Virtual Keyboard Developer Leaked 31M Client Records
mackeepersecurity.com
mackeepersecurity.com
Things like: “your Mac has been infected, click here” while the user is downloading some torrent or watching porn. Faking the system's dialog boxes, using chatbots “is your Mac slow?”, etc.
I'm amazed Apple hasn't banned them from the Mac App Store. I don't know how these people sleep at night.
Are you talking about Apple management or the malware developers?
Never attribute to malice…
After that, I installed uBlock Origin for her.
They're the worst.
The problem I see, a smartphone is me thing. A PC of your lawyer, your doctors is a hell another dimension. And unfortunately it's a group of jobs like these that run on Windows Professional often without an admin or AD server. Guess what, it's a wet dream for them.
I have a suspicion that due to how cheap bulk storage is these days, that companies collect as much information as they can get away with in hopes that _maybe_ it will be useful one day. That mixed with poor security practices is just going to keep leading to these sorts of events happening.
https://techcrunch.com/2014/10/04/everything-you-need-to-kno...
I was never sure what "Full Access" meant, other than keyboard data (including keystroke recording if the dev wanted it) going forward. But surely it doesn't mean everything, as in access to keyboard-non-related data (user photos, etc).?
https://developer.apple.com/library/content/documentation/Ge...
The gist of it is that requesting "full access" allows them to access the internet and some other bits automatically, but they need to ask for further permissions for photos, location, contacts, etc.
I tried some alternate ones for swype style typing, but frankly they were all worse than the stock Google keyboard from my days on Android so I gave up on it and learned to type with my thumbs again.
Bummer that it has a giant search bar at the top of the keyboard, which is an enormous waste of space on an iPhone SE. If you don't give it full access, the same space is used to constantly beg for full access to turn on the search bar, and accidentally touching that will pull you out of your app over to the Gboard app, which gives you a button to open the Settings app.
I can see why they do it. No way to serve ads to the keyboard, so searches are the only way to make money off of it. Shame they had to crap it up though, I'd have happily paid money for this keyboard, but I think I'll have to pass.
In keeping with this thread, I'm not that into the idea of giving Google access to my keystrokes even if they pinky-swear to not use them. We're talking about the same company currently being sued for deliberately working around iOS's privacy protections:
https://9to5mac.com/2017/11/30/google-safari-work-around-cla...
EDIT - the search prompt actually only pops up if you bump the G button at the left side, otherwise the bar is text predictions once you start typing. Maybe I'll give this a shot.
Android version definitely lets you disable the G button. It's listed right next to the "Predictive search" setting, so I'm fairly sure this can not be disabled on iOS. https://www.ghacks.net/2016/12/19/remove-g-button-android-ke...
1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some small to moderate fines, depending on each case.
2) Collect whatever you want (while still mentioning it in your Privacy Policy, and the whole thing). But if you suffer a data breach, and that data is exposed, you should need a big fat banking account to survive the fine that will be imposed on you. The fines should be big enough that they should deter even the big players from collecting too much of the data they don't need.
UPD: For example, we often hear news about hackers from some Eastern European country that were obtaining personal information in large quantities. Their actions are very similar to what the developers of this keyboard did.
If you don't trust the keyboard developer to not be an idiot with your keystrokes, better to not give that access.
Is this simply frequently typed emoji/words?
One of the revelations that came out of the "binary option" fiasco is that it's legal in Israel to scam non-Israelis.[1] Financed by the binary option industry, which is 40% of Israel's financial sector, Israel's organized crime sector has become much larger. They need sucker lists for marketing. Data from phones is a good way to figure out who has spare cash.
Although a recent law change in Israel is expected to shut down the binary option industry next January, the law is very narrow. The scammers are moving to "forex" and initial coin offerings.[2]
[1] https://www.timesofisrael.com/knesset-committee-to-vote-mond... [2] https://www.timesofisrael.com/cryptocurrencies-may-be-the-ne...
And the understatement of the year award goes to...
What an amazing future we live in.
Aside from the spacing/layout/etc. preferences from a soft keyboard, they function differently. Samsung's default keyboard is by far the worst thing to work with from a development standpoint. I've never had an issue working with any other soft keyboard, but the way Samsung handles certain input events is orthogonal to other major keyboards.
I found some, but I realized the hardware was basically a keylogger with a little extra code. Made me too uncomfortable to suggest it to my coworkers.
Apple, Google, Microsoft have shown no interest in wanting to actively prevent these apps from being on the app store [1], [2], try spotting the fakes.
And the fact that there is no legislation against this behaviour, and there's no real way to punish leaks like this in a purely objective way.
Welcome to the 21st century I guess?
[1]: https://fnd.io/#/us/search?mediaType=ios&term=whatsapp
[2]: https://play.google.com/store/search?q=whatsapp%20messenger&...
Do they have to drive to your house to find out where they can break in or can they see from Google StreetView? Do they have to collect a whole bunch of phone books to find out your name+number or is it readily available in a dataset online? Can they just access your PC without hindrance or do they need to strap you to a torture rack to get your password out of you?
And just as well, information loses value over time. Either because it's not anymore correct / particularly relevant, or because it's covered up by more accessible information.
Why worry about fingerprinting one user's browser when billions of people don't even clear their cookies? Why sift through a data leak of 10000 people when a data leak with millions of people is just as well available? Why try to steal the identity of that guy who's data got leaked in one data leak, if there's this other guy with cross-referencable entries in 8 data leaks?
As such, it's still always going to be worth something to try to reduce your data footprint. If you're smarter about your data than most other people are, you'll stop being interesting to data brokers, because you're just too much effort.
Welll... i wonder whether they kept all that data?
> Phone number,
> full name of the owner,
> IMEI number
> links and the information associated with the social media profiles (birthdate, title, emails etc.)
What's wrong with their users? Why would a keyboard app need this information?
At least I would not install an app requiring those permissions. And I allow the Android phone to connect to the Internet only via my firewall (of course Google servers are blocked from the start).
These are the new oil spills.
This systematic data collection is really annoying and hard to avoid today.
"One flaw is that the default settings of a MongoDB database would allow anyone with an internet connection to browse the databases, download them, or even worst case scenario to even delete the data stored on them"
Unless a product requires certification to use it can’t rely on expert knowledge to provide safety.
Of course, from a security standpoint, people will still make mistakes like this, but the onus is NOT on the tool developers. They make it configurable for a reason.
Is it really that difficult to require someone to set a secure password before a product is usable?