SecurityScorecard Exposes DeepSeek Android App Flaws: Hardcoded Keys, Data Flows to Chinese State Entities
joshrogin · x · 2026-08-20
SecurityScorecard's STRIKE research analyzed the DeepSeek Android app, uncovering serious vulnerabilities including hardcoded encryption keys, weak cryptographic algorithms, and SQL injection risks. Data is transmitted to domains linked to Chinese state-owned entities, raising data sovereignty concerns. Embedded ByteDance code suggests undisclosed data-sharing connections. The app employs anti-debugging mechanisms, contradicting its transparency claims.
More from Safety
- Sam Altman on the AI dilemma: trade-offs between loss of control and power centralization — r0ck3t23 · 2026-08-24
- Debate erupts over lethal military robots vs. failing civilian units — teortaxesTex · 2026-08-24
- Only 1 of 20 Potential Presidential Candidates Answered AI Pause Query — DavidSKrueger · 2026-08-24
- Chinese Transforming Robot Dog Sparks US Trade Policy Criticism — TinfoilTricorn · 2026-08-24
- Turkey blocks at least 12 Grok posts on national security grounds — Unusual_Variation293 · 2026-08-24
- Nature Comment: Provenance, not interpretability, grounds trust in autonomous science — gabepgomes · 2026-08-24