Breaking News

Arctic announces Senza AI 370 Under Desk PC for AI Applications CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud Sharkoon announces S100 ARGB AIO Cooler

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Disover Security Issues with Alibaba's UC Browser

Researchers Disover Security Issues with Alibaba's UC Browser

Enterprise & IT May 21,2015 0

UC Browser, a popular mobile web browser in China and India owned by the Alibaba Group, has multiple security and privacy deficits, a Canadian technology research group said on Thursday. Researchers at Citizen Lab revealed that UC Browser poorly secures data in its English and Chinese language versions for Android. Sensitive user data, such as device identifiers, nearby Wi-Fi access points, and cellular tower information, as well as search queries to the search engine Shenma, asre insufficiently secured by the Chinese version of the application before transmitting to its destination, according to a report published by Citizen Lab. The Chinese version also permanently retains users’ DNS query history which was discovered after researchers tried to delete personal information using the application’s built-in personal information deletion functions.

The ressearchers also discovered that the English version of the application sends search queries to Yahoo! India or Google without encryption; however, it does not exhibit the other information leakages present in the Chinese version of the application.

"Our analysis shows that the information leakages in the Chinese version of the application could be used to track the location of persons either in real-time or retroactively," the researchers said. "Moreover, the application’s failure to delete DNS queries means that third parties that access the application’s cache could determine what websites a user had previously visited. Both the Chinese and English versions of the applications showcase poor security practices by failing to encrypt queries made to either Chinese- or English-based search engines."

The transmission of unencrypted search engine queries enables third parties to monitor searches as well as potentially return modified search results without the user realizing that their data has been monitored or modified. Sensitive personal information can be inferred from search results including health conditions, such as pregnancy, disease, mental and psychological conditions, marital relations, and medical information. The data can also be used by third parties to develop, use, and sell user profiles and by corporate or government agents to modify or prevent access to certain search results.

Generally, the researchers found that users of the English version of the applications experience fewer privacy or security problems compared to users of the Chinese version.

Citizen Lab disclosed their findings to Alibaba on April 15, 2015. The company responded, indicating that Alibaba security engineers were investigating the issue.

The researchers later tested a newer version (10.4.1-576) of the Chinese language version of UC Browser. This version did not appear to send location data insecurely to AMAP. However, issues relating to insecure data transmission to the Umeng component, as well the lack of encryption on search terms, did not appear to have changed in that latest version.

Tags: Alibaba
Previous Post
Should We Expect Android OS For IoT Next Week?
Next Post
HP Partners With Chinese Tsinghua

Related Posts

  • Ubisoft Sues Apple, Google Over Distribution of Alibaba’s Area F2 Game

  • Alibaba Announces $28 billion Cloud Investment

  • Alibaba is Offering Europe Coronavirus Diagnostic Tool

  • Alipay Announces Three-Year Plan to Support the Digital Transformation of 40 Million Service Providers in China

  • Alibaba Reports High Earnings but Coronavirus Questions Remain

  • Alibaba Raises Up to $12.9 billion in Hong Kong Listing

  • Alibaba Group Generated $38.4 Billion of GMV During the Global Shopping Festival

  • Alibaba Group Generated $12 Billion of GMV in the First Hour of the Global Shopping Festival

Latest News

Arctic announces Senza AI 370 Under Desk PC for AI Applications
Consumer Electronics

Arctic announces Senza AI 370 Under Desk PC for AI Applications

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds
Cooling Systems

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads
Enterprise & IT

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads

World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud
Enterprise & IT

World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud

Sharkoon announces S100 ARGB AIO Cooler
Cooling Systems

Sharkoon announces S100 ARGB AIO Cooler

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed