"Baidu IME" and "Simeji" send the conversion string without permission, NISC reveals the ministry
The Japanese input system "BAIDU IME" for Windows provided by Baidu Co., Ltd. and the Japanese input system "Simeji" for Android turn off the "cloud input" that converts it in cooperation with the server on the cloud.Even in the state, it was found that the Cabinet Secretariat Information Security Center (NISC) had been warning the central government, saying that input information was sent to the server.The Ministry of Education, Culture, Sports, Science and Technology is also paying attention to domestic universities.
NISC calls for creating confidential documents to turn off the function of sending information to an external server in the Japanese input system, or if it cannot be turned off.
According to Net Agent Co., Ltd., as a result of investigating Baidu IME and Simeji, even if the "cloud input" function is turned off in cooperation with the server on the cloud, the conversion confirmed character string is sent to the server.It turns out that it is doing.The information is sent only for full -width input, and it is not transmitted if only half -width input is input.
In the case of Baidu IME, the transmitted information is the conversion confirmed character string, the security identifier SID of the Windows PC, the path name of the application used, the Baidu IME version.In some cases, Windows user names may be sent from the application path name.
In the case of Simeji, the conversion confirmed character string, the individual terminal identifier with UUID, the device name used, the package name of the application used, and the Simeji version are sent.
In response to this matter, the Internet agent has advised that Baidu IME and Simeji will improve, but it may be better to refrain from using them until the version upgrade is improved.
[Postscript 12/27] Baidu Co., Ltd. announced his opinion on IME information transmission on the 26th.Baidu IME and Simeji explained that they will not send information if they have not obtained the permission of the cloud or log information.However, for Simeji, even if the cloud transmission is set off, a version has been revised, as if the input string was transmitted by the implementation bug.In addition, Baidu IME has improved the point that prior license setting has been improved.
[Postscript 2014/1/6] Baidu Co., Ltd. version of BAIDU IME on the 30th.5.2.It has been updated to 9 "and announced that the cloud conversion has changed the state of" off "as the default setting.It is said that the terms of use have been improved to make it easier to understand.