Ez ki fogja törölni a(z) "Static Analysis of The DeepSeek Android App"
oldalt. Jól gondold meg.
I carried out a static analysis of DeepSeek, a Chinese LLM chatbot, using version 1.8.0 from the Google Play Store. The objective was to identify potential security and privacy issues.
I have actually discussed DeepSeek previously here.
Additional security and personal privacy issues about DeepSeek have actually been raised.
See also this analysis by NowSecure of the iPhone version of DeepSeek
The findings detailed in this report are based purely on static analysis. This suggests that while the code exists within the app, there is no conclusive proof that all of it is executed in practice. Nonetheless, the existence of such code warrants scrutiny, particularly given the growing issues around information privacy, monitoring, the potential abuse of AI-driven applications, and cyber-espionage dynamics in between international powers.
Key Findings
Suspicious Data Handling & Exfiltration
- Hardcoded URLs direct data to external servers, raising issues about user activity monitoring, such as to ByteDance "volce.com" endpoints. NowSecure determines these in the iPhone app the other day too.
Ez ki fogja törölni a(z) "Static Analysis of The DeepSeek Android App"
oldalt. Jól gondold meg.