TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Static analysis of the DeepSeek Android app

8 pointsby mbac327683 months ago

2 comments

asimpleusecase3 months ago
It would be good to do this kind of analysis on apps that have more than 10 million users - but in the mean time , has someone done this analysis on TicTok?
mbac327683 months ago
tl;dr it does aggressive device fingerprinting, root detection, has anti-tampering mechanisms, bundles native code and has dynamic code loading and execution facilities.<p>IMO, none of which should be necessary for an app like this<p>A dynamic analysis is still needed to confirm what it actually does.<p>I decided to do this after a researcher found obfuscated surveillance code in the web app <a href="https:&#x2F;&#x2F;apnews.com&#x2F;article&#x2F;deepseek-china-generative-ai-internet-security-concerns-c52562f8c4760a81c4f76bc5fbdebad0" rel="nofollow">https:&#x2F;&#x2F;apnews.com&#x2F;article&#x2F;deepseek-china-generative-ai-inte...</a><p>NowSecure found similar not great runtime behavior in the iOS mobile app <a href="https:&#x2F;&#x2F;www.nowsecure.com&#x2F;press-releases&#x2F;nowsecure-urges-enterprises-to-ban-the-deepseek-ios-mobile-app&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.nowsecure.com&#x2F;press-releases&#x2F;nowsecure-urges-ent...</a>
评论 #42974487 未加载