Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping.

you are viewing a single comment's thread
view the rest of the comments
[–] 113 points 3 years ago (1 child)

It probably doesn't though. Obviously it's closed source making it harder to tell what's actually happening, but there's nothing stopping security analysts from looking at network usage and such. I would imagine that Google doesn't install a keylogger on every Android phone, not out of the goodness of their hearts, but because they don't want the bad publicity and lawsuits when it would inevitably be discovered.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 43 points 3 years ago* (1 child)

    they do collect usage stats by default though.
    which include typed sentences passed through their ai model and words usage counts.
    it can all be turned off and gboard seems to respect these options. it doesn't access online services unless requested with these options off.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 3 years ago* (last edited 3 years ago)

    If you mean by "collect usage stats" train their AI model on-device and send the training result to Google, then yes. If you mean that the actual words get sent to Google's servers, then no. There was a study shared recently that looked into this. Only metadata about what's typed is sent. That's not nothing of course, but it's not what Tencent does at all.

    E: Found it.

  • source
  • parent