to say that the Chinese state artitrarily detaining people is due to Signal not working around the IME issue. Let's be clear: the Chinese state detains people all the time, based on many sources of information, probably the least important being interception of keystrokes to Signal in an input method app. They own all the app makers and the app stores. They can push a specific version of…

Of course signal is not the only way people get compromised in China but if the claim in TFA that 70% of Chinese users use a third party IME is correct, it seems reasonable that some of them, thinking their chat is secure, would say something that gets them in trouble. Naomi Wu has claimed this has happened and I have no reason to doubt her. Yes OWS is small, but a major security vulnerability for a country with over…

Since MSS are unlikely to tell us their decision making process it is quite opaque. It could have been CCTV, an informant, an unfounded denunciation, something they said on WeChat, one of the main compromised Chinese apps. It really isn't open to her claim this level of confidence.

If the keyboard is leaking keystrokes or word searches on a wide basis it would be difficult to hide technically. DFIR techniques for this are pretty straightforward, I'm sure plenty of people in HK could do it. Why no details?

But ultimately this is a much bigger Android problem, and won't be solved by fixing the keyboard (which OWS is obviously unqualified and ill-equipped to do). A broad ranging device lockdown guide, and OPSEC training (like [1] but for protest groups), is necessary to have anything except illusory protection. I don't think OWS should get into the business of issuing security advisories for all the platforms that they port to.

The pro-democracy groups seem to have this stuff figured out as well as you can and still have a visible protest movement. Very much following Chairman Mao: "The revolutionary must swim with the fishes."

[1] https://www.slideshare.net/grugq/opsec-for-hackers

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#68

I'll file this under "security tips". Signal should probably give its users tips for communicating securely - but that's at least one degree separate from "warn users about insecure IMEs". Additionally, if you're already using a chinese phone, why does it matter whether your IME is compromised? Doesn't the CCP already have its nose in all of the manufacturers' OSes already? Maybe Signal should warn about that as well…

> Doesn't the CCP already have its nose in all of the manufacturers' OSes already? What specifically are you saying here? Are you suggesting that every Chinese person's phone is sending off their keyboard inputs to the Chinese government even if they don't use a compromised IME? Because if not, then yes it matters whether or not your IME is compromised. Otherwise your position is just "the phone might be compromised…

> Are you suggesting that every Chinese person's phone is sending off their keyboard inputs to the Chinese government even if they don't use a compromised IME?

Yes.

You have a point about the rest, though, especially when it comes to more secure systems.

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#69
post #2

Im confused .. people are debating wether it's good to track what keyboard people use but instead of tracking which keyboard peoeple use, would it be not simpler for signal to basically build their own integrated keyboard and deactivate the android default one ?

I think the word 'track' is misleading in this context. The proposal outlines various methods to detect the use of a third-party keyboard, whereas the term 'track' commonly denotes corporate surveillance. They could do that, but it would have a maintenance cost. I do think we need to find a solution to this, however, as these personalised keyboards actually _track_ what people type. That could have real-world implica…

The word is not from me, read the messages of the issue

Re: 68.3% of people in China use third-party keyboards – many of them use Signal

#70

I remember a few days ago there was a post on hackernews to stop being mean to the people that worked at signal. The Twitter user linked in that article is railing into signal devs and she calls them assholes that don’t care about what happens outside of western society. https://twitter.com/RealSexyCyborg/status/119769537620088012...

It doesn't matter. You can compromise most of the phones (at least non rooted) if you or your people make the OS and thus also the OS level libraries that handle Text input from the IME, or even touchscreen information would be enough in most cases (unless everyone uses the randomized keyboard layout, and guard against "known plaintext" type attacks)
Post reply on HN