Breaking News

Firewalla Launches MSP 2.9: Introducing FireAI Search, AP7 Wi-Fi Management, Enhanced User Support, Mobile App Access Control Elgato Launches Retail-Exclusive, Discord-Edition Stream Deck Mini LIAN LI Unveils HydroShift II LCD-S Series AIO with Hot-Swappable Square LCD ASUS Republic of Gamers Announces Availability of Swift OLED PG27AQWP-W and Strix OLED XG27AQWMG ASUS Announces Prime AP303 Compact Mid-Tower ATX Case

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Baidu Browser Collects And Leaks User's Data, Researchers Say

Baidu Browser Collects And Leaks User's Data, Researchers Say

Smartphones Feb 24,2016 0

Baidu Browser, a free web browser for the Windows and Android platforms produced by Baidu, manages and transmits user data during its operation, researchers say. Baidu Browser offers a number of features beyond those found in standard browsers, including video and audio download tools and built-in torrent support.

Researchers at Canada-based Citizen Lab analyzed how Baidu Browser manages and transmits user data. The report identifies security concerns in both the Windows and Android versions of the browser that may expose personal user data, including a user’s geolocation, hardware identifiers, nearby wireless networks, web browsing data and search terms. Such user data is transmitted, in both the Windows and Android versions, unencrypted or with easily decryptable encryption, which means that any in-path actor could acquire this data by collecting the traffic and performing any necessary decryption. In addition, neither version of the application secures its software update process with a digital signature, which means that a malicious in-path actor could cause the browser to download and execute arbitrary code.

Previously, the researchers had been examining the security and privacy of popular mobile applications in Asia. They had similar concerns with UC Browser, a popular mobile web browser owned by China-based e-commerce giant Alibaba. That report documented UC Browser’s unencrypted transmission of sensitive user information, including IMSI, IMEI, Android ID, Wi-Fi MAC Address, geolocation data and user search queries. The security issues in UC Browser were identified in documents leaked by Edward Snowden that indicated the Five Eyes intelligence alliance, consisting of intelligence agencies from Canada, the United States, the United Kingdom, Australia and New Zealand, had used these vulnerabilities as a means of identifying users.

Thousands of apps running code built by Chinese Internet giant Baidu have collected and transmitted users' personal information to the company, much of it easily intercepted, researchers added.

Alibaba fixed those vulnerabilities, and Baidu said it would be fixing the encryption holes in its kits, but would still collect data for commercial use, some of which it said it shares with third parties.

Tags: baidu
Previous Post
HP Offers Global Wi-Fi Access on HP Devices
Next Post
Xiaomi Announces the Mi 5 Amd Mi 4S Smartphones

Related Posts

  • Baidu 'Cloud Phone' Lets You Run Android Apps on the Cloud

  • Baidu and Samsung Ready for Production of AI Chip for Early Next Year

  • Organization Identifies Implications of BigTech's Engagement in Financial Data

  • Baidu Reports Strong Quarterly Results as a Result of Video Streaming Growth

  • Volvo and Baidu to Develop Autonomous Cars

  • Ford and Baidu to Jointly Test Autonomous Vehicles

  • Baidu Unveils High-Performance Kunlun AI Chip, AI Partnerships With Intel

  • BlackBerry, Baidu Partner on Driverless Car Software

Latest News

Firewalla Launches MSP 2.9: Introducing FireAI Search, AP7 Wi-Fi Management, Enhanced User Support, Mobile App Access Control
Enterprise & IT

Firewalla Launches MSP 2.9: Introducing FireAI Search, AP7 Wi-Fi Management, Enhanced User Support, Mobile App Access Control

Elgato Launches Retail-Exclusive, Discord-Edition Stream Deck Mini
Consumer Electronics

Elgato Launches Retail-Exclusive, Discord-Edition Stream Deck Mini

LIAN LI Unveils HydroShift II LCD-S Series AIO with Hot-Swappable Square LCD
Cooling Systems

LIAN LI Unveils HydroShift II LCD-S Series AIO with Hot-Swappable Square LCD

ASUS Republic of Gamers Announces Availability of Swift OLED PG27AQWP-W and Strix OLED XG27AQWMG
Gaming

ASUS Republic of Gamers Announces Availability of Swift OLED PG27AQWP-W and Strix OLED XG27AQWMG

ASUS Announces Prime AP303 Compact Mid-Tower ATX Case
Cooling Systems

ASUS Announces Prime AP303 Compact Mid-Tower ATX Case

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed