Baidu apps leak personal data: study

A research group says thousands of apps running on Chinese internet giant Baidu's platform have a security flaw that puts users' data at risk.

Baidu is huge in China

Baidu is huge in China Source: AAP

Thousands of apps running code built by Chinese Internet giant Baidu have collected users' personal information and transmitted it to the company, researchers say.

Much of the information is easily intercepted, according to the researchers at Canada-based Citizen Lab.

The apps have been downloaded hundreds of millions of times.

The researchers said they found the problems in an Android software development kit developed by Baidu.

These affected Baidu's mobile browser and apps developed by Baidu and other firms using the same kit. Baidu's Windows browser was also affected, they said.
The same researchers last year highlighted similar problems with unsecured personal data in Alibaba's UC Browser, another mobile browser widely used in the world's biggest Internet market.

Alibaba fixed those vulnerabilities, and Baidu told Reuters it would be fixing the encryption holes in its kits, but would still collect data for commercial use, some of which it said it shares with third parties.

Baidu said it "only provides what data is lawfully requested by duly constituted law enforcement agencies."

The unencrypted information that has been collected includes a user's location, search terms and website visits, Jeffrey Knockel, chief researcher at Citizen Lab, told Reuters ahead of publication of the research on Wednesday.

The problem highlights how difficult it is for users to know just what data their phone collects and transmits, and the risk that personal data might leak because of poor or no encryption.
It also highlights how many different groups might be interested in accessing such data.

"It's either shoddy design or it's surveillance by design," said Citizen Lab director Ron Deibert.

Citizen Lab said Baidu - which reports quarterly earnings in New York on Thursday - had fixed some of the problems since they were brought to the company's attention in November, but the Android browser still sends sensitive data such as the device ID in an easily decryptable format.

Baidu told Reuters its interest in the data was just commercial, but declined to say who else might have access.

Some software developers in China say a lack of encryption is commonplace, and partly due to rapid growth and poor security awareness.

"It's really, really painful, but it's a growing pain," said Andy Tian, CEO of Beijing-based app developer Asia Innovations.


Share
3 min read

Published

Updated

Source: AAP


Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world