{"id":61770,"date":"2016-02-27T23:07:00","date_gmt":"2016-02-27T23:07:00","guid":{"rendered":"http:\/\/127.0.0.1:10081\/?p=61770 "},"modified":"2016-02-27T23:07:00","modified_gmt":"2016-02-27T23:07:00","slug":"61770-revision-v1","status":"publish","type":"post","link":"https:\/\/minzhuzhongguo.org\/?p=61770","title":{"rendered":"Baidu apps found to be \\&#8217;leaking\\&#8217; personal data"},"content":{"rendered":"<p><span style=\"font-size: 12pt;\">26 February 2016<\/span><\/p><div>&nbsp;<\/div>  <p><img decoding=\"async\" src=\"http:\/\/mzzg.org\/UploadCenter\/ArticlePics\/2016\/8\/2016226_88464832_031629146-1.jpg\" alt=\"2016226_88464832_031629146-1.jpg (660&#215;371)\" \/><\/p>  <p><span style=\"font-size: 12pt;\">Baidu logoImage copyrightReuters<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Image caption<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Many apps built with a Baidu created software kit do a poor job of protecting personal data, researchers have found<\/span><\/p><div>&nbsp;<\/div>  <p>&nbsp;<\/p>  <p><span style=\"font-size: 12pt;\">Personal data is being collected and transmitted insecurely by thousands of apps using code from the Chinese net giant Baidu, say security researchers.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Millions of Chinese people are believed to have been affected by the data leaks, said security experts at the University of Toronto.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">The data reveals where people are, search terms, sites visited and the ID numbers of devices they own.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Baidu said it had tackled the problems with the insecure computer code.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">&#8216;Shoddy design&#8217;<\/span><\/p>  <p><span style=\"font-size: 12pt;\">The code is found in a software development kit that can be used to create apps for Android phones and programs for Windows.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Baidu itself used it to make web browsers for Android and Windows and many other firms have used the kit too.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Apps and browsers made using the Baidu kit have been downloaded hundreds of millions of times, said researchers at Toronto&#8217;s Citizen Lab in the report. As part of a long-running research project, the Lab has focussed on privacy and personal data use in China. Last year the team found shortcomings in the Alibaba browser.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">The latest report found several security and privacy shortcomings in the Baidu code.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Some data, including GPS coordinates and search terms, is sent in plain text.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">In addition, the protections added to other forms of information, such as unique device IDs, could easily be broken.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Poor protection of apps made with the kit also made users &#8220;susceptible&#8221; to fake updates that could give an attacker access to a phone or a Windows computer.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">&#8220;The transmission of personal data without properly implemented encryption can expose a user&#8217;s data to surveillance,&#8221; said the authors in their report.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Worryingly, they added, users would have no warning that the data was being transmitted or gathered.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">&#8220;The leakage of such user data is particularly problematic for individuals who use these applications and their devices to engage in politically sensitive communications,&#8221; said the report.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">&#8220;It&#8217;s either shoddy design or it&#8217;s surveillance by design,&#8221; Ron Deibert, director of the Citizen Lab, told Reuters.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Fixed?<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Citizen Lab said that Baidu had fixed some of the bugs in the code since it had first been told about them in November last year.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">However, it added, the poor encryption scheme was still being used on sensitive data.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">Baidu said it was collecting the data about users for commercial purposes. Occasionally, it said, it shared the data with partners.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">It added that the information was not handed over wholesale to the Chinese authorities.<\/span><\/p>  <p><span style=\"font-size: 12pt;\">It said it &#8220;only provides what data is lawfully requested by duly constituted law enforcement agencies&#8221;.<\/span><\/p>  <p>&nbsp;<\/p>  <p><br \/><\/p>  <p><a href=\"http:\/\/www.bbc.com\/news\/technology-35669817\"><span style=\"font-size: 12pt;\">For detail please visit here<\/span><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>&lt;div&gt;Millions of Chinese people are believed to have been affected by the data leaks, said security experts at the University of Toronto.The data reveals where people are, search terms, sites visited and the ID numbers of devices they own.&lt;\/div&gt;<\/p>\n","protected":false},"author":24,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[14],"tags":[],"class_list":["post-61770","post","type-post","status-publish","format-standard","hentry","category-ChinaHumanRights","et-doesnt-have-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=\/wp\/v2\/posts\/61770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=61770"}],"version-history":[{"count":0,"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=\/wp\/v2\/posts\/61770\/revisions"}],"wp:attachment":[{"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=61770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=61770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/minzhuzhongguo.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=61770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}