Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror

Submission + - DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers (arstechnica.com)

An anonymous reader writes: On Thursday, mobile security company NowSecure reported that the app sends sensitive data over unencrypted channels, making the data readable to anyone who can monitor the traffic. More sophisticated attackers could also tamper with the data while it's in transit. Apple strongly encourages iPhone and iPad developers to enforce encryption of data sent over the wire using ATS (App Transport Security). For unknown reasons, that protection is globally disabled in the app, NowSecure said.

The app is “not equipped or willing to provide basic security protections of your data and identity,” NowSecure co-founder Andrew Hoog told Ars. “There are fundamental security practices that are not being observed, either intentionally or unintentionally. In the end, it puts your and your company’s data and identity at risk.”

This data, along with a mix of other encrypted information, is sent to DeepSeek over infrastructure provided by Volcengine a cloud platform developed by ByteDance. While the IP address the app connects to geo-locates to the US and is owned by US-based telecom Level 3 Communications, the DeepSeek privacy policy makes clear that the company "store[s] the data we collect in secure servers located in the People's Republic of China."

US lawmakers began pushing to immediately ban DeepSeek from all government devices, citing national security concerns that the Chinese Communist Party may have built a backdoor into the service to access Americans' sensitive private data. If passed, DeepSeek could be banned within 60 days.

Comment Re:Hmm (Score 1) 571

Well, I do now that I paid for it - but I didn't prior to buying it. I had a "lite" version, which worked OK for a while, but did not have the "source" for any of the functions/features that the paid version has. After I bought the paid version, I was sent a copy of the full theme.

This is the theme in question.

Regardless of how this GPL thing works out, it was money well spent. I could have slapped something similar together myself, but it would have taken me a while, so I'd much rather spend $50 and be done with it.

Slashdot Top Deals

The universe is like a safe to which there is a combination -- but the combination is locked up in the safe. -- Peter DeVries

Working...