{"id":1810,"date":"2025-02-07T03:03:41","date_gmt":"2025-02-07T03:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/07\/experts-flag-security-privacy-risks-in-deepseek-ai-app\/"},"modified":"2025-02-07T03:03:41","modified_gmt":"2025-02-07T03:03:41","slug":"experts-flag-security-privacy-risks-in-deepseek-ai-app","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/07\/experts-flag-security-privacy-risks-in-deepseek-ai-app\/","title":{"rendered":"Experts Flag Security, Privacy Risks in DeepSeek AI App"},"content":{"rendered":"<p>    Experts Flag Security, Privacy Risks in DeepSeek AI App<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>New mobile apps from the Chinese artificial intelligence (AI) company <strong>DeepSeek<\/strong> have remained among the top three \u201cfree\u201d downloads for Apple and Google devices since their debut on Jan. 25, 2025. But experts caution that many of DeepSeek\u2019s design choices \u2014 such as using hard-coded encryption keys, and sending unencrypted user and device data to Chinese companies \u2014 introduce a number of glaring security and privacy risks.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-70327\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek.png?resize=747%2C417&#038;ssl=1\" alt=\"\" width=\"747\" height=\"417\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek.png 854w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-768x428.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-782x436.png 782w\" sizes=\"(max-width: 747px) 100vw, 747px\"><\/p>\n<p>Public interest in the DeepSeek AI chat apps swelled following widespread <a href=\"https:\/\/www.nytimes.com\/2025\/01\/27\/business\/us-stock-market-deepseek-ai-sp500-nvidia.html\" target=\"_blank\" rel=\"noopener\">media<\/a> reports that the upstart Chinese AI firm had managed to match the abilities of cutting-edge chatbots while using a fraction of the specialized computer chips that leading AI companies rely on. As of this writing, DeepSeek is the third most-downloaded \u201cfree\u201d app on the Apple store, and #1 on Google Play.<\/p>\n<p>DeepSeek\u2019s rapid rise caught the attention of the mobile security firm <strong>NowSecure<\/strong>, a Chicago-based company that helps clients screen mobile apps for security and privacy threats. In <a href=\"https:\/\/www.nowsecure.com\/blog\/2025\/02\/06\/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app\/\" target=\"_blank\" rel=\"noopener\">a teardown<\/a> of the DeepSeek app published today, NowSecure urged organizations to remove the DeepSeek iOS mobile app from their environments, citing security concerns.<\/p>\n<p>NowSecure founder <strong>Andrew Hoog<\/strong> said they haven\u2019t yet concluded an in-depth analysis of the DeepSeek app for <strong>Android<\/strong> devices, but that there is little reason to believe its basic design would be functionally much different.<\/p>\n<p>Hoog told KrebsOnSecurity there were a number of qualities about the DeepSeek iOS app that suggest the presence of deep-seated security and privacy risks. For starters, he said, the app collects an awful lot of data about the user\u2019s device.<\/p>\n<p>\u201cThey are doing some very interesting things that are on the edge of advanced device fingerprinting,\u201d Hoog said, noting that one property of the app tracks the device\u2019s name \u2014 which for many iOS devices defaults to the customer\u2019s name followed by the type of iOS device.<\/p>\n<p>The device information shared, combined with the user\u2019s Internet address and <a href=\"https:\/\/krebsonsecurity.com\/2024\/10\/the-global-surveillance-free-for-all-in-mobile-ad-data\/\" target=\"_blank\" rel=\"noopener\">data gathered from mobile advertising companies<\/a>, could be used to deanonymize users of the DeepSeek iOS app, NowSecure warned. The report notes that DeepSeek communicates with <strong>Volcengine<\/strong>, a cloud platform developed by <strong>ByteDance<\/strong> (the makers of <strong>TikTok<\/strong>), although NowSecure said it wasn\u2019t clear if the data is just leveraging ByteDance\u2019s digital transformation cloud service or if the declared information share extends further between the two companies.<\/p>\n<div id=\"attachment_70342\" style=\"width: 760px\" class=\"wp-caption aligncenter\">\n<a href=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-graphic.png?ssl=1\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-70342\" decoding=\"async\" loading=\"lazy\" class=\"wp-image-70342\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-graphic.png?resize=750%2C327&#038;ssl=1\" alt=\"\" width=\"750\" height=\"327\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-graphic.png 1634w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-graphic-768x335.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-graphic-1536x669.png 1536w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/deepseek-graphic-782x341.png 782w\" sizes=\"(max-width: 750px) 100vw, 750px\"><\/a><\/p>\n<p id=\"caption-attachment-70342\" class=\"wp-caption-text\">Image: NowSecure.<\/p>\n<\/div>\n<p>Perhaps more concerning, NowSecure said the iOS app transmits device information \u201cin the clear,\u201d without any encryption to encapsulate the data. This means the data being handled by the app could be intercepted, read, and even modified by anyone who has access to any of the networks that carry the app\u2019s traffic.