DeepSeek AI App Faces Serious Security and Privacy Concerns

Curated by THEOUTPOST

On Wed, 5 Feb, 4:04 PM UTC

19 Sources

Share

Multiple security audits reveal significant vulnerabilities in DeepSeek's iOS and Android apps, including unencrypted data transmission to Chinese servers and poor security practices, raising concerns about user privacy and data protection.

DeepSeek's Rapid Rise and Security Concerns

DeepSeek, an AI chatbot app that briefly surpassed ChatGPT in popularity, has come under scrutiny for significant security and privacy issues. The app, which topped download charts on both iOS and Android platforms, is now facing serious questions about its data handling practices and potential risks to user information 1.

Critical Security Flaws Uncovered

Security audits conducted by NowSecure and Security Scorecard have revealed alarming vulnerabilities in both the iOS and Android versions of the DeepSeek app. Key findings include:

  1. Unencrypted Data Transmission: The app sends user data over the internet without proper encryption, exposing it to potential interception and manipulation 2.

  2. Disabled Security Features: DeepSeek's iOS app globally disables Apple's App Transport Security (ATS), a crucial protection mechanism 3.

  3. Outdated Encryption Methods: The app utilizes the 3DES algorithm, now considered an insecure form of encryption 2.

  4. Hardcoded Keys and Weak Cryptography: Security Scorecard identified issues such as hardcoded keys and vulnerabilities to SQL injection attacks 1.

Data Collection and Privacy Concerns

DeepSeek's privacy policy reveals extensive data collection practices, including:

  • Text and audio inputs, prompts, and chat history
  • Technical information such as IP addresses and device models
  • Keystroke patterns and rhythms, which can be used to infer user identity and behavior 1

Chinese Server Connections and Regulatory Issues

A major concern is the transmission of user data to servers controlled by ByteDance, the parent company of TikTok. This raises potential compliance issues with GDPR, CCPA, and national security laws 4. The app's website has also been found to send user login information to China Mobile, a state-owned telecommunications company banned from operating in the United States 4.

Government Responses and Bans

In response to these security concerns, several countries and government agencies have taken action:

  • Australia, Italy, Taiwan, the Netherlands, and South Korea have banned DeepSeek from government devices
  • U.S. agencies including NASA, Navy, Pentagon, and the state of Texas have also instituted bans
  • U.S. lawmakers are pushing for a nationwide ban on government devices 4

Recommendations and Future Implications

Security experts recommend deleting the DeepSeek app from managed and BYOD environments until these issues are addressed 5. Organizations are advised to consider alternative AI chatbot solutions that prioritize mobile app security and data protection.

As DeepSeek faces scrutiny similar to TikTok, it may need to address these security and privacy concerns promptly to avoid potential bans or forced sales in certain markets 3. The situation highlights the growing importance of data security and privacy in AI applications, especially those with international reach and potential geopolitical implications.

Continue Reading
DeepSeek's Cybersecurity Woes: Exposed Database Raises

DeepSeek's Cybersecurity Woes: Exposed Database Raises Serious Concerns

A cybersecurity firm discovers an unprotected DeepSeek database, exposing sensitive information and raising questions about the AI startup's security practices.

pcgamer logoNDTV Gadgets 360 logoAndroid Authority logo

3 Sources

pcgamer logoNDTV Gadgets 360 logoAndroid Authority logo

3 Sources

DeepSeek AI Faces Global Scrutiny Over Security and Privacy

DeepSeek AI Faces Global Scrutiny Over Security and Privacy Concerns

DeepSeek, a Chinese AI chatbot, has gained popularity but faces bans and investigations worldwide due to security and privacy concerns, drawing comparisons to TikTok's challenges.

CNET logoMashable logoDataconomy logoNBC News logo

14 Sources

CNET logoMashable logoDataconomy logoNBC News logo

14 Sources

DeepSeek AI Under Scrutiny: South Korea Investigates Data

DeepSeek AI Under Scrutiny: South Korea Investigates Data Sharing with ByteDance

South Korea's data protection authority accuses Chinese AI firm DeepSeek of sharing user data with ByteDance, TikTok's parent company, raising global privacy concerns and prompting investigations.

MediaNama logoTechRadar logoBreaking News.ie logoSky News logo

41 Sources

MediaNama logoTechRadar logoBreaking News.ie logoSky News logo

41 Sources

DeepSeek AI Chatbot Fails All Safety Tests, Raising Serious

DeepSeek AI Chatbot Fails All Safety Tests, Raising Serious Security Concerns

DeepSeek's AI model, despite its high performance and low cost, has failed every safety test conducted by researchers, making it vulnerable to jailbreak attempts and potentially harmful content generation.

Wccftech logoGizmodo logo9to5Mac logoPC Magazine logo

12 Sources

Wccftech logoGizmodo logo9to5Mac logoPC Magazine logo

12 Sources

DeepSeek AI Faces Global Scrutiny Over Security and Privacy

DeepSeek AI Faces Global Scrutiny Over Security and Privacy Concerns

DeepSeek, a Chinese AI startup, is under investigation by multiple countries due to security vulnerabilities and data privacy issues, leading to bans on government devices and probes into its practices.

Euronews English logoSilicon Republic logoDigital Trends logoTech Xplore logo

5 Sources

Euronews English logoSilicon Republic logoDigital Trends logoTech Xplore logo

5 Sources

TheOutpost.ai

Your one-stop AI hub

The Outpost is a comprehensive collection of curated artificial intelligence software tools that cater to the needs of small business owners, bloggers, artists, musicians, entrepreneurs, marketers, writers, and researchers.

© 2025 TheOutpost.AI All rights reserved