Breaking News

ASUS Announces ProArt Router PRT-BE5000 and ProArt Switch PQG-U1080 CORSAIR Expands the Popular FRAME Series Case Lineup DeepCool Launches the LT360 VISION ARGB Noctua and Asetek Announce Flagship AIO Liquid Coolers Toshiba Begins Sampling of 30-34 TB SMR Nearline Hard Disk Drives

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Baidu Browser Collects And Leaks User's Data, Researchers Say

Baidu Browser Collects And Leaks User's Data, Researchers Say

Smartphones Feb 24,2016 0

Baidu Browser, a free web browser for the Windows and Android platforms produced by Baidu, manages and transmits user data during its operation, researchers say. Baidu Browser offers a number of features beyond those found in standard browsers, including video and audio download tools and built-in torrent support.

Researchers at Canada-based Citizen Lab analyzed how Baidu Browser manages and transmits user data. The report identifies security concerns in both the Windows and Android versions of the browser that may expose personal user data, including a user’s geolocation, hardware identifiers, nearby wireless networks, web browsing data and search terms. Such user data is transmitted, in both the Windows and Android versions, unencrypted or with easily decryptable encryption, which means that any in-path actor could acquire this data by collecting the traffic and performing any necessary decryption. In addition, neither version of the application secures its software update process with a digital signature, which means that a malicious in-path actor could cause the browser to download and execute arbitrary code.

Previously, the researchers had been examining the security and privacy of popular mobile applications in Asia. They had similar concerns with UC Browser, a popular mobile web browser owned by China-based e-commerce giant Alibaba. That report documented UC Browser’s unencrypted transmission of sensitive user information, including IMSI, IMEI, Android ID, Wi-Fi MAC Address, geolocation data and user search queries. The security issues in UC Browser were identified in documents leaked by Edward Snowden that indicated the Five Eyes intelligence alliance, consisting of intelligence agencies from Canada, the United States, the United Kingdom, Australia and New Zealand, had used these vulnerabilities as a means of identifying users.

Thousands of apps running code built by Chinese Internet giant Baidu have collected and transmitted users' personal information to the company, much of it easily intercepted, researchers added.

Alibaba fixed those vulnerabilities, and Baidu said it would be fixing the encryption holes in its kits, but would still collect data for commercial use, some of which it said it shares with third parties.

Tags: baidu
Previous Post
HP Offers Global Wi-Fi Access on HP Devices
Next Post
Xiaomi Announces the Mi 5 Amd Mi 4S Smartphones

Related Posts

  • Baidu 'Cloud Phone' Lets You Run Android Apps on the Cloud

  • Baidu and Samsung Ready for Production of AI Chip for Early Next Year

  • Organization Identifies Implications of BigTech's Engagement in Financial Data

  • Baidu Reports Strong Quarterly Results as a Result of Video Streaming Growth

  • Volvo and Baidu to Develop Autonomous Cars

  • Ford and Baidu to Jointly Test Autonomous Vehicles

  • Baidu Unveils High-Performance Kunlun AI Chip, AI Partnerships With Intel

  • BlackBerry, Baidu Partner on Driverless Car Software

Latest News

ASUS Announces ProArt Router PRT-BE5000 and ProArt Switch PQG-U1080
Enterprise & IT

ASUS Announces ProArt Router PRT-BE5000 and ProArt Switch PQG-U1080

CORSAIR Expands the Popular FRAME Series Case Lineup
Cooling Systems

CORSAIR Expands the Popular FRAME Series Case Lineup

DeepCool Launches the LT360 VISION ARGB
Cooling Systems

DeepCool Launches the LT360 VISION ARGB

Noctua and Asetek Announce Flagship AIO Liquid Coolers
Cooling Systems

Noctua and Asetek Announce Flagship AIO Liquid Coolers

Toshiba Begins Sampling of 30-34 TB SMR Nearline Hard Disk Drives
Enterprise & IT

Toshiba Begins Sampling of 30-34 TB SMR Nearline Hard Disk Drives

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed