Menu
EN

Go spy, GO! Popular app with 200M+ users crosses the red line

UPDATED on 25.09.2017, details are in the bottom of the article

Have you ever thought that your keyboard could be a professional spy? And we are not talking about jamesbondish handsome spies from Hollywood movies, but about the overt and constant home phoning of the personal information with its future distribution to third parties. Our recent research discovered a popular Android keyboard to spy on its users, with tons of personal information being sent to remote servers and using a prohibited technique to download dangerous executable code.

The goal of the research was to investigate keyboards' traffic consumption, unwanted behavior and demonstration of ads, and what users' private data they send to their servers and third-parties. We decided to test keyboard apps after the [recent story](https://blog.adguard.com/en/keyboard_ads/) with TouchPal, a keyboard, that started showing ads to HTC devices users right in the typing area. Why does it matter? A keyboard is an input tool wherethrough almost all your valuable private data passes. Just imagine, you enter your logins, passwords, texts of emails, and messages using your keyboard, and then - everything is sent (maybe even sold) to third-parties. GO Keyboard has become an absolute "champion" in this field. This app offers a "smart" keyboard with various colorful and attractive themes. It has 200M+ users all over the world and is developed by the Chinese GOMO Dev Team.

How did we conduct the research

Besides being a popular ad blocker and a privacy protection utility, AdGuard for Android is also an excellent tool for inspecting the apps' traffic. The mighty filtering log shows you what exact web requests do your apps send, and the option to record a HAR (Http Archive) file lets you look into the request's body.

The Mighty Filtering Log

What you should know about the notorious Go keyboard

  • It has 2 versions (first, second) in Google play;
  • It has 200M+ downloads;
  • It advertises itself as "We will never collect your personal info including credit card information. In fact, we cares for privacy of what you type and who you type!":
  • Its privacy policy contradicts this statement;
  • It communicates with dozens of third-party trackers and ad networks. It also downloads over 14 MB of data and sends quite a lot of information about you right after the installation.
  • It has access to sensitive data including your identity, phone calls log, contacts, microphone.

Unfortunately, everything listed above is a norm nowadays. Recent research showed that 7 in 10 mobile apps share your data with third-party services. However, this developer crossed the red line and directly violated the Google Play content policies - malicious behavior section.

The red line

Apps that steal a user’s authentication information (such as usernames or passwords) or that mimic other apps or websites to trick users into disclosing personal or authentication information.

Without explicit user consent, the GO keyboard reports to its servers your Google account email in addition to language, IMSI, location, network type, screen size, Android version and build, device model, etc.

GO Steals Your Email

Apps or SDKs that download executable code, such as dex files or native code, from a source other than Google Play.

Shortly after the installation, both apps downloaded and executed code from a remote server, directly violating this policy. Some of the downloaded plugins are marked as Adware or PUP by multiple AV engines.

GO Downloading Adware

What's important, given the apps' extensive permissions, remote code execution introduces severe security and privacy risks. At any time the server owner may decide to change the app behavior and not just steal your email address, but do literally whatever he or she wants. Remember, it's a keyboard, and every important bit of information you enter goes through it!

We informed Google of these violations and are waiting for their reaction. Whatever their decision is, we find this behavior unacceptable and dangerous. Having 200+ Million users does not make an app trustworthy. Do not blindly trust mobile apps and always check their privacy policy and what permissions do they require before the installation.

HAR files and plugins are available here.

UPDATE (25.09.2017): Almost every GO app (including even GO Music) has received an update on September 22. We have re-evaluated both keyboard apps and can confirm that the violations are gone now.

Liked this post?
By downloading the comments you agree the terms and policies

AdGuard
for Windows

AdGuard for Windows is more than an ad blocker. It is a multipurpose tool that blocks ads, controls access to dangerous sites, speeds up page loading, and protects children from inappropriate content.
User Reviews: 18562
4.7 out of 5
By downloading the program you accept the terms of the License agreement
Read more

AdGuard
for Mac

AdGuard for Mac is a unique ad blocker designed with macOS in mind. In addition to protecting you from annoying ads in browsers and apps, it shields you from tracking, phishing, and fraud.
User Reviews: 18562
4.7 out of 5
By downloading the program you accept the terms of the License agreement
Read more

AdGuard
for Android

AdGuard for Android is a perfect solution for Android devices. Unlike most other ad blockers, AdGuard doesn't require root access and provides a wide range of app management options.
User Reviews: 18562
4.7 out of 5
By downloading the program you accept the terms of the License agreement

AdGuard
for iOS

The most advanced ad blocker for Safari: it makes you forget about pop-up ads, speeds up page loading, and protects your personal data. A manual element-blocking tool and highly customizable settings help you tailor the filtering to your exact needs.
User Reviews: 18562
4.7 out of 5
By downloading the program you accept the terms of the License agreement

AdGuard Browser extension

AdGuard is the fastest and most lightweight ad blocking extension that effectively blocks all types of ads on all web pages! Choose AdGuard for the browser you use and get ad-free, fast and safe browsing.
User Reviews: 18562
4.7 out of 5

AdGuard for Safari

Ad blocking extensions for Safari are having hard time since Apple started to force everyone to use the new SDK. AdGuard extension is supposed to bring back the high quality ad blocking back to Safari.
User Reviews: 18562
4.7 out of 5
Available on the
App Store
Download
By downloading the program you accept the terms of the License agreement

AdGuard Home

AdGuard Home is a network-wide software for blocking ads & tracking. After you set it up, it’ll cover ALL your home devices, and you don’t need any client-side software for that. With the rise of Internet-Of-Things and connected devices, it becomes more and more important to be able to control your whole network.
User Reviews: 18562
4.7 out of 5

AdGuard Content Blocker

AdGuard Content Blocker will eliminate all kinds of ads in mobile browsers that support content blocker technology — namely, Samsung Internet and Yandex.Browser. While being more limited than AdGuard for Android, it is free, easy to install and still provides high ad blocking quality.
User Reviews: 18562
4.7 out of 5
By downloading the program you accept the terms of the License agreement
Read more

AdGuard Assistant

A companion browser extension for AdGuard desktop apps. It offers an in-browser access to such features as custom element blocking, allowlisting a website or sending a report.
User Reviews: 18562
4.7 out of 5
Assistant for Chrome Is it your current browser?
Install
By downloading the program you accept the terms of the License agreement
Assistant for Firefox Is it your current browser?
Install
By downloading the program you accept the terms of the License agreement
Assistant for Edge Is it your current browser?
Install
By downloading the program you accept the terms of the License agreement
Assistant for Opera Is it your current browser?
Install
By downloading the program you accept the terms of the License agreement
Assistant for Yandex Is it your current browser?
Install
By downloading the program you accept the terms of the License agreement
Assistant for Safari Is it your current browser?
If you can't find your browser, try the old legacy Assistant version, which you can find in AdGuard extension settings.
Downloading AdGuard To install AdGuard, click the file indicated by the arrow Select "Open" and click "OK", then wait for the file to be downloaded. In the opened window, drag the AdGuard icon to the "Applications" folder. Thank you for choosing AdGuard! Select "Open" and click "OK", then wait for the file to be downloaded. In the opened window, click "Install". Thank you for choosing AdGuard!
Install AdGuard on your mobile device