South Korean regulator accuses DeepSeek of sharing user data with ByteDance
bbc.com
bbc.com
Here's the SecurityScoreCard article that brought attention to this: https://securityscorecard.com/blog/a-deep-peek-at-deepseek/#...
Besides the usual analytics data (device metadata, user behavior, app performance, errors, etc), it's possible raw chat data is being shared as well, but it's not a smoking gun.
[1] https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers...
question: does the DeepSeek's app use of hardcoded encryption keys rise beyond just their attempt to obfuscate and protect their app's private API endpoints? I believe this an attempt to make abusing their mobile app's private web APIs more difficult since even with cert-pinning disabled and HTTPS MITM'd you still can't observe the real traffic and replicate their requests.
If all its doing is obfuscation though, then I don't understand why pointing out that the keys are hardcoded is meaningful. It certainly doesn't engender trust. But if the app's binary is ultimately decoding some encrypted data, it needs the key, meaning it's ultimately available to the reverse engineer. Whether it's hardcoded or not doesn't matter.
It's a bad look, but if the app used the latest tech and assigned each client its own symmetric encryption key for a session, wouldn't you still be able to access the same data? What would be meaningfully different from a security perspective if they had done this obfuscation better?
[1] https://www.nowsecure.com/blog/2017/12/29/enable-ios-app-tra...
[2] https://developer.apple.com/news/?id=12212016b
[3] https://www.klundberg.com/blog/app-transport-security-delay/
In fact, I wonder if it may further underscore their concerns, given that it surfaces the interconnectedness between all of these firms.
This is the reason, say, revelations about interconnectedness matter when it comes to Chinese apps versus U.S. apps.
You may disagree about whether there should be cause for concern, but that's another matter.
But, if you're asking me if I personally think there's cause for concern around allowing a foreign adversary access to your citizenry via social media platforms, then the answer is yes.
And, of course, China itself also believes it's a problem, which is why U.S. social media is banned there.
>For anyone who doesn't already think Chinese apps are automatically their adversary...
I think we're drifting from the original context. My point was that some people, including many in U.S. Congress, do take issue with at least some Chinese apps (let's just say TikTok here). This concern is at least partially WRT its data collection/handling and espionage. So any other apps that connect to it (or its parent company's products) and provide data would obviously also be viewed as problematic.
Incidentally, this isn't necessarily related to whether that other app is China-based.
You brought in the question of whether U.S. companies would face similar scrutiny for connecting to other U.S. companies, and I was merely explaining the difference.
No one cares about the details. (Heck, I'd be willing to wager good money that the politicians and most of their staffers don't even understand the details). In the end, it's just one more reason that Chinese models will not be legal in the US in the near future.
This isn't about the model, it's about the mobile app.
The open source model weights are different from the website and the app. The model cannot track you.
Not just Congress, even techies can be confused about these things.
Following typical tropes about China, "we" decided to ban space cooperation with them because they were just going to steal American space tech or whatever. That's why, to this day, you never see Chinese on the ISS. Of course China then became the 2nd largest player in space, behind only SpaceX, launched and manned their own space station, sent a rover to Mars, carried out unprecedented sample return missions from the dark side of the Moon, and just generally ran circles around the US sans SpaceX.
If it wasn't for this dumb law, it's likely NASA would have been able to use Russia, China, and SpaceX as redundancies for getting Americans to the ISS as one country/company fell out of favor with this administration or that. As was we ended up turning to Boeing for a redundancy. For those that don't follow space news, the 2 astronauts Boeing [barely] sent to the ISS are still stranded up there after their vessel was deemed too dangerous to return in.
I oft wondered what it would have been like to live in Rome circa 460.
anyways, hoping its not so bad!
Maybe it cannot but can it say inject a tracker in suggested code https://news.ycombinator.com/item?id=43121383
South Korea bans new DeepSeek AI downloads
Secondly, most data in China is shared among most companies anyway, because, firstly, the government (not necessarily CCP) orders most companies to share data with "technological leaders" and "strategically important" companies, and secondly because computer security is mostly an alien concept to Chinese.
Copyright (broadly speaking, most restrictions on unrestricted dissemination if data) is what is killing the US economy.
that's the main reason
i don't know how the situation is elsewhere, but in China, 2/3 of startups expose their databases on public network with a password 'abc123'
security is not a requirement for many startups, velocity is
You, personally, set the password to a public internet-facing database to 'abc123'?
And if you really did, how much do you estimate that increased your 'velocity'?
a month later, your manager decided to share it with other teams, the decision was made in a meeting which you're not invited
when the manager came to you, you asked:
- how about give me a week to make it a saas, with authn/authz
- no, we don't have the time, just tell them the endpoint and the password
another month later, something changed, your company built a partership with another company, your manager decided to share the project with teams in the other company
you asked:
- how about we do something like virtual network peering so that we can share a connected network with our parter
- it's complex, we can not change the network status of our partner, and we don't have a responsible role for this work, just give them the endpoint and the password
password 'abc123' is just a analogy, in this case, there's no password at all
They designate who is strategic, and those designated strategic tell them what kind of data they need.
(1) all videos are captioned, automatically then often again by the content creator manually. This data alone is extremely valuable for training purposes.
(2) the videos contain great information about slang terms, and youth vernacular. Which is unique data that is harder to find elsewhere.
(3) young people seem to use TikTok as a search engine, so presumably some of the videos' content must be explicitly valuable enough as an information source, similar to YouTube.
