
DEF CON 32 - Breaking network crypto in popular Chinese keyboard apps - Jeffrey Knockel, Mona Wang
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 48:35
The video reveals that millions of users worldwide—especially in China—are sending their keystrokes over insecure, proprietary encryption in popular Chinese keyboard apps, exposing their private data to passive network eavesdroppers and state actors. These apps, including those from Soo, iFlytech, and Samsung, use weak or custom cryptography (e.g., flawed AES variants, CBC padding oracles, or no encryption at all), allowing attackers to decrypt and collect full user input with minimal effort. Even apps with TLS on iOS and Android are vulnerable due to poor implementation or lack of cryptographic integrity. The research shows that 91% of top Google Play apps use standard TLS, but only 2 of the top 45 apps on the App Store do—highlighting a systemic failure in Chinese app security. The study urges a shift from proprietary crypto to standard TLS and calls for platform-level enforcement to prevent such vulnerabilities.
Key Takeaways:
• Insecure keyboard apps transmit keystrokes in plaintext or with flawed encryption, enabling passive decryption by state actors or network eavesdroppers 5:09.
• Soo’s keyboard uses a CBC padding oracle vulnerability to decrypt keystrokes, with the IV and message being recoverable through manipulation of encrypted traffic 10:01.
• iFlytech’s Android/iOS apps use a custom AES variant in ECB mode with predictable keys derived from timestamps, allowing passive collection of all keystrokes 20:09.
• Samsung’s Chinese ROM keyboard sends keystrokes in plaintext when “suggest rare words” is enabled, offering zero privacy protection 29:18.
• A systemic lack of TLS adoption in Chinese apps—despite global standards—exposes billions of users to surveillance, with no cryptographic integrity or forward s
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Applause] and with that I hand the podium the stage and the mics off to you both hello thanks for showing up to Devcon on a Sunday morning I'm Jeff this is Mona our talk will eventually be about how certain State actors probably knew what almost every Chinese speaker in the world was typing at any time but before we get there we first have a little background we have to do uh what's a Chinese keyboard well it's something that has a Chinese IM or input method editor in built into it uh if you're like me though you probably are only familiar with keyboards like this uh there's just enough buttons for all the letters in your alphabet so typing in your language is actually pretty easy but if you've ever had to use a device like this you might know what the problem is there's fewer buttons tha…