Artificial Intelligence

151 readers
12 users here now

Chat about and share AI stuff

founded 2 years ago
MODERATORS
1
 
 

cross-posted from: https://lemmy.sdf.org/post/29128134

Archived

A NowSecure mobile application security and privacy assessment has uncovered multiple security and privacy issues in the DeepSeek iOS mobile app that lead us to urge enterprises to prohibit/forbid its usage in their organizations.

...

Key Risks Identified:

  • Unencrypted Data Transmission: The app transmits sensitive data over the internet without encryption, making it vulnerable to interception and manipulation.
  • Weak & Hardcoded Encryption Keys: Uses outdated Triple DES encryption, reuses initialization vectors, and hardcodes encryption keys, violating best security practices.
  • Insecure Data Storage: Username, password, and encryption keys are stored insecurely, increasing the risk of credential theft.
  • Extensive Data Collection & Fingerprinting: The app collects user and device data, which can be used for tracking and de-anonymization.
  • Data Sent to China & Governed by PRC Laws: User data is transmitted to servers controlled by ByteDance, raising concerns over government access and compliance risks.

...

How to Mitigate the DeepSeek iOS App Risks

It is difficult, if not impossible, at this time to immediately mitigate the numerous security, privacy and data risks that exist in the DeepSeek iOS today. Over time, we hope the security issue will be remediated and that some of the practices impacting privacy could be addressed. But for US and EU based businesses and government agencies, it is difficult to mitigate the storage, analysis and processing of data in the People’s Republic of China. Of course, each organization can make this determination themselves and hopefully the risks outlined above provide insights and a path towards a more secure and secure iOS app.

In the meantime, there are immediate steps companies and government agencies can take:

  1. Immediately stop using the DeepSeek iOS app until security and privacy failures are sufficiently mitigated
  2. Determine if the data collection, privacy policy, terms of service and legal jurisdiction are issues that put your organization at risk
  3. Consider leveraging the DeepSeek open source model via hosted solutions from companies like Microsoft or via self-hosting the model (e.g. via Hugging Face)
  4. Investigate alternative AI apps that offer the DeepSeek open source model but with better security, privacy and data governance. Or consider other AI offerings that address your organization’s needs

...

2
 
 

cross-posted from: https://lemmy.sdf.org/post/28910537

Archived

Researchers claim they had a ‘100% attack success rate’ on jailbreak attempts against Chinese AI DeepSeek

"DeepSeek R1 was purportedly trained with a fraction of the budgets that other frontier model providers spend on developing their models. However, it comes at a different cost: safety and security," researchers say.

A research team at Cisco managed to jailbreak DeepSeek R1 with a 100% attack success rate. This means that there was not a single prompt from the HarmBench set that did not obtain an affirmative answer from DeepSeek R1. This is in contrast to other frontier models, such as o1, which blocks a majority of adversarial attacks with its model guardrails.

...

In other related news, experts are cited by CNBC that DeepSeek’s privacy policy “isn’t worth the paper it is written on."

...

3
4
 
 

The interstellar beings has ask me to share this low quality YouTube video in hope of inspiring a new era of technological advancement.