Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemmy.world to Technology@lemmy.worldEnglish · 3 months ago

DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers

arstechnica.com

external-link
message-square
53
link
fedilink
417
external-link

DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers

arstechnica.com

cm0002@lemmy.world to Technology@lemmy.worldEnglish · 3 months ago
message-square
53
link
fedilink
Apple’s defenses that protect data from being sent in the clear are globally disabled.
alert-triangle
You must log in or register to comment.
  • Crackhappy@lemmy.world
    link
    fedilink
    English
    arrow-up
    156
    ·
    3 months ago

    Absolutely “shocked” I tell you.

    • aeronmelon@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      3 months ago

      loudly places hand on side of face

  • Pennomi@lemmy.world
    link
    fedilink
    English
    arrow-up
    81
    arrow-down
    2
    ·
    3 months ago

    The hell? There’s no reason to use plain HTTP instead of HTTPS.

    And symmetric encryption is wildly irresponsible as well.

    • webghost0101@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      45
      arrow-down
      2
      ·
      3 months ago

      Not for s second do I believe this was a accidental oversight.

      I am sure they had very good reasons, all alligned with their actual interests with no thought spared to even consider consequences for small fish users.

      • kinsnik@lemmy.world
        link
        fedilink
        English
        arrow-up
        27
        ·
        3 months ago

        i just can’t think of any. like the article says, i fully expected the app to send data to china. but even if you are maliciously spying on users, why would you send the stolen data on unsecured channels? so that everyone in the path takes advantage of the data your wanted to steal?

        • sunzu2@thebrainbin.org
          link
          fedilink
          arrow-up
          7
          ·
          3 months ago

          Sounds plain sloppy lol

          Badest AI, rookie opsec

        • fmstrat@lemmy.nowsci.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 months ago

          If forced to relocate servers to a US partner,it leaves an attack vector.

      • trolololol@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        3 months ago

        Yep I’m with you.

        It’s so easy to use https with secure encryption. It’s the default. You have to go out of your way to use s symmetric key or to even allow http without SSL in xcode or Android studio.

    • dragonlobster@programming.dev
      link
      fedilink
      English
      arrow-up
      13
      ·
      3 months ago

      Well many of China’s websites don’t even use HTTPS. Look at china.org.cn, or en.people.cn for example

    • cadekat@pawb.social
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      14
      ·
      3 months ago

      Depends on how much traffic you’re talking about. Encrypting/decrypting isn’t free.

      • Pennomi@lemmy.world
        link
        fedilink
        English
        arrow-up
        28
        ·
        3 months ago

        It’s trivial compared to the compute they dedicate to AI models. Like, not even a rounding error.

        • cadekat@pawb.social
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          13
          ·
          3 months ago

          A penny saved is still a penny saved. I’m not saying it would amount to much, but it is non-zero.

          • 0xD@infosec.pub
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            3 months ago

            These are completely different systems. It doesn’t make a difference.

  • cybersin@lemm.ee
    link
    fedilink
    English
    arrow-up
    83
    arrow-down
    8
    ·
    3 months ago

    This is dumb.

    Even if you encrypt network traffic, the receiving server still knows what you’re doing. All it does is prevent third parties from snooping.

    Usually.

    • stephen01king@lemmy.zip
      link
      fedilink
      English
      arrow-up
      44
      arrow-down
      3
      ·
      3 months ago

      Yes, so not only are they doing something shady, they’re doing something shady and exposing your data to anyone wanting to snoop it. What’s dumb about criticising the latter part?

      • cybersin@lemm.ee
        link
        fedilink
        English
        arrow-up
        33
        arrow-down
        8
        ·
        3 months ago

        The fact that anyone thinks they have any semblance of privacy when typing into an online AI chatbot is saddening.

        Of course anything you type into a externally hosted AI is going to be harvested and sold.

        But sure, in this case you are also potentially exposing your queries to your ISP or someone listening on your local network too.

        • breadsmasher@lemmy.world
          link
          fedilink
          English
          arrow-up
          24
          ·
          edit-2
          3 months ago

          Regardless of the downstream server, you should expect the interim traffic to be encrypted in transit

          • cybersin@lemm.ee
            link
            fedilink
            English
            arrow-up
            7
            arrow-down
            11
            ·
            3 months ago

            Sure, it’s not a bad thing and it should be standard practice, but to act like encrypted traffic guarantees privacy is silly.

            • prettybunnys@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              19
              ·
              edit-2
              3 months ago

              The thing is that with the traffic unencrypted it opens the door to all sorts of attacks on that traffic.

              It’s not just privacy.

              If you can intercept and interpret you have the ability to replace as well.

