NEW RESEARCH: most popular Chinese keyboard app (450 million monthly users!) transmits every key typed to #Tencent in #China.
My @citizenlab colleagues found vulnerable encryption means the keystrokes could *also* be intercepted by 3rd parties.
Even in encrypted chat apps.
We did responsible disclosure.
The vulnerable encryption = fixed.
Sogou Keyboard users should update!
But they should also remain aware that everything you type still goes to the developer.
https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/