DeepSeek AI App Under Scrutiny: Security Vulnerabilities and Privacy Breaches Exposed

Experts uncover major flaws in DeepSeek’s iOS app, sparking global privacy and cybersecurity concerns.

DeepSeek, a Chinese AI-powered app, is facing intense criticism after security experts discovered significant flaws in its iOS application. A recent investigation by cybersecurity firm NowSecure revealed that DeepSeek R1, the app’s iOS version, has multiple security vulnerabilities that could compromise user data. These issues include the complete disabling of Apple’s App Transport Security (ATS), reliance on an outdated encryption algorithm, and an exposed database containing sensitive user information. The flaws raise serious concerns about the safety of user data, as well as potential surveillance risks linked to the Chinese government.

Critical Security Vulnerabilities Found in DeepSeek’s iOS App
The NowSecure report found that DeepSeek R1 had intentionally disabled Apple’s ATS, a key security feature that ensures encrypted transmission of user data. Without ATS, the app can send unencrypted information over the internet, making it susceptible to interception by malicious actors. Additionally, the app relies on the outdated 3DES encryption algorithm, which is considered weak and vulnerable to attacks.

To make matters worse, researchers uncovered a publicly accessible DeepSeek database containing highly sensitive user data, including chat logs and secret keys. Without proper authentication in place, any attacker with basic technical skills could access this information, putting user privacy at serious risk. Experts warn that even seemingly trivial user data, when collected and analyzed over time, can be exploited for targeted surveillance or identity tracking.

South Korea’s Warnings Over DeepSeek’s Data Collection
Amid growing cybersecurity concerns, South Korea’s National Intelligence Service (NIS) has issued warnings about DeepSeek, accusing it of excessive data collection. According to the NIS, the app tracks user keyboard input patterns and stores chat logs on Chinese servers, raising fears that the Chinese government could access this information under its data regulations. In response, several South Korean government agencies have banned the use of DeepSeek, joining other countries like Australia and Taiwan in restricting access.

Adding to these concerns, DeepSeek’s AI responses reportedly display inconsistencies when addressing politically sensitive topics. For instance, when asked in Korean about the origin of kimchi, the app identified it as a Korean dish, but in Chinese, it attributed its origins to China. Furthermore, discussions related to the 1989 Tiananmen Square protests are actively censored, with the app prompting users to “talk about something else.”

Global Response and DeepSeek’s Silence
The controversy surrounding DeepSeek has intensified scrutiny of AI-powered applications and their approach to user data security. While China’s foreign ministry has defended its technology sector, claiming that companies do not collect personal data unlawfully, DeepSeek has remained silent on the allegations.

For now, cybersecurity experts advise users, businesses, and government organizations to avoid using DeepSeek until the company improves transparency, strengthens encryption measures, and addresses concerns about unauthorized data collection.

Related Articles

Back to top button

Adblock Detected

Please consider supporting us by disabling your ad blocker