              This is the integrity of your data

            • stephen01king@lemmy.zip
              link
              fedilink
              English
              arrow-up
              8
              ·
              3 months ago

              Tell me where in this thread are anyone expecting privacy from any online LLM service, or anyone saying encrypted traffic guarantees privacy?

        • Ulrich@feddit.org
          link
          fedilink
          English
          arrow-up
          19
          ·
          3 months ago

          Privacy is not the same as security

    • trolololol@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      3 months ago

      Yep it also prevents anyone in the airport impersonating the WiFi and the bytedance server (which is trivial) and crafting payloads that run insecure code on your phone ( not that easy but there’s heaps of CVEs like this in apps like Safari over the years, so there’s at least 2x as many in an app like this)

    • MNByChoice@midwest.social
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 months ago

      Maybe they want 3rd parties snooping?

      • cybersin@lemm.ee
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        2
        ·
        3 months ago

        If you are implying that a government wants your data, they can just buy it or request it from the company directly. They don’t have to snoop to get it. Also SSL isn’t going to stop them.

        • MNByChoice@midwest.social
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 months ago

          Oh, no. I don’t mean USA government. I do mean some governments, but also any company between here an there.

          Imagin that your company wants to sell user data. There are limits on what your company can sell due to contracts or laws, due to having a relationship with the customers.
          Your company leases internet connections from another company, ISP or not, that can sell the data. Sending the data without SSL provides an okay, if not ideal, method to move that data.

  • Anarki_@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    50
    arrow-down
    3
    ·
    edit-2
    3 months ago

    ⢀⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⠀⣠⣤⣶⣶ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⢰⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣧⣀⣀⣾⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⡏⠉⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿ ⣿⣿⣿⣿⣿⣿⠀⠀⠀⠈⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠉⠁⠀⣿ ⣿⣿⣿⣿⣿⣿⣧⡀⠀⠀⠀⠀⠙⠿⠿⠿⠻⠿⠿⠟⠿⠛⠉⠀⠀⠀⠀⠀⣸⣿ ⣿⣿⣿⣿⣿⣿⣿⣷⣄⠀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠠⣴⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡟⠀⠀⢰⣹⡆⠀⠀⠀⠀⠀⠀⣭⣷⠀⠀⠀⠸⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠈⠉⠀⠀⠤⠄⠀⠀⠀⠉⠁⠀⠀⠀⠀⢿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⢾⣿⣷⠀⠀⠀⠀⡠⠤⢄⠀⠀⠀⠠⣿⣿⣷⠀⢸⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡀⠉⠀⠀⠀⠀⠀⢄⠀⢀⠀⠀⠀⠀⠉⠉⠁⠀⠀⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠈⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿

    • breadsmasher@lemmy.world
      link
      fedilink
      English
      arrow-up
      29
      arrow-down
      1
      ·
      3 months ago

      🌕🌕🌕🌕🌕🌕🌕🌕

      🌕🌕🌕🌕🌕🎩🌕🌕

      🌕🌕🌕🌕🌘🌑🌒🌕

      🌕🌕🌕🌘🌑🌑🌑🌓

      🌕🌕🌖🌑👁️🌑👁️🌓

      🌕🌕🌗🌑🌑🫦🌑🌔

      🌕🌕🌘🌑🌑🌑🌒🌕

      🌕🌕🌘🌑🌑🎀🌓🌕

      🌕🌕🌘🌑🌑🌑🌔🌕

      🌕🌕🌘🌔🍆🌑🌕🌕

      🌕🌖🌓🌕🌗🌒🌕🌕

      🌕🌗🌓🌕🌗🌓🌕🌕

      🌕🌘🌔🌕🌗🌓🌕🌕

      🌕👠🌕🌕🌕👠🌕🌕

      • Ænima@lemm.ee
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        3 months ago

        How the fuck do I explain this boner, now?

    • Stovetop@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      3 months ago

      Ah, the ol’ Blahaj Pik-a-choo

  • ZILtoid1991@lemmy.world
    link
    fedilink
    English
    arrow-up
    45
    ·
    3 months ago

    And that’s why you use local instances…

    • oysterenjoyer@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 months ago

      True, but you need powerful server in order to run the most capable Deepseek model, which most people don’t have.

      • brucethemoose@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        3 months ago

        That’s an understatement. It won’t even fit well in 8xA100, you need an EPYC server to run it in CPU RAM, very slowly.

        • Hackworth@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          3 months ago

          To run the 671B parameter R1, my napkin math was something like 3/4 of a million dollars in hardware. But that (plus the much lower training cost) made this a millionaire’s game rather than a billionaire’s. Plus the distillations do seem better than anything else we have at the smaller sizes at the moment. That said, I’m more looking forward to the first use of deepseek’s methods with google’s Titan architectures.

