3 ms·
Answering my own question in case others find it helpful. Here's the original source of the research. https://citizenlab.ca/2024/04/vulnerabilities-across-keyb
by arcastroe 2y ago
Answering my own question in case others find it helpful. Here's the original source of the research.
https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/ https://citizenlab.ca/2024/04/vulnerabilities-across-keyboar...
> While many keyboard apps operate locally, solely within a user’s device, IME-based keyboard apps often have cloud features which enhance their functionality. Because of the complexities of predicting which characters a user may want to type next, especially in logographic languages like Chinese, IMEs often offer “cloud-based” prediction services which reach out over the network. Enabling “cloud-based” features in these apps means that longer strings of syllables that users type will be transmitted to servers elsewhere
- pheatherlite 2y agoWhat the f... woah
- LinuxBender 2y agoInteresting. Testing this myself I have an uleFone running Android and when I pull up the text messaging interface there is a load of isakmp traffic to t-mobile and it continuously talks to Google AS15169 over HTTPS I assume for RCS. Every character I type creates a burst of isakmp vpn traffic. LTE over Wifi I've not installed any keyboard apps, this is the bog standard uleFone. This happens even if I disable smart-reply and I always disable the Let others know when I am typing. I must be missing a setting somewhere. It's odd that if RCS uses Google over HTTPS then I dont know why it sends so many packets for each character I type to TMO over their VPN / isakmp especially since I have not sent a message. The isakmp packet rate is reduced slightly if I disable spell checking which allowed me to change more settings that were greyed out. I guess my question is why would my phone mirror all my keypresses to both TMO over their VPN and to Google over RCS in bigger bursts vs keypress, all without my actually sending a message? It appears that to debug this I have to install Magisk to use my Squid SSL Bump proxy but I doubt that will help my with the isakmp traffic unless they bootstrap the preshared secret over HTTPS on a domain not using public key pinning which Google has on several subdomains.