Submitted via IRC for SoyCow8963
Security researchers from Adguard have issued a warning that the popular GO Keyboard app is spying on users. Produced by Chinese developers GOMO Dev Team, GO Keyboard was found to be transmitting personal information about users back to remote servers, as well as "using a prohibited technique to download dangerous executable code."
Adguard made the discovery while conducting research into the traffic consumption and unwanted behavior of various Android keyboards. The AdGuard for Android app makes it possible to see exactly what traffic an app is generating, and it showed that GO Keyboard was making worrying connections, making use of trackers, and sharing personal information.
[...] Within the app description, the developers say:
PRIVACY and security
We will never collect your personal info including credit card information. In fact, we cares for privacy of what you type and who you type! [sic]But Adguard points out that this is contradicted by the company's privacy policy. In addition to this, GO Keyboard shares personal information right after installation, communicates with dozens of tracking servers, and has access to sensitive data on phone. Adguard concedes that this is fairly typical for modern apps, but goes on to say that the app violates Google Play policies.
The apps in question are:
Source: https://betanews.com/2017/09/21/go-keyboard-spying-warning/
(Score: 2) by quacking duck on Monday September 25 2017, @01:55PM
Auto-fill in this context should be the responsibility of the app that's being typed into, not the keyboard being typed on.
To verify this (on iOS anyway), I went into the default Mail.app and, using Google's Gboard (which does NOT have permission to access to my contacts), typed the first few letters into the "To" field of someone in my Contacts app that I've never actually emailed before, and it autofilled their name just fine. I then tested it in the Messages app, with the first few digits of a phone number this time (for a contact I've never called or texted before, the police non-emergency number), and again it autofilled fine.