Die Seite "Static Analysis of The DeepSeek Android App"
wird gelöscht. Bitte seien Sie vorsichtig.
I conducted a static analysis of DeepSeek, a Chinese LLM chatbot, utilizing version 1.8.0 from the Google Play Store. The objective was to determine possible security and personal privacy concerns.
I've blogged about DeepSeek formerly here.
Additional security and personal privacy issues about DeepSeek have actually been raised.
See also this analysis by NowSecure of the iPhone variation of DeepSeek
The findings detailed in this report are based purely on fixed analysis. This suggests that while the code exists within the app, there is no definitive proof that all of it is executed in practice. Nonetheless, the existence of such code warrants analysis, especially given the growing issues around information personal privacy, security, the potential misuse of AI-driven applications, and cyber-espionage dynamics between international powers.
Key Findings
Suspicious Data Handling & Exfiltration
- Hardcoded URLs direct information to external servers, raising issues about user activity monitoring, such as to ByteDance "volce.com" endpoints. NowSecure identifies these in the iPhone app the other day too.
Die Seite "Static Analysis of The DeepSeek Android App"
wird gelöscht. Bitte seien Sie vorsichtig.