OUTVIVID Telegram 4284
The Citizen Lab 发现,腾讯公司开发的搜狗输入法在上传用户的输入数据到服务器时(官方称是用于云输入服务),使用了 HTTP 配合自行开发的 EncryptWall 加密方案,而非标准 HTTPS*。骇客可以利用 CBC padding oracle attack 及云端对于合法/非法 padding 的密文的不同回应解密客户端向云端的请求,并还原出 Windows/Android 用户输入的(拼音)内容。

建议搜狗输入法用户更新至最新版本,例如 13.7 (Windows)、11.26 (Android) 或 11.25 (iOS)。

另外值得提到的一点是,由于 citizenlab.ca 在中国大陆被墙,腾讯的邮件服务器可能无法回复邮件给 @citizenlab.ca 的漏洞报告邮箱;最后漏洞报告者使用了另外的 @utoronto.ca 邮箱与腾讯进行联系。

https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/
seealso: HackerNews:37063568

* iOS 版本软件在上传这些数据时使用了 HTTPS。

linksrc: https://www.tgoop.com/billchenla/18902

#Sogou #Tencent #Privacy #DontRollYourOwnCrypto



tgoop.com/outvivid/4284
Create:
Last Update:

The Citizen Lab 发现,腾讯公司开发的搜狗输入法在上传用户的输入数据到服务器时(官方称是用于云输入服务),使用了 HTTP 配合自行开发的 EncryptWall 加密方案,而非标准 HTTPS*。骇客可以利用 CBC padding oracle attack 及云端对于合法/非法 padding 的密文的不同回应解密客户端向云端的请求,并还原出 Windows/Android 用户输入的(拼音)内容。

建议搜狗输入法用户更新至最新版本,例如 13.7 (Windows)、11.26 (Android) 或 11.25 (iOS)。

另外值得提到的一点是,由于 citizenlab.ca 在中国大陆被墙,腾讯的邮件服务器可能无法回复邮件给 @citizenlab.ca 的漏洞报告邮箱;最后漏洞报告者使用了另外的 @utoronto.ca 邮箱与腾讯进行联系。

https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/
seealso: HackerNews:37063568

* iOS 版本软件在上传这些数据时使用了 HTTPS。

linksrc: https://www.tgoop.com/billchenla/18902

#Sogou #Tencent #Privacy #DontRollYourOwnCrypto

BY 层叠 - The Cascading




Share with your friend now:
tgoop.com/outvivid/4284

View MORE
Open in Telegram


Telegram News

Date: |

As of Thursday, the SUCK Channel had 34,146 subscribers, with only one message dated August 28, 2020. It was an announcement stating that police had removed all posts on the channel because its content “contravenes the laws of Hong Kong.” On Tuesday, some local media outlets included Sing Tao Daily cited sources as saying the Hong Kong government was considering restricting access to Telegram. Privacy Commissioner for Personal Data Ada Chung told to the Legislative Council on Monday that government officials, police and lawmakers remain the targets of “doxxing” despite a privacy law amendment last year that criminalised the malicious disclosure of personal information. SUCK Channel Telegram So far, more than a dozen different members have contributed to the group, posting voice notes of themselves screaming, yelling, groaning, and wailing in various pitches and rhythms. To edit your name or bio, click the Menu icon and select “Manage Channel.”
from us


Telegram 层叠 - The Cascading
FROM American