TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Static analysis of the DeepSeek Android app

8 点作者 mbac327683 个月前

2 条评论

asimpleusecase3 个月前
It would be good to do this kind of analysis on apps that have more than 10 million users - but in the mean time , has someone done this analysis on TicTok?
mbac327683 个月前
tl;dr it does aggressive device fingerprinting, root detection, has anti-tampering mechanisms, bundles native code and has dynamic code loading and execution facilities.<p>IMO, none of which should be necessary for an app like this<p>A dynamic analysis is still needed to confirm what it actually does.<p>I decided to do this after a researcher found obfuscated surveillance code in the web app <a href="https:&#x2F;&#x2F;apnews.com&#x2F;article&#x2F;deepseek-china-generative-ai-internet-security-concerns-c52562f8c4760a81c4f76bc5fbdebad0" rel="nofollow">https:&#x2F;&#x2F;apnews.com&#x2F;article&#x2F;deepseek-china-generative-ai-inte...</a><p>NowSecure found similar not great runtime behavior in the iOS mobile app <a href="https:&#x2F;&#x2F;www.nowsecure.com&#x2F;press-releases&#x2F;nowsecure-urges-enterprises-to-ban-the-deepseek-ios-mobile-app&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.nowsecure.com&#x2F;press-releases&#x2F;nowsecure-urges-ent...</a>
评论 #42974487 未加载