Over a billion users could be at risk from keyboard logging app security flaw


by TechRadar

TechRadar— Most Chinese mobile manufacturers used vulnerable keyboards which relayed keystrokes in plain text.

MIT Technology Review—Almost every Chinese keyboard app has a security flaw that reveals what users type. Almost all keyboard apps used by Chinese people around the world share a security loophole that makes it possible to spy on what users are typing.  The vulnerability, which allows the keystroke data that these apps send to the cloud to be intercepted, has existed for years and could have been exploited by cybercriminals and…

TechSpot—Nearly all Chinese keyboard apps have encryption flaws, exposing millions of users to keylogging. Researchers recently discovered severe encryption flaws in cloud-based pinyin input software from eight companies that could allow eavesdropping. Although there is no evidence that the vulnerabilities are actively being exploited, earlier incidents make this a potentially serious issue.Read Entire Article

Tech Times—US Government Warns of Security Flaw in Chirp Systems' App, Risking Smart Home Locks Control. This vulnerability, detected in a smart access control system widely deployed across rental properties in the US, permits unauthorized individuals to manipulate any lock within the affected premises remotely.