3 ms·
To be fair, there is no evidence that CIQ is "breaking the HTTPS handshake". The article I read implied that the software had access to keystrokes, which could
by sharkbot 15y ago
To be fair, there is no evidence that CIQ is "breaking the HTTPS handshake". The article I read implied that the software had access to keystrokes, which could be used to infer data that would be encrypted on the wire, not that it was breaking HTTPS.
It's possible that CIQ is getting keystroke information, but only storing metadata (character counts, number of corrections, etc). But, without more evidence, it's best to be wary. I think John raises a valid point; crack open a debugger, disassemble the .dex, start a network sniffer. Find out what is happening, don't just assume.
Edit: fixed minor typo.
- jgrahamc 15y agoAnd my reward for making a valid point is to be downvoted and have my submission flagged. It is really tiresome that people on Hacker News would rather continue in a circle jerk fashion with a narrative that excites them rather than using their heads to examine what's really happening. And if it does turn out that my keystrokes are being sent to some third-party company in the US then I'll be the first to sign up for the class action lawsuit.
- mukyu 15y agoYour blog post is basically content-free and makes more sense as the comment you already made on a submitted story. I actually upvoted your other post on the story as it was too grey for my taste (making an honest attempt at on-topic discussion), but downvoted the comment I'm reply to as it is strictly noise.