<\/p>\n<p>\u201cThe DeepSeek iOS app globally disables App Transport Security (ATS) which is an iOS platform level protection that prevents sensitive data from being sent over unencrypted channels,\u201d the report observed. \u201cSince this protection is disabled, the app can (and does) send unencrypted data over the internet.\u201d<span id=\"more-70323\"><\/span><\/p>\n<p>Hoog said the app does selectively encrypt portions of the responses coming from DeepSeek servers. But they also found it uses an insecure and now deprecated encryption algorithm called 3DES (aka <a href=\"https:\/\/en.wikipedia.org\/wiki\/Triple_DES\" target=\"_blank\" rel=\"noopener\">Triple DES<\/a>), and that the developers had hard-coded the encryption key. That means the cryptographic key needed to decipher those data fields can be extracted from the app itself.<\/p>\n<p>There were other, less alarming security and privacy issues highlighted in the report, but Hoog said he\u2019s confident there are additional, unseen security concerns lurking within the app\u2019s code.<\/p>\n<p>\u201cWhen we see people exhibit really simplistic coding errors, as you dig deeper there are usually a lot more issues,\u201d Hoog said. \u201cThere is virtually no priority around security or privacy. Whether cultural, or mandated by China, or a witting choice, taken together they point to significant lapse in security and privacy controls, and that puts companies at risk.\u201d<\/p>\n<p>Apparently, plenty of others share this view. <em>Axios<\/em> <a href=\"https:\/\/www.axios.com\/2025\/01\/30\/house-congress-bans-deepseek-ai\" target=\"_blank\" rel=\"noopener\">reported<\/a> on January 30 that U.S. congressional offices are being warned not to use the app.<\/p>\n<p>\u201c[T]hreat actors are already exploiting DeepSeek to deliver malicious software and infect devices,\u201d read the notice from the chief administrative officer for the House of Representatives. \u201cTo mitigate these risks, the House has taken security measures to restrict DeepSeek\u2019s functionality on all House-issued devices.\u201d<\/p>\n<p><em>TechCrunch<\/em> <a href=\"https:\/\/techcrunch.com\/2025\/02\/03\/deepseek-the-countries-and-agencies-that-have-banned-the-ai-companys-tech\/\" target=\"_blank\" rel=\"noopener\">reports<\/a> that Italy and Taiwan have already moved to ban DeepSeek over security concerns. <em>Bloomberg<\/em> <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-01-30\/pentagon-workers-used-deepseek-s-chatbot-for-days-before-block\" target=\"_blank\" rel=\"noopener\">writes<\/a> that <strong>The Pentagon<\/strong> has blocked access to DeepSeek. <em>CNBC<\/em> <a href=\"https:\/\/www.cnbc.com\/2025\/01\/31\/nasa-becomes-latest-federal-agency-to-block-chinas-deepseek.html\" target=\"_blank\" rel=\"noopener\">says<\/a> <strong>NASA<\/strong> also banned employees from using the service, as did the <strong>U.S. Navy<\/strong>.<\/p>\n<p>Beyond security concerns tied to the DeepSeek iOS app, there are indications the Chinese AI company may be playing fast and loose with the data that it collects from and about users. On January 29, researchers at <strong>Wiz<\/strong> <a href=\"https:\/\/www.wiz.io\/blog\/wiz-research-uncovers-exposed-deepseek-database-leak\" target=\"_blank\" rel=\"noopener\">said<\/a> they discovered a publicly accessible database linked to DeepSeek that exposed \u201ca significant volume of chat history, backend data and sensitive information, including log streams, API secrets, and operational details.\u201d<\/p>\n<p>\u201cMore critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world,\u201d Wiz wrote. [Full disclosure: Wiz is currently an advertiser on this website.]<\/p>\n<p>KrebsOnSecurity sought comment on the report from DeepSeek and from Apple. This story will be updated with any substantive replies.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    BrianKrebs<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/krebsonsecurity.com\/2025\/02\/experts-flag-security-privacy-risks-in-deepseek-ai-app\/\">Go to krebsonsecurity<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Experts Flag Security, Privacy Risks in DeepSeek AI App New mobile apps from the Chinese artificial intelligence (AI) company DeepSeek have remained among the top three \u201cfree\u201d downloads for Apple and Google devices since their debut on Jan. 25, 2025. But experts caution that many of DeepSeek\u2019s design choices \u2014 such as using hard-coded encryption [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[188,736,737,276,266,738,479,706,739,277,55,206,740,207,741],"tags":[72],"class_list":["post-1810","post","type-post","status-publish","format-standard","hentry","category-a-little-sunshine","category-andrew-hoog","category-app-transport-security","category-apple","category-artificial-intelligence","category-bytedance","category-china","category-deepseek","category-deepseek-ai","category-ios","category-krebsonsecurity","category-latest-warnings","category-nowsecure","category-the-coming-storm","category-volcengine","tag-krebsonsecurity"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1810"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1810"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1810\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1810"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1810"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1810"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}