Thousands of Apps Running Baidu Code Collect, Leak Personal Data: Report

Advertisement
By Reuters | Updated: 24 February 2016 09:43 IST
Thousands of Apps Running Baidu Code Collect, Leak Personal Data: Report
Thousands of apps running code built by Chinese Internet giant Baidu have collected and transmitted users' personal information to the company, much of it easily intercepted, researchers say.

The apps have been downloaded hundreds of millions of times.

The researchers at Canada-based Citizen Lab said they found the problems in an Android software development kit developed by Baidu. These affected Baidu's mobile browser and apps developed by Baidu and other firms using the same kit. Baidu's Windows browser was also affected, they said.

The same researchers last year highlighted similar problems with unsecured personal data in Alibaba's UC Browser, another mobile browser widely used in the world's biggest Internet market.

Alibaba fixed those vulnerabilities, and Baidu told Reuters it would be fixing the encryption holes in its kits, but would still collect data for commercial use, some of which it said it shares with third parties. Baidu said it "only provides what data is lawfully requested by duly constituted law enforcement agencies."

Advertisement

The unencrypted information that has been collected includes a user's location, search terms and website visits, JeffreyKnockel, chief researcher at Citizen Lab, told Reuters ahead of publication of the research on Wednesday.

The problem highlights how difficult it is for users to know just what data their phone collects and transmits, and the risk that personal data might leak because of poor or no encryption. It also highlights how many different groups might be interested in accessing such data.

Advertisement

"It's either shoddy design or it's surveillance by design,"said Citizen Lab director Ron Deibert.

Citizen Lab said Baidu - which reports quarterly earnings in New York on Thursday - had fixed some of the problems since it brought them to the company's attention in November, but the Android browser still sends sensitive data such as the device ID in an easily decryptable format.

Advertisement

Baidu told Reuters its interest in the data was just commercial, but declined to say who else might have access.

Data security and privacy issues have been highlighted in the United States, where Apple is in a stand-off with the Federal Bureau of Investigation over requests to unlock an iPhone owned by one of those who went on a shooting rampage in San Bernardino, California in December.

Citizen Lab said its research into Alibaba's UC Browser last year was prompted by documents from National Security Agency whistleblower Edward Snowden showing Western intelligence agencies had used holes in the browser to spy on users.

Alibaba said then there was no evidence that user data was taken, but it had addressed concerns by asking users to update their browsers.

The researchers said it was not possible to assess how many users were affected by the Baidu problem, both in China and beyond.

Some software developers in China say a lack of encryption is commonplace, and partly due to rapid growth and poor security awareness.

"It's really, really painful, but it's a growing pain," said Andy Tian, CEO of Beijing-based app developer Asia Innovations.

© Thomson Reuters 2016

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Android, Apps, Baidu, Baidu Code Collect
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo T4 Ultra Launched in India With 50-Megapixel Periscope Camera
  2. Alappuzha Gymkhana OTT Release Date: When and Where to Watch it Online?
  3. Xiaomi Teases Mix Flip 2 Launch; May Arrive Later This Month
  4. Starlink to Launch in India With Rs. 33,000 Setup Kit, Unlimited Plans
  5. Here's When the OnePlus Nord 5 and OnePlus Nord CE 5 Could Launch
  6. Shubhanshu Shukla's Axiom-4 Spaceflight Postponed Following Oxygen Leak in Falcon 9 Booster
  1. Shubhanshu Shukla’s Axiom-4 Spaceflight Postponed Following Oxygen Leak in Falcon 9 Booster
  2. Giada In My Kitchen OTT Release Date: When and Where to Watch Giada De Laurentiis Makeover Special
  3. Too Much OTT Release Date: When and Where to Watch Upcoming Rom-Com Online?
  4. Alappuzha Gymkhana OTT Release Date: When and Where to Watch Malayalam Comedy Drama Online?
  5. Ballard OTT Release Date: When and Where to Watch Crime Thriller Series Online?
  6. MindsEye Developer Says Its Working on Patch as Players Report Performance Issues, Bugs at Launch
  7. Huawei Pura 80 Ultra With Switchable Telephoto System Launched Alongside Pura 80, Pura 80 Pro and Pura 80 Pro+
  8. OpenAI Reportedly Planning to Use Google Cloud to Meet Computational Needs
  9. Kishore-Starrer Vadakkan Now Streaming in Tamil and Telugu: Everything You Need to Know
  10. French President Emmanuel Macron to Push for Ban on Social Media for Under-15s After School Stabbing
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.