I mean when I visit a random website or open a random app, I kind of expect that it will use something like Google Analytics or Firebase Crashlytics so that my "user data" is shared with Google.
If the article wants me to feel outraged about this practice, I don't. I understand that analytics and performance monitoring are often outsourced to a third party, often without a choice of turning off the analytics and performance monitoring features in the first place.
I use the DeepSeek app happily without giving it any data I consider private. I have a separate local DeepSeek distilled model for that.
1. DeepSeek is full of propaganda/censorship (https://arstechnica.com/ai/2025/01/the-questions-the-chinese...)
2. They already had a serious security and privacy issue when they left their database wide open and leaked everyone’s chat history (https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepse... )
3. Multiple teams of security researchers found code that links DeepSeek to the Chinese government through China Mobile, who is banned from operating in the US (https://www.pbs.org/newshour/world/researchers-link-deepseek...)
4. Other countries like South Korea are banning DeepSeek already over privacy concerns (https://mashable.com/article/south-korea-blocks-deepseek)
Trump needs to enforce PAFACA and ban TikTok, but also ban DeepSeek, which has the same exact issues since it is also effectively operated by a foreign adversary and poses various security threats.
Your source doesn't even mention "propaganda". Moreover, while censorship is concerning is concerning, I don't see how that practically affects users. If I want to know how to center a div, who cares if it's cagey about what happened in 1989?
"Western" AI is also arguably full of "propaganda/censorship". Remember when chatgpt just came out, and conservatives were lambasting it for being "woke"?
>3. Multiple teams of security researchers found code that links DeepSeek to the Chinese government through China Mobile, who is banned from operating in the US (https://www.pbs.org/newshour/world/researchers-link-deepseek...)
Seems like a nothingburger?
"Neither Feroot nor the other researchers observed data transferred to China Mobile when testing logins in North America, but they could not rule out that data for some users was being transferred to the Chinese telecom."
>4. Other countries like South Korea are banning DeepSeek already over privacy concerns (https://mashable.com/article/south-korea-blocks-deepseek)
That's what this thread is about. Many commenters have mentioned why South Korea's actions were dumb.
Clearly a false equivalence. You think government propaganda compelled by a dictatorship with access to a military and nukes is the same thing?
Let us be honest here.. China censors directly. US censors indirectly through the private companies [2] and through covert use of force [3]. If you had a pro-Russian stance in 2022 or pro-Palestine stance, you will see your content censored in very subtle ways in US.
1. https://www.kenklippenstein.com/p/tiktok-ban-fueled-by-israe... 2. https://indi.ca/why-i-left-medium-they-defenestrated-me/ 3. https://www.kenklippenstein.com/p/the-fbi-knocked-on-my-door
It is surprising how people in US cannot see the disinformation campaign they are being subjected to.
It's quite literally the difference between exposing a public API and actually handing over the contents of the database.
Both are real violations of users.
If you're shocked or even the slightest bit surprised, then I can't imagine how blissful your life is to be so unaware about how much corporations are sharing data with each other.
Like, I wholeheartedly expect that if I mention Beyblade toys on Facebook, then the next time I visit Amazon, they'll be suggesting Beyblades even if I've never even searched Amazon for toys, let alone Beyblade.
With deepseek and bytedance things are a lot less clear cut.
Stop looking at any opportunity to bark as Sinophobia.
We don't need the pitchforks just yet, sure, but shit, you have to remain realistic about these things.
Your words, not mine. I never made such claims, and you're trying to move the goalposts from "Meta does this" to "I'll be surprised if Meta does this".
I think you mean "I'll NOT be surprised if Meta does this", which is the reasonable position of any rational person to take.
I'm allowed to extrapolate expectations of future behaviour, based on past behaviour. Doing otherwise is naive, dangerously so if you're responsible for someone else's security or privacy.
And I truly believe Meta has an incentive to do so. They had to reveal a conversation on Facebook Messenger on the topic of abortion after the police asked for it, which resulted in someone put in jail. Regardless of Meta's (or rather Zuck's) ever changing political position, they don't want to have liability over anything like this. They want to walk away and just say to the cops, look it's all encrypted, there's nothing we can share with you.
Better keep conspiracy theories to yourself. It's ok to question things, but better back that up with evidence.
When you have a history of doing greasy shit, you don't get the benefit of the doubt.
>I wholeheartedly expect that if I mention Beyblade toys on Facebook...
Isn't the lede here that this isn't just some random data sharing agreement between companies, but that these are both Chinese companies, and the recipient of the data has been banned in the U.S. precisely because of data concerns?
Is this empirically supported? IME it doesn't hesitate to talk about Tienanmen Square or whatever, so if there's "bias" it must be very well hidden.
If you have a better model for the OP to run, please present it.
Edit: https://huggingface.co/perplexity-ai/r1-1776
Just released.
USA has to make a decision between safety and national security.
Through Google Analytics.
Yeah, believe it or not. ByteDance has a cloud offering. And it includes a frontend APM product. And DeepSeek used that. How surprising! A Chinese company used a Chinese cloud.
Oh, and chat.deepseek.com resolve to a Huawei Cloud IP address in China. It resolves to Cloudflare outside of mainland China, but who knows, maybe they just decided to wrap with another CDN and their servers are still on Huawei Cloud. So they sent data to Huawei, too. I repeat, H-U-A-W-E-I. That cursed telecom equipment company in the States.
Using a Chinese company for every thing except for distillation for which they used OpenAI lol.