this post was submitted on 24 Aug 2023
105 points (96.5% liked)

Privacy

29831 readers
701 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS
 

I was taking a look at the Naomi Wu situation (A Chinese DIY tech youtuber who went missing after being watched by the government) and in one part they mentioned that she was concerned about her privacy, so started using Signal, but had a default chinese keyboard that had a keylogger and the police had looked into what she was talking on there.

I'm not sure if it was a mobile only thing, but it was mentioned that the keyboard app was used in like 70% por chinese smarthphones.

Now, I use AnySoftKey and refuse to use default keyboard apps, but how far can we reach on the keyboard security thing? Is typing on a computer or using a physical keyboard on a mobile device 100% safe? I think the keyboard issue is often overlooked and would like to know what recommendations your have? Or what should be known more?

(page 2) 24 comments
sorted by: hot top controversial new old
[–] [email protected] 2 points 10 months ago (10 children)

On a standard computer, be it a desktop or laptop, it's very hard to effectively avoid keylogging.

I don't say you 100% have a keylogger on your PC, that's not my point.
My point is that both on Windows, and on Linux systems that use the X11 window system instead of Wayland, any program can log your let presses with basically no effort.
On windows this is somewhat restricted when a program opens a secure desktop (a temporary "desktop", usually (always?) with a single window). This happens when you have to grant admin rights to a program, but other programs can request such a thing too, like the keepass password manager can be set to prompt for the password on a secure desktop. I don't know if the X11 window system of Linux has a similar feature.

But, as the other commenter said too, it depends on your threat model, because it can go a lot deeper than your choice of keyboard app.
If you use the original system of your smartphone, the manufacturer may have hidden software in it that can log your key presses even without cooperation if your keyboard app.
But if the modem - which is basically a different operating system that runs in parralel to the main one, but with the purpose of handling the connection with the cellular network, besides doing quite a few other things too - could get compromised, often it could be used to have open access to all the hardware that your main, android operating system uses. How is this on topic? This way intruders could observe where do you touch the touch screen, among a lot of other things.

load more comments (10 replies)
[–] [email protected] 1 points 10 months ago (1 children)

I think the keyboard issue is often overlooked and would like to know what recommendations your have? Or what should be known more?

Overlooked? Not really, for years I have never used built-in keyboard from stock rom, keyboards from goolag store or goolag board.

Most people stick with non-foss keyboards just because it's convenient

[–] [email protected] 2 points 10 months ago

I can't lie, gboard is incredible, especially since I use two languages, and I don't have to switch the language every time, it just figures out which language to autocorrect to. switched to open board either way, but I do miss the convenience of gboard

load more comments
view more: ‹ prev next ›