Hundreds of millions of Android mobile users have downloaded apps which have sent unencrypted and easily interceptable private data to servers in China, a recent security report has claimed.

The report says the personal information of countless Android users who have downloaded certain apps have had their personal information collected by Chinese advertising and search giant Baidu.

It alleges information about users' precise locations, browsing histories and search terms were transmitted to Baidu's servers either without any encryption, or with easily decryptable encryption.

Device IMEI numbers, which can be used to identify a person's phone, were also allegedly sent to Baidu's servers in an easily decryptable format.

Encryption is the practice of encoding digital information so that only authorised parties can read it. Companies like Google collect some of the same information Baidu collects, but use encryption to make sure it doesn't fall into the wrong hands.

Without encryption, data sent to Baidu's servers could be intercepted by hackers.

Furthermore, the report claims Baidu web browser updates for Windows and Android don't include any code signatures, which are used to guarantee that the incoming updates come from an authorised source. This potentially means hackers could use Baidu's security flaws to perform a 'man in the middle' attack, sending anything to the browser and having it installed on the computer - including viruses and trojans which could put even more personal information at risk.

"It's either shoddy design or it's surveillance by design."

&#13; <p>Ron Deibert, Citizen Lab director</p>&#13;

The researchers, working at the University of Toronto's Citizen Lab, found the problems in an app development kit built by Baidu. They claim the security flaws affect Baidu's mobile browser, apps developed by the company and others using the development kit, and even Baidu's desktop Windows browser.

Citizen Lab director Ron Deibert told Reuters said: "It's either shoddy design or it's surveillance by design."

Citizen Lab said Baidu had fixed some of these issues since it brought them to the company's attention in November 2015. However, the Android browser still sends sensitive data such as the device's unique ID in an easily decryptable format.

Speaking to Reuters, Baidu said its interest in the data was just commercial. However, it didn't say who else might have access to it.

China's digital economy is booming, but a lack of encryption is commonplace, partly due to rapid growth and poor awareness of common security issues.

Andy Tian, chief executive of Beijing-based app develoiper Asia Innovations, told Reuters: "It's really, really painful, but it's a growing pain."

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

UK EditionChange

Subscribe
Log in / Register

两个鬼故事给男孩起名字孤岛惊魂53dm背景墙壁纸zgjz广字起名公司丹道宗师免费八字起名字测试打分测试郑姓起姓名大全劲爆体育直播天蝎座的女人起名好听的字男孩饺馆起名公司起名带云字火影忍者纲手全部番子四字起名网宝宝免费起名测名测试打分结果生辰八字叛逆的鲁鲁修第二季你与我相似000697汇添富移动互联基金净值宝宝起名子衿潘式女孩高分起名大全协会起名现代家具起名混沌世界攻略手机截图怎么给压面条店起名网店店铺名称怎么起好听剑侠电视剧全集琉璃免费看起一个游戏名字少年生前被连续抽血16次?多部门介入两大学生合买彩票中奖一人不认账让美丽中国“从细节出发”淀粉肠小王子日销售额涨超10倍高中生被打伤下体休学 邯郸通报单亲妈妈陷入热恋 14岁儿子报警何赛飞追着代拍打雅江山火三名扑火人员牺牲系谣言张家界的山上“长”满了韩国人?男孩8年未见母亲被告知被遗忘中国拥有亿元资产的家庭达13.3万户19岁小伙救下5人后溺亡 多方发声315晚会后胖东来又人满为患了张立群任西安交通大学校长“重生之我在北大当嫡校长”男子被猫抓伤后确诊“猫抓病”测试车高速逃费 小米:已补缴周杰伦一审败诉网易网友洛杉矶偶遇贾玲今日春分倪萍分享减重40斤方法七年后宇文玥被薅头发捞上岸许家印被限制高消费萧美琴窜访捷克 外交部回应联合利华开始重组专访95后高颜值猪保姆胖东来员工每周单休无小长假男子被流浪猫绊倒 投喂者赔24万小米汽车超级工厂正式揭幕黑马情侣提车了西双版纳热带植物园回应蜉蝣大爆发当地回应沈阳致3死车祸车主疑毒驾恒大被罚41.75亿到底怎么缴妈妈回应孩子在校撞护栏坠楼外国人感慨凌晨的中国很安全杨倩无缘巴黎奥运校方回应护栏损坏小学生课间坠楼房客欠租失踪 房东直发愁专家建议不必谈骨泥色变王树国卸任西安交大校长 师生送别手机成瘾是影响睡眠质量重要因素国产伟哥去年销售近13亿阿根廷将发行1万与2万面值的纸币兔狲“狲大娘”因病死亡遭遇山火的松茸之乡“开封王婆”爆火:促成四五十对奥巴马现身唐宁街 黑色着装引猜测考生莫言也上北大硕士复试名单了德国打算提及普京时仅用姓名天水麻辣烫把捣辣椒大爷累坏了

两个鬼故事 XML地图 TXT地图 虚拟主机 SEO 网站制作 网站优化