![Community banner](https://lemmy.sdf.org/pictrs/image/df7700f2-2d50-4c1c-9b1d-97a5427e48c8.png)
-
DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers in China, researchers say
cross-posted from: https://lemmy.sdf.org/post/29128134
> Archived > > A NowSecure mobile application security and privacy assessment has uncovered multiple security and privacy issues in the DeepSeek iOS mobile app that lead us to urge enterprises to prohibit/forbid its usage in their organizations. > > ... > > Key Risks Identified: > > - Unencrypted Data Transmission: The app transmits sensitive data over the internet without encryption, making it vulnerable to interception and manipulation. > - Weak & Hardcoded Encryption Keys: Uses outdated Triple DES encryption, reuses initialization vectors, and hardcodes encryption keys, violating best security practices. > - Insecure Data Storage: Username, password, and encryption keys are stored insecurely, increasing the risk of credential theft. > - Extensive Data Collection & Fingerprinting: The app collects user and device data, which can be used for tracking and de-anonymization. > - Data Sent to China & Governed by PRC Laws: User data is transmitted to servers controlled by ByteDance, raising concerns over government access and compliance risks. > > ... > > How to Mitigate the DeepSeek iOS App Risks > > >It is difficult, if not impossible, at this time to immediately mitigate the numerous security, privacy and data risks that exist in the DeepSeek iOS today. Over time, we hope the security issue will be remediated and that some of the practices impacting privacy could be addressed. But for US and EU based businesses and government agencies, it is difficult to mitigate the storage, analysis and processing of data in the People’s Republic of China. Of course, each organization can make this determination themselves and hopefully the risks outlined above provide insights and a path towards a more secure and secure iOS app. > > In the meantime, there are immediate steps companies and government agencies can take: > > 1. Immediately stop using the DeepSeek iOS app until security and privacy failures are sufficiently mitigated > 2. Determine if the data collection, privacy policy, terms of service and legal jurisdiction are issues that put your organization at risk > 3. Consider leveraging the DeepSeek open source model via hosted solutions from companies like Microsoft or via self-hosting the model (e.g. via Hugging Face) > 4. Investigate alternative AI apps that offer the DeepSeek open source model but with better security, privacy and data governance. Or consider other AI offerings that address your organization’s needs > > ...