South Korea has temporarily suspended downloads of DeepSeek AI’s apps due to privacy concerns. The Personal Information Protection Commission (PIPC) cited the need for the service to comply with data protection regulations. This action follows similar restrictions in other regions, highlighting increasing global scrutiny over AI app privacy practices. The suspension will remain in effect until DeepSeek implements the necessary changes to address the identified privacy issues.
This cluster details a report by Citizen Lab and the EFF Threat Lab highlighting critical privacy vulnerabilities in the “RedNote” app. The analysis of version 8.59.5 found that the app transmits user content over unencrypted HTTP, potentially exposing sensitive data to network attackers. Static analysis also revealed the use of static keys for encrypting certain files, exposing those files to decryption. Furthermore, the app transmits device metadata without encryption, potentially vulnerable to man-in-the-middle attacks.
Mozilla is still promoting Onerep almost a year after KrebsOnSecurity revealed that the founder of the personal data removal service Onerep also founded dozens of people-search companies. Mozilla said it would stop bundling Onerep with the Firefox browser and wind down its partnership. It’s a win-win for Mozilla that they’ve received accolades for their principled response while continuing to partner with Onerep almost a year later.
This cluster centers around the UK government’s order mandating Apple to create a backdoor for accessing end-to-end encrypted data in iCloud. This order raises significant concerns about user privacy and security, as well as potential implications for global digital privacy norms. Apple is being legally pressured to compromise user data which would seriously damage privacy and security.
Microsoft’s new AI feature ‘Recall’ for Copilot+ PCs stores screenshots of sensitive data, including credit cards and social security numbers, even when a ‘sensitive information’ filter is enabled. This has raised serious privacy and security concerns among users. This feature takes continuous screenshots of everything a user does. The data is stored locally but sent off to Microsoft’s LLM for analysis. This has prompted an investigation by the UK Information Commissioner’s Office. This incident highlights the potential risks of AI-powered surveillance features and the importance of user privacy.