Usunięcie strony wiki 'Static Analysis of The DeepSeek Android App' nie może zostać cofnięte. Kontynuować?
I conducted a fixed analysis of DeepSeek, a Chinese LLM chatbot, utilizing variation 1.8.0 from the Google Play Store. The objective was to determine potential security and privacy problems.
I’ve blogged about DeepSeek formerly here.
Additional security and privacy concerns about DeepSeek have been raised.
See also this analysis by NowSecure of the iPhone variation of DeepSeek
The findings detailed in this report are based purely on static analysis. This means that while the code exists within the app, there is no conclusive evidence that all of it is executed in practice. Nonetheless, the existence of such code warrants analysis, specifically provided the growing issues around information personal privacy, monitoring, the prospective misuse of AI-driven applications, and cyber-espionage dynamics in between worldwide powers.
Key Findings
Suspicious Data Handling & Exfiltration
- Hardcoded URLs direct information to external servers, raising issues about user activity monitoring, such as to ByteDance “volce.com” endpoints. NowSecure determines these in the iPhone app yesterday too.
Usunięcie strony wiki 'Static Analysis of The DeepSeek Android App' nie może zostać cofnięte. Kontynuować?