this post was submitted on 28 Aug 2024
534 points (96.5% liked)

Privacy

31998 readers
882 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] heavyboots@lemmy.ml 8 points 2 months ago (1 children)

As an example of this, I believe SexyCyborg got in trouble for reporting on leaks via people's 3rd party Chinese language keyboards. So her theory is that the keyboard apps people had installed leaked data when Hong Kong protesters were communicating with the press, rather than the actual Signal app. But… as stated above, people have to take responsibility for their device and in this case, they had chosen to install apps with leak issues into the communication process.

[–] socsa@piefed.social 6 points 2 months ago (2 children)

This is precisely why opsec is more than just an app.

Leaky keyboards are a possibility, but what is actually far more likely is just that someone on the signal group chat was a mole who was archiving the traffic for the party. Signal has since made efforts to bring anonymous accounts to the platform, which will help thwart such attacks. Though against a state actor it is still not enough unless you take additional measures to obfuscate traffic. And then that still doesn't protect you against some CCP brownshirt from tailing you and then snatching your phone out of your hand when you unlock it.

[–] milicent_bystandr@lemm.ee 3 points 2 months ago

Leaky keyboards are more than a possibility. Sogou, the biggest one for Chinese typing, got found out a year or so ago for having terrible client-server encryption. They fixed it in an update, but many people didn't get the update - not to mention it's still sending every keystroke to Tencent (are the owners I think?) so they could also be saving and analysing private typing anyway.