Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers (arstechnica.com)
6 points by canucker2016 7 months ago | hide | past | favorite | 2 comments


Also, "...the app uses a symmetric encryption scheme known as 3DES or triple DES."

And

    Another concern is that the symmetric keys, which are identical for every iOS user, are hardcoded into the app and stored on the device.

    The app is “not equipped or willing to provide basic security protections of your data and identity,” NowSecure co-founder Andrew Hoog told Ars. “There are fundamental security practices that are not being observed, either intentionally or unintentionally. In the end, it puts your and your company’s data and identity at risk.”

    Hoog added that the DeepSeek app for Android is even less secure than its iOS counterpart and should also be removed.


Original source (12 points, 2 hours ago) https://news.ycombinator.com/item?id=42967527




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: