Static Analysis of The DeepSeek Android App
vitocuthbertso урећивао ову страницу пре 1 месец


I carried out a fixed analysis of DeepSeek, a Chinese LLM chatbot, using variation 1.8.0 from the Google Play Store. The objective was to determine prospective security and privacy issues.

I've discussed DeepSeek previously here.

Additional security and privacy concerns about DeepSeek have actually been raised.

See likewise this analysis by NowSecure of the iPhone variation of DeepSeek

The findings detailed in this report are based simply on fixed analysis. This implies that while the code exists within the app, there is no definitive evidence that all of it is executed in practice. Nonetheless, the existence of such code warrants scrutiny, particularly offered the growing issues around information privacy, security, bybio.co the prospective misuse of AI-driven applications, and cyber-espionage characteristics between worldwide powers.

Key Findings

Suspicious Data Handling & Exfiltration

- Hardcoded URLs direct information to external servers, raising issues about user activity tracking, such as to ByteDance "volce.com" endpoints. NowSecure recognizes these in the iPhone app yesterday too.