    • Wildly_Utilize@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 months ago

      2nd place is duck.AI in via tor browser

  • daniskarma@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    2
    ·
    3 months ago

    There’s zero relationship between data being unencrypted and it being sent to chinese servers.

    If you use a chinese service it’s obvious that data is going to be sent to a chinese server and that the chinese server would be able to read it.

    Unencrypted data transfer, it’s a totally different thing. I would like to see if it’s truly unencrypted or just not using apple proprietary encryption.

    I luckily don’t own any apple product, but I have deepseek app on my android device. If I’m bored later I’ll try to intercept my own data to see if it’s truly unencrypted. This is easy to test. If it’s not true that newspaper is going to my “block list” asap.

  • Kawawete@reddeet.com
    link
    fedilink
    English
    arrow-up
    20
    ·
    3 months ago

    surprised pikachu no one could see this coming from a few thousand miles away

    • OfficerBribe@lemm.ee
      link
      fedilink
      English
      arrow-up
      8
      ·
      3 months ago

      To be honest, not using TLS nowadays is pretty surprising.

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        3 months ago

        Yeah, it’s actually easier to use TLS than not due to browser checks.

  • misk@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    18
    ·
    edit-2
    3 months ago

    Volcengine is a platform of cloud services released by Bytedance in 2021 to help enterprises with digital transformation. Bytedance connection to China is well established. Sensitive data or data effective for fingerprinting and tracking are in bold.

    So they use a Chinese CDN or hosting? Shocking stuff. Hilarious that a company so bad at basic security beat OpenAI.

    • Ulrich@feddit.org
      link
      fedilink
      English
      arrow-up
      7
      ·
      3 months ago

      I sincerely doubt they’re bad at it.

      • misk@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 months ago

        If leaking data is intentional then there are better ways than doing it in the open. Doubly so if you supposedly are in cahoots with your hosting and Chinese government.

        • gens@programming.dev
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 months ago

          "Open"ai is definitely sharing everything you tipe with your government. Only difference is that chinese care less about your illusions. That said we are not even a blip in the sea of data so it doesn’t matter anyway.

          Bdw your patriot act says that any data that goes over your border can be stored and used indefinitely. So me seing your comment means your nsa will store it and can use it, even though spying on your own people is against your constitution or something.

          • misk@sopuli.xyz
            link
            fedilink
            English
            arrow-up
            5
            ·
            edit-2
            3 months ago

            Yeah, I’m not an American and not here to argue one’s better than the other because if you care about your data you just don’t give them opportunity to see it. I’m having fun pointing out how silly this poo-slinging between US and China looks to bystanders, that’s all. It’s like denouncing DeepSeek is a modern day swearing fealty to the American lords.

          • misk@sopuli.xyz
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 months ago

            deleted by creator

  • Nobilmantis@feddit.it
    link
    fedilink
    English
    arrow-up
    13
    ·
    3 months ago

    Basically anything else you use here in the west sends all data to Amazon-controlled servers. But they make sure its encrypted so only them can see it. Nice.

  • giacomo@lemm.ee
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 months ago

    its nice of them not to encrypt it at least. it can get harvested along the way!

  • don@lemm.ee
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    1
    ·
    3 months ago

    Fucking duh

  • CallateCoyote@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    3 months ago

    Does this actually matter so long as I just ask it questions I want answers to? I’m not feeding it any personal information. Sincere question. Enlighten me if so.

    • AnxiousDuck@feddit.it
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      3 months ago

      You wouldn’t believe how little information can be personally identifying, especially when combined with other little pieces.

      Also, knowing what’s on the mind of western people, how they write, how they engage in conversations can be extremely valuable information.

      • coolmojo@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        3 months ago

        Oh no. They will know that I don’t know how to implement cache invalidation in python. /s

    • ILikeBoobies@lemmy.ca
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 months ago

      Having an app installed gives it a lot of information

      Unencrypted just means people on the way to that server can peek

      • Toribor@corndog.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 months ago

        I’ve started using Firefox to install sites ‘as a web app’. I use that for cloud services and things I self host. Basically works like a native app but way more control over data.

  • HowAbt2morrow@futurology.today
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    3 months ago

    No shit?

  • Admeen@reddeet.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    deleted by creator

  • Tarkcanis@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    22
    ·
    3 months ago

    Removed by mod

    • prettybunnys@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      1
      ·
      3 months ago

      Do you understand what you’re commenting on or just commenting hoping it’s funny?

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3.68K users / day
  • 9.76K users / week
  • 18.3K users / month
  • 32.2K users / 6 months
  • 1 local subscriber
  • 69.8K subscribers
  • 3.3K Posts
  • 79.